clause.watch Contracts Recent changes Start monitoring

Monitored company

Bloomreach

clause.watch tracks 3 legal documents published by Bloomreach, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy at Bloomreach

3,848 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Privacy Policy

5,765 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Terms of Service

4,007 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Change history

2026-09-06 · Privacy at Bloomreach

shrank 32.1% · Observed by clause.watch

Summary of Important Changes

1. Major replacement of cookie-consent content

The original cookie-banner and cookie-policy language has largely been replaced with Bloomreach website navigation and marketing content. Deleted language included:

  • Consent to the collection and use of cookies.
  • Ability to customize or decline cookie categories.
  • Explanations of necessary, functional, analytical, and marketing cookies.
  • Statements about personalization, analytics, advertising, and sharing data with partners.
  • References to the Cookie Policy and Privacy Notice.

The replacement content mainly promotes Bloomreach products, including AI-powered personalization, marketing automation, search, agents, and integrations.

Risk: The revised content may no longer provide legally sufficient cookie notice or obtain valid consent. In particular, it appears to remove clear explanations of purposes, consent categories, user choices, and the consequences of accepting or declining cookies. This could create compliance risks under laws such as the GDPR/ePrivacy rules, UK PECR, and applicable U.S. state privacy laws.

2. Reduced transparency regarding data use

The deleted language explained that cookies could be used to:

  • Personalize content and advertisements.
  • Analyze website usage.
  • Improve site functionality.
  • Partner with companies to serve interest-based advertising.
  • Process cookies depending on the visitor’s consent choices.

The replacement does not provide equivalent disclosures. It instead contains general product descriptions such as “AI-powered personalization,” “autonomous” agents, and “workflows powered by Loomi intelligence.”

Risk: Marketing descriptions do not substitute for a legally adequate privacy or cookie disclosure. The revised text may make it unclear what personal data is collected, for what purposes, by which parties, and on what legal basis.

3. AI and model-training implications

The diff introduces or emphasizes:

  • “Loomi AI platform.”
  • “Agentic personalization.”
  • AI-powered marketing, search, and shopping agents.
  • Custom agents and workflows “powered by Loomi intelligence.”
  • Connections to more than 175 integrations.
  • Intent-driven personalization and autonomous workflows.

However, the diff does not expressly state that customer data will be used to train, fine-tune, or improve AI models, nor does it expressly prohibit such use.

Risk: The absence of a training-data provision leaves an important issue unresolved. Customers cannot determine from this text whether their data, prompts, content, behavioral information, or outputs may be used for:

  • Training or improving shared or general-purpose models.
  • Training customer-specific models.
  • Product development, analytics, or benchmarking.
  • Human review or model safety processes.
  • Sharing with third-party AI or integration providers.

Any customer agreement or privacy notice should address these points expressly, including ownership, confidentiality, opt-out rights, retention, de-identification, subprocessors, and whether data is isolated from other customers’ models.

4. Broken or misleading presentation risk

The diff appears to insert extensive navigation, promotional, and error-page content into the cookie-policy text, including “404” messaging and unrelated product pages.

Risk: This may be a website publishing or version-control error that makes the policy confusing, inaccessible, or legally unreliable. The correct cookie and privacy notices should be restored and separately reviewed before publication.

2026-09-03 · Privacy at Bloomreach

shrank 2.7% · Observed by clause.watch

Summary of Important Changes

1. Navigation and marketing content replaced

The diff primarily updates website navigation labels and promotional copy. Several existing terms are replaced with new content, including:

  • “BFCM” replaced with “Partners” or “ESG”, depending on location.
  • “email” replaced with “at Bloomreach”.
  • Promotional text about an email journey built live is replaced with navigation items such as:
  • “Partners”
  • “RFP/RFI”
  • “Company”
  • “Our Story”
  • “Why Bloomreach”
  • “Leadership Team”
  • “ESG at Bloomreach”
  • “News”
  • “Careers”
  • “is closer than it looks” is replaced with “RFP/RFI Company Our Story Why Bloomreach Leadership Team ESG at Bloomreach News Careers”, suggesting a page-template, navigation, or content-rendering change rather than a substantive contractual amendment.

