What a Privacy Policy Must Tell You by Law
Modern privacy laws require companies to disclose specific information. GDPR (EU) mandates disclosure of data categories collected, the legal basis for processing, retention periods, international transfers, and individual rights. CCPA (California) requires disclosure of what personal information is collected, how it's used, and whether it's sold — plus the right to opt out. COPPA (U.S.) applies to children under 13. Despite these requirements, privacy policies are often written to technically satisfy legal obligations while obscuring the practical reality of how data is used. Key things to look for: which categories of data are collected, the definition of "partners" the data is shared with, and how you can exercise your rights.
What Data Companies Actually Collect
Companies collect more data than most users realize. Identity data includes name, email, date of birth, and address. Contact data includes phone number and mailing address. Transactional data includes purchase history and payment information. Behavioral data includes browsing patterns within the app, search queries, time on page, and click patterns — a detailed map of how you use the service. Location data may be precise GPS coordinates or coarse IP-based location. Device data includes browser type, operating system, screen resolution, and persistent device identifiers. Inferred data is derived from the above — interest profiles, propensity scores, demographic estimates — and is often the most commercially valuable. Many policies describe inferred data vaguely or not at all.
Third-Party Data Sharing: Read Between the Lines
The data-sharing section is where privacy policies get most opaque. Companies typically share data with three types of entities: service providers (vendors who process data on the company's behalf — cloud hosts, analytics platforms, payment processors); business partners (other companies integrated into the platform for features, joint marketing, or promotions); and advertising networks or data brokers (companies that use your data to target ads or resell it to others). "We do not sell your data" is a phrase many companies use while technically exploiting definitional loopholes — under California law, "sell" has a specific legal meaning, and many forms of data-for-advertising exchanges may not legally qualify as a "sale" even though they're functionally similar.
Your Rights and How to Exercise Them
Your privacy rights depend on where you live. GDPR grants EU residents: the right to access (get a copy of your data), the right to erasure (request deletion), the right to portability (receive data in machine-readable format), the right to restrict processing, and the right to object. CCPA gives California residents: the right to know, the right to delete, the right to opt out of sale or sharing, and the right to non-discrimination for exercising these rights. The privacy policy should explain how to submit a request — typically via email, account settings, or a web form. Responses are required within 30 days (GDPR) or 45 days (CCPA).
Cookies, Tracking Pixels, and Fingerprinting
Most privacy policies include a section on cookies and other tracking technologies, often cross-referencing a separate Cookie Policy. Beyond simple cookies, modern tracking includes: persistent cookies that remain on your device for extended periods; third-party cookies placed by advertising networks to track you across multiple websites; tracking pixels (tiny invisible images) that record when emails are opened and what links are clicked; session recording tools that replay your exact mouse movements and keystrokes on web pages; and browser fingerprinting, which builds a unique identifier for your device without cookies — making it resistant to cookie deletion. After GDPR and state-level cookie laws, companies must obtain consent for non-essential cookies in many jurisdictions, though dark patterns that make opting out difficult remain widespread.
How Long They Keep Your Data
Data retention schedules in privacy policies range from specific to deliberately vague. Account data is often retained until you delete your account plus an additional period afterward. Transactional data (purchase history) may be kept for years for legal and tax compliance purposes. Server logs (records of your sessions and IP addresses) may be retained for months. Marketing data may be retained indefinitely unless you opt out. A policy that says data is retained "as long as necessary for legitimate business purposes" with no further specifics is a red flag for potential indefinite retention. After your data is no longer needed, it should be deleted or anonymized — look for language confirming this.