2. Careers count updated

The displayed careers number changes from:

  • “Careers 69” to “Careers 73”

This appears to be a current job-opening count. It has no apparent legal effect unless the number is incorporated into a representation, offer, or other binding commercial statement.

3. Language and regional navigation

The diff adds or preserves expanded regional and language navigation, including:

  • APAC, EU, US, UK, and Canada
  • English, French, and German

This may affect which regional website version, legal terms, privacy notice, or cookie settings a visitor sees. Businesses should confirm that localized legal documents remain consistent across these versions.

4. AI training and customer-data use

No changes concerning customer data, AI-model training, machine learning, or use of customer content were identified in this diff.

Although the updated navigation references the “Loomi AI platform” and an “Agentic personalization platform,” the diff does not add or remove language addressing:

  • Whether customer data is used to train AI models;
  • Whether data is used to improve Bloomreach’s products or models;
  • Customer consent or opt-out rights;
  • Ownership of inputs, outputs, or derived data;
  • Data retention, anonymization, or aggregation;
  • Restrictions on using customer data for general-purpose or third-party model training.

5. Overall legal significance

The changes appear predominantly editorial and navigational, with no clear amendment to contractual rights or obligations. The main legal review point is to verify that links from the revised navigation continue to direct users to the correct privacy, security, cookie, and AI-related terms.

2026-09-01 · Privacy at Bloomreach

grew 45.5% · Observed by clause.watch

Executive Summary

The diff appears to replace much of the website’s prior content with a cookie-consent notice and revised marketing/navigation content. The most legally significant changes concern cookie use, consent choices, profiling/personalization, analytics, and advertising. The diff does not expressly state that customer data is used to train AI models, nor does it expressly prohibit such use.

Important Changes and Risks

1. Expanded cookie disclosure and consent mechanism

The revised language states that Bloomreach uses cookies to:

  • Help users navigate the website and perform functions;
  • Tailor the website and display content that “might be interesting” to each visitor;
  • Remember user choices;
  • Support security and regulatory compliance;
  • Personalize browsing experiences;
  • Analyze website usage and improve functionality; and
  • Partner with companies to serve relevant advertisements.

Users may accept, decline, or customize cookies, except for “strictly necessary” cookies that remain active.

Risks:

  • The purposes are broad and may cover profiling, behavioral advertising, and personalization.
  • “Strictly necessary” is not defined in the diff. Treating cookies as necessary when they support AI or marketing functionality could create consent and regulatory risk.
  • The statement that certain cookies “cannot be switched off” may be problematic if those cookies are not genuinely essential.
  • The language does not identify specific cookie providers, retention periods, data categories, international transfers, or user-rights procedures.
2. New or clearer separation of cookie categories

The revised text identifies:

  • Essential/Always Active cookies;
  • Functional cookies;
  • Analytical cookies; and
  • Marketing cookies.

Functional cookies are described as enhancing the website, analytical cookies as measuring and improving performance, and marketing cookies as enabling relevant advertising.

Risks:

  • The notice may imply that analytical and marketing data is shared with third-party companies, but does not identify those companies or explain their independent uses.
  • The consent interface and wording should ensure that non-essential cookies are disabled by default where required and that consent is as easy to withdraw as to give.
3. AI-related data use and model training

The updated website substantially expands references to AI products, including AI-powered personalization, autonomous marketing, search, shopping assistants, agents, and workflows. It also states that Loomi Connect is powered by “Loomi intelligence” and integrates with more than 175 systems.

However, the diff contains no express provision stating that customer data, prompts, outputs, usage data, or cookie data will be used to train, fine-tune, evaluate, or improve AI models. It also contains no express opt-out, ownership protection, de-identification commitment, or restriction on use of customer data for model training.

Risk: The absence of a clear training-use statement leaves the contractual position ambiguous. The privacy notice, product terms, data-processing agreement, and AI terms should be reviewed for provisions addressing model training and secondary use.

4. Broader personalization and advertising claims

The revision changes language from content that “maximizes revenue” to content that “might be interesting,” and adds personalization and relevant-advertising purposes.

This may reduce the strength of the commercial claim but broadens the stated behavioral use of visitor data. It may also require clearer disclosures concerning profiling, automated decision-making, and targeted advertising.

Recommended Follow-Up

Confirm whether separate terms address:

1. AI model training and improvement;

2. Customer-data ownership and permitted processing;

3. Use of prompts, outputs, and telemetry;

4. Third-party AI providers and subprocessors;

5. Cookie consent defaults and withdrawal; and

6. Profiling, targeted advertising, retention, and international transfers.

2026-09-01 · Privacy at Bloomreach

grew 1.6% · Observed by clause.watch

Summary

Scope of the Change
  • The diff states only that approximately eight words were added.
  • The actual added wording is not provided.
Legal and Commercial Impact
  • It is not possible to determine whether the addition:
  • Changes the parties’ rights or obligations;
  • Expands or limits liability, confidentiality, indemnity, or termination rights;
  • Alters data ownership, licensing, or permitted uses;
  • Adds consent, notice, audit, or compliance requirements; or
  • Creates new operational or financial risks.
AI Training and Customer Data
  • The supplied diff does not identify any specific language concerning:
  • Use of customer data to train, fine-tune, validate, or improve AI models;
  • Whether customer data may be combined with other users’ data;
  • Whether data is anonymized, de-identified, or retained;
  • Whether customer consent is required;
  • Whether derived data, prompts, outputs, or model weights may be used commercially; or
  • Whether the customer may opt out of AI training.

Accordingly, no reliable conclusion can be reached about changes to AI-training rights or related privacy and confidentiality risks.

Required Information

To perform a meaningful legal analysis, provide the actual eight added words, together with the surrounding clause or a redlined version showing the relevant text.

2026-08-31 · Terms of Service

grew 1.6% · Observed by clause.watch

Summary

The diff only states that approximately eight words were added, but it does not identify the actual words or their location in the agreement.

Legal and Risk Analysis

  • No substantive change can be assessed from the information provided.
  • It is not possible to determine whether the added language changes:
  • The parties’ rights or obligations;
  • Liability, indemnities, confidentiality, or termination rights;
  • Data ownership or permitted data uses;
  • Privacy, security, or regulatory compliance obligations; or
  • AI-related data processing or model-training rights.

AI Model Training and Customer Data

The diff provides no identifiable change concerning whether customer data may be:

  • Used to train, fine-tune, or improve AI models;
  • Shared with model providers or other third parties;
  • Retained after the customer relationship ends;
  • Aggregated, anonymized, or de-identified for model development; or
  • Excluded from training or subject to an opt-out.

Because the actual eight added words are not shown, any conclusion about AI training rights would be speculative.

Required Information

To perform a meaningful legal analysis, provide the exact added language and, preferably, its position in the agreement. The comparison should show the words using the stated notation, for example:

  • {new language}
  • [deleted language]
  • [old language]{new language}

2026-08-31 · Privacy Policy

grew 46.2% · Observed by clause.watch

Summary

The provided diff does not include the actual contract language. It only states:

> “Added approximately 284 words to the document”

Accordingly, it is not possible to identify:

  • The specific legal or commercial changes;
  • New customer obligations or provider rights;
  • Changes to liability, confidentiality, intellectual property, security, or termination provisions; or
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models.

AI Training and Data-Use Review

No substantive language concerning AI models or customer data is included in the diff provided. Therefore, it is not possible to determine whether the revised terms:

  • Permit use of customer data for model training or improvement;
  • Limit training use to aggregated, de-identified, or anonymized data;
  • Require customer consent or provide an opt-out;
  • Allow human review or sharing with affiliates and service providers;
  • Grant the provider ownership or broad usage rights in customer inputs or outputs;
  • Impose deletion, retention, or data-isolation obligations; or
  • Address whether prompts, outputs, or derived information are considered confidential information.

Information Needed

Please provide the actual added, deleted, and replacement text using the stated notation. The phrase indicating that approximately 284 words were added is insufficient to perform a legal comparison or identify new risks.

2026-08-31 · Privacy at Bloomreach

shrank 31.6% · Observed by clause.watch

Summary of Important Changes

1. Major content replacement

The diff appears to replace a detailed cookie-consent notice with unrelated Bloomreach marketing and website-navigation content. The revised text includes product descriptions, industry lists, promotional material, contact links, and footer content.

This is not a conventional legal revision. It may indicate that the wrong webpage, template, or content block was inserted.

2. Cookie consent language substantially removed

The original text stated that:

  • Cookies are used for navigation, functionality, personalization, analytics, and advertising.
  • Strictly necessary cookies are permitted by law.
  • Users may choose which cookie categories to allow.
  • Users may customize or decline cookies.
  • Additional information is available in the Cookie Policy and Privacy Notice.
  • Analytical cookies may be used to improve the website.
  • Marketing cookies may be used with companies to serve relevant advertisements.

Most or all of this language is deleted or displaced in the revised content. The replacement does not appear to provide a functional explanation of cookie categories, consent choices, withdrawal mechanisms, or applicable legal basis.

Legal and compliance risk

The revised text may fail to provide legally required transparency and consent controls under privacy laws such as the GDPR, ePrivacy rules, UK GDPR, and similar laws. In particular, the revised content may no longer clearly explain:

  • What cookies or similar technologies are used;
  • The purposes for each category;
  • Whether third parties receive data;
  • How consent can be refused or withdrawn; and
  • How users can access the Cookie Policy or Privacy Notice.

If this content is intended to appear in a consent-management interface, replacing the notice with marketing copy could also make consent invalid or misleading.

3. AI-related changes

The revised content introduces extensive AI and automation marketing language, including:

  • “AI future”;
  • “AI-powered personalization”;
  • “AI-native commerce search”;
  • “AI Agents”;
  • “Marketing Agent” and “Shopping Agent”;
  • “Loomi intelligence”; and
  • Custom agents and workflows connected to more than 175 integrations.

The original cookie notice did not expressly authorize or describe the use of customer or visitor data to train AI models. The revised text also does not expressly state that customer data will be used for model training.

AI data-use risk

Although no explicit training right is added, the revised references to AI systems, personalization, agents, integrations, and “Loomi intelligence” create ambiguity about whether customer data, behavioral data, prompts, outputs, or connected-system data may be:

  • Used to operate AI features;
  • Used to improve services or algorithms;
  • Used to train or fine-tune general or customer-specific models; or
  • Shared with AI or integration providers.

Those purposes should be addressed expressly in the privacy notice, product terms, and data-processing agreement. The revised copy should not be treated as granting a clear contractual right to train AI models.

4. Recommended action

Confirm whether this diff reflects an accidental content or deployment error. Restore the cookie notice and add a specific AI data-use provision addressing training, service improvement, retention, subprocessors, customer controls, and opt-out rights.

2026-08-30 · Privacy at Bloomreach

grew 46.2% · Observed by clause.watch

Summary

The supplied diff does not include the actual amended legal language. It only states:

> “Added approximately 284 words to the document”

Accordingly, it is not possible to identify:

  • The specific contractual changes;
  • New customer obligations or provider rights;
  • Changes to liability, confidentiality, security, or termination provisions;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether such use is subject to consent, opt-out rights, anonymization, retention limits, or restrictions on human review; or
  • Any new risks arising from the additions.

AI Training and Data-Use Review

No conclusion can be reached regarding AI-model training because the added wording itself is not provided. The key provisions to check for include whether the agreement:

  • Grants the provider a license to use customer content, data, prompts, or outputs;
  • Permits use for “service improvement,” “research,” analytics, or model training;
  • Allows data to be shared with affiliates, contractors, or third-party model providers;
  • Distinguishes between account data, inputs, outputs, and personal or confidential information;
  • Provides an opt-out or requires affirmative customer consent;
  • States whether data is de-identified, aggregated, deleted, or retained; and
  • Explains whether trained models may continue to reflect customer data after deletion or termination.

Required Information

Please provide the actual redline text, with additions, deletions, and replacements shown. Without the substantive diff, the only reliable conclusion is that approximately 284 words were added, but their legal effect and any AI-training risks cannot be assessed.

2026-08-30 · Terms of Service

shrank 31.6% · Observed by clause.watch

Structured Summary of Important Changes

1. Overall nature of the change

The diff appears to replace a detailed cookie-consent notice with large amounts of Bloomreach website navigation, marketing, product, and footer content. Much of the replacement is not legally operative cookie-policy language. The result may be confusing, incomplete, or technically defective if published as a privacy or consent notice.

2. Customer data use and cookies

Deleted or materially reduced language

The prior text expressly stated that:

  • Cookies are used to optimize communications and enhance the customer experience.
  • Cookies may personalize advertisements.
  • Users can choose which cookie categories to allow, except strictly necessary cookies.
  • Cookie data may be used to tailor website content to users’ needs.
  • Analytical-cookie data may be used to analyze site usage and improve functionality.
  • Marketing cookies may involve partnering with companies to serve ads relevant to users’ interests.
  • Users could decline cookies, customize preferences, or save preferences.

These provisions are largely deleted or displaced.

New or remaining language

The replacement primarily promotes:

  • AI-powered personalization;
  • AI-native commerce search;
  • AI agents and autonomous shopping tools;
  • Email, SMS, WhatsApp, advertising, retargeting, and ecommerce products;
  • Loomi and integrations.

The new text does not clearly explain what customer or cookie data is collected, the purposes of processing, the legal bases, retention periods, sharing arrangements, or user rights.

3. AI-model training implications

No express provision was added stating that customer data, personal data, cookie data, prompts, outputs, usage data, or business content may be used to train, fine-tune, evaluate, or improve AI models.

However, the replacement introduces extensive references to AI products and “Loomi intelligence,” including custom agents and workflows. This creates ambiguity because readers may reasonably ask whether data supplied to those products is used for model development.

Risk: The absence of a training statement does not necessarily prohibit training, but it provides no clear disclosure or contractual limitation. If customer data is in fact used to train or improve models, the revised text may be insufficient for transparency, consent, controller/processor allocation, confidentiality, and data-protection compliance.

4. Key legal and operational risks

  • Invalid or weakened cookie consent: The revised text may no longer provide clear, accessible information needed for informed consent.
  • Loss of granular choices: Decline/customization language appears removed or obscured.
  • Purpose ambiguity: Advertising, personalization, analytics, and AI processing are no longer clearly separated.
  • Misleading presentation: Marketing navigation may be mistaken for legally required privacy disclosures.
  • Broken drafting/publication risk: Repeated and interleaved text suggests a corrupted webpage or failed content replacement.
  • AI governance gap: No clear restrictions on using customer data for model training, nor any explanation of opt-out rights or safeguards.

5. Recommended action

Do not publish this version as a cookie notice or privacy disclosure without restoring clear consent language and adding an explicit AI-data-use provision addressing whether customer data may be used for training or improving AI models.

2026-08-29 · Terms of Service

grew 46.2% · Observed by clause.watch

Summary

No substantive text provided

The diff only states:

> “Added approximately 284 words to the document”

It does not include the actual added language or identify which provisions were changed. As a result, it is not possible to determine:

  • What contractual rights or obligations were added;
  • Whether liability, indemnity, confidentiality, security, payment, termination, or dispute-resolution terms changed;
  • Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data may be shared with affiliates, vendors, or third parties for AI-related purposes;
  • Whether customer data will be anonymized, aggregated, retained, or deleted;
  • Whether the customer can opt out of AI training or revoke consent;
  • Whether the provider obtains ownership or broad usage rights in customer data or outputs; or
  • Whether new restrictions or compliance obligations apply to the customer.
AI-training risk assessment

No conclusion can be reached regarding AI-model training because the relevant contractual wording is missing. The added language should be reviewed specifically for terms such as:

  • “train,” “fine-tune,” “develop,” “improve,” or “evaluate” models;
  • “customer data,” “content,” “inputs,” “outputs,” or “usage data”;
  • “de-identified,” “anonymized,” or “aggregated” information;
  • Rights granted to use data “for any purpose” or “to improve services”;
  • Data retention and deletion periods;
  • Opt-out, consent, or objection mechanisms; and
  • Restrictions on using confidential, personal, regulated, or proprietary information.
Information needed

Please provide the actual 284 words added, together with any surrounding text or the complete marked-up diff. Without that language, a reliable legal-risk analysis is not possible.

2026-08-29 · Privacy Policy

grew 2.9% · Observed by clause.watch

Summary of Important Changes

1. No substantive customer-data or AI-training changes identified

The diff appears to concern website navigation, labels, and footer links rather than contractual terms, privacy terms, or data-processing provisions.

  • There is no language stating that customer data may be used to train, fine-tune, test, validate, or improve AI models.
  • There is no deletion or limitation of an existing AI-training restriction in the text provided.
  • There are no changes addressing:
  • Whether customer content, prompts, behavioral data, or personal data may be used for AI training;
  • Whether data is aggregated, anonymized, or de-identified before such use;
  • Opt-out or consent rights;
  • Human review or model-development access;
  • Retention, deletion, or segregation of customer data used with AI products;
  • Ownership of model outputs or trained models.

Risk assessment: Based solely on this diff, there is no apparent new contractual permission to use customer data for AI training. However, the diff may not include linked privacy policies, product terms, or data-processing terms where those rights could appear.

2. New or expanded website links

The revised navigation adds or reorganizes links including:

  • “Privacy at Bloomreach”
  • “Security at Bloomreach”
  • “Bloomreach Academy”
  • “Analyst Reports”
  • “Learn”
  • “Use Cases”
  • “Case Studies”
  • “Blog”
  • “Resource Library”
  • “Roadmap & Product Updates”
  • Additional competitor-comparison pages, including Bloomreach vs. Braze, SAP, and Voyado.

These changes may make privacy and security materials more prominent, but the diff does not show the substantive content of those materials. If incorporated by reference into a customer agreement, updated linked pages could potentially affect customers’ understanding of data handling or security practices. Their contractual status should therefore be confirmed.

3. Potentially important deletions or replacements

Several navigation groupings are replaced or rearranged, including:

  • “Resources / Integrations / Documentation / Product Tours / Partners”
  • “Alternatives / Bloomreach vs. Salesforce”
  • “Learn / Use Cases / Case Studies…”

These appear to be marketing-navigation changes, not deletions of contractual rights or services.

4. Apparent numerical changes

“Careers 70” is replaced with “Careers 66” in several places. This appears to be a page-count, job-count, or navigation-label change. It has no evident legal significance unless the number represents a contractual quantity, which is unlikely.

5. Recommended follow-up

Review the linked Privacy, Security, AI-product, and data-processing pages separately. Those documents should be checked for any provisions allowing customer data to be used for AI training or product improvement, particularly where the website terms can be updated unilaterally.

2026-08-28 · Terms of Service

shrank 31.6% · Observed by clause.watch

Structured Summary

1. Major change: cookie-consent language appears to have been removed or replaced

The original text was a conventional cookie notice stating that Bloomreach:

  • Uses cookies to optimize communications, improve customer experience, and personalize advertising.
  • Collects and uses cookies for those purposes when the user clicks “Accept All.”
  • Permits users to customize or decline non-essential cookies.
  • Uses functional, analytical, and marketing cookies.
  • May use cookie data to analyze website usage, improve functionality, personalize the browsing experience, and serve relevant advertising.

In the revised text, most of this language is replaced by unrelated website navigation, product descriptions, marketing copy, and resource links. The revised material includes references to AI products such as “AI-powered personalization,” “AI-native commerce search,” “Marketing Agent,” “Shopping Agent,” and “Loomi.”

Risk: The revised text may no longer provide a legally adequate cookie disclosure or consent mechanism. It appears to omit or obscure:

  • The purposes and categories of cookies.
  • The distinction between strictly necessary and optional cookies.
  • The ability to decline or customize cookies.
  • Information about analytics, advertising, and third-party sharing.
  • Links or references to the Cookie Policy and Privacy Notice.

If this is intended to be customer-facing legal text rather than a corrupted webpage extract, it could create consent, transparency, and regulatory risks under GDPR/ePrivacy, UK privacy law, and similar regimes.

2. AI-related changes

The revision adds extensive marketing references to AI functionality, including:

  • “AI future with intent-driven personalization.”
  • “AI-powered personalization across email, SMS, and more.”
  • “AI-native commerce search.”
  • “AI Agents,” “Marketing Agent,” and “Shopping Agent.”
  • “Build custom agents and workflows powered by Loomi intelligence.”
  • “Autonomous” marketing, search, and shopping functionality.

However, the diff does not expressly state that customer data, cookie data, personal data, prompts, outputs, or usage information will be used to train AI models.

Important limitation: The absence of an express training provision does not establish that customer data is excluded from model training. The revised language should be checked against the operative Privacy Policy, customer agreement, data-processing addendum, and AI-specific terms.

3. Other legal and operational risks
  • The diff appears heavily corrupted, with legal notice text replaced by site-navigation content and unrelated marketing material.
  • References to “ads,” “retargeting,” personalization, analytics, and AI agents may expand perceived processing activities without corresponding disclosures.
  • The revised text may create ambiguity about whether AI tools process customer data, for what purposes, and whether data is shared with providers or used for product improvement.
  • Broken or misleading links and consent labels could undermine valid consent and make recordkeeping difficult.
Recommended action

Treat the revised text as unusable legal copy. Restore a clear cookie notice and separately confirm, in contract/privacy language, whether customer data is used for AI model training, fine-tuning, evaluation, service improvement, or human review.

2026-08-28 · Terms of Service

grew 46.2% · Observed by clause.watch

Executive Summary

The diff appears to replace much of the website’s marketing/navigation content with a detailed cookie-consent notice and expanded descriptions of Bloomreach’s AI products. The principal legal changes concern cookie use, personalization, analytics, advertising, and user consent. No express statement authorizing the use of customer data to train AI models has been added. However, the expanded data-use language may permit broader processing for personalization, analytics, and marketing, which could be relevant to AI systems depending on how those systems operate.

Important Changes and Risks

1. Expanded cookie purposes and data processing

The revised language states that Bloomreach uses cookies to:

  • Help users navigate the website and perform functions;
  • Tailor the website and content to users’ needs;
  • Personalize the browsing experience;
  • Analyze website usage and improve functionality;
  • Cater the experience to users; and
  • Partner with companies to serve relevant advertisements.

Risk: These purposes are broader than a simple website-functionality notice and may involve profiling, behavioral tracking, targeted advertising, and sharing data with advertising or technology partners. The wording “data” is not defined, so it is unclear whether it includes identifiers, browsing behavior, inferred interests, or other personal information.

2. Consent and user-choice mechanisms

The new notice distinguishes between:

  • Strictly necessary cookies, which are used without consent;
  • Functional cookies, which support additional features;
  • Analytical cookies, used to measure and improve website usage; and
  • Marketing cookies, used with partner companies for relevant advertising.

It adds controls such as Accept All, Customize Consent, Decline, Save Preferences, and a statement that users may change preferences.

Risk: The notice improves transparency and control but should be reviewed for compliance with applicable consent laws, including whether non-essential cookies are blocked before consent and whether consent is equally easy to refuse or withdraw. The phrase that strictly necessary cookies are “allowed by law” is not a substitute for explaining the legal basis and limits of their use.

3. AI products and automated personalization

The revised content prominently introduces or expands references to:

  • Loomi AI;
  • AI-powered personalization;
  • Autonomous marketing;
  • AI-native commerce search;
  • Marketing and Shopping Agents; and
  • Custom agents and workflows connected to more than 175 integrations.

Risk: These references indicate increased use of automated decision-making and potentially extensive data integration. The text does not explain what data the AI tools receive, whether personal or sensitive data may be used, how outputs are reviewed, or whether customers can opt out of automated profiling.

4. AI-model training

No new language expressly states that customer data, customer content, prompts, outputs, or usage data may be used to train, fine-tune, evaluate, or improve AI models.

Nevertheless, the broad references to analyzing usage, improving functionality, personalization, integrations, and “Loomi intelligence” do not clearly exclude model-development activities.

Recommendation: Add an explicit contractual statement addressing whether customer data is used for AI training, whether it is excluded by default, applicable de-identification standards, customer opt-in/opt-out rights, retention, subprocessors, and ownership of resulting models and outputs.

5. Privacy documentation

The revised footer links to a Privacy Policy, Cookie Settings, security information, and data-control resources. These links should be checked to ensure they accurately describe the expanded AI and cookie processing and are incorporated into the governing agreement where appropriate.

2026-08-25 · Terms of Service

grew 2.9% · Observed by clause.watch

Summary of Important Changes

Overall assessment

The diff appears to concern website navigation, menu labels, and links rather than contractual terms, privacy language, or data-processing provisions. No substantive legal wording is added or removed.

Key changes

1. Updated careers references

Multiple instances of:

  • Careers 68Careers 70
  • Careers68Careers70

This appears to update a displayed number associated with the Careers link, likely the number of open positions. It does not appear to change employment terms, customer obligations, or data rights.

Potential risk: If “68” or “70” represents a factual claim rather than merely a navigation identifier, the updated number should be accurate and kept current.

2. Navigation and resource restructuring

Several menu sections were reorganized. Changes include:

  • Addition or repositioning of links such as Compare us, Why Bloomreach, Alternatives, and competitor comparison pages.
  • Reordering or expansion of links for:
  • Integrations
  • Documentation
  • Product Tours
  • Bloomreach Academy
  • Partners
  • Analyst Reports
  • Use Cases
  • Case Studies
  • Blog
  • Resource Library
  • Roadmap & Product Updates
  • Addition of links referring to comparisons with Braze, SAP (former Emarsys), and Voyado.
  • Addition of Privacy at Bloomreach and expansion from Security to Security at Bloomreach.
  • Addition of a Contact Us link in the footer/navigation.

These appear to be presentation and discoverability changes only.

Potential risks:

  • Competitor comparison pages may create advertising, substantiation, trademark, or unfair-commercial-practices issues if claims on those pages are inaccurate, outdated, or insufficiently supported.
  • The revised “Privacy at Bloomreach” and “Security at Bloomreach” links should point to the correct, current policies and security materials. Any inconsistency between those materials and the operative contract could create customer confusion or reliance risk.
  • References to “Roadmap & Product Updates” should not unintentionally create binding commitments about future functionality.

AI-model training and customer data

The diff contains no apparent changes addressing:

  • Whether customer data may be used to train AI models;
  • Whether customer content, prompts, outputs, or personal data may be used for model improvement;
  • Opt-in or opt-out rights;
  • Aggregation, anonymization, or de-identification;
  • Retention or deletion of AI-related data;
  • Use of third-party AI providers; or
  • Ownership of inputs and outputs.

Accordingly, this diff does not create an identifiable new AI-training authorization or restriction. Any such terms would need to be reviewed in the underlying privacy policy, data-processing addendum, product terms, or AI-specific documentation linked from the site.

2026-08-25 · Privacy at Bloomreach

grew 2.9% · Observed by clause.watch

Summary

The supplied diff only states:

> “Added approximately 15 words to the document”

It does not identify the actual added, deleted, or replaced legal language.

Key Changes

  • No substantive changes can be analyzed because the specific text of the amendment is missing.
  • The nature and legal effect of the added 15 words cannot be determined.
  • No conclusions can be drawn about changes to:
  • Customer data ownership or rights
  • Data collection, disclosure, or retention
  • Confidentiality or security obligations
  • Use of data for artificial intelligence or machine-learning purposes
  • Training, fine-tuning, testing, or improving AI models
  • Opt-out, consent, or deletion rights
  • Liability, indemnification, or compliance obligations

AI Training and Model-Use Risk

The provided diff contains no language addressing whether customer data may be used to train, fine-tune, evaluate, or improve AI models. Accordingly, no change in AI-training rights or restrictions can be identified.

Required Information

To perform a meaningful legal analysis, please provide the actual marked-up text, using:

  • {added text}
  • [deleted text]
  • []{} for replacement language, with the deleted and added wording clearly shown

The full surrounding clause may also be necessary because the legal impact of a 15-word addition can depend on definitions, exceptions, and related provisions elsewhere in the agreement.

2026-08-23 · Privacy at Bloomreach

shrank 32.2% · Observed by clause.watch

Executive Summary

The diff appears to replace a detailed cookie-consent notice with Bloomreach marketing/navigation content. It does not appear to be a coherent amendment to contractual data-processing terms. The principal legal risk is that important privacy and consent disclosures may have been removed or displaced, while the replacement text introduces broad AI and personalization claims without corresponding data-use limitations.

Important Changes and Risks

1. Removal of detailed cookie-consent language

The deleted text explained that:

  • Strictly necessary cookies are always active.
  • Users could choose which other cookie categories to allow.
  • Functional, analytical, and marketing cookies had different purposes.
  • Analytical data could be used to improve the site and tailor the user experience.
  • Marketing cookies could involve partners serving relevant advertisements.
  • Users could review the Cookie Policy and Privacy Notice.

This has been replaced largely by website navigation, product descriptions, and promotional content.

Risk: The revised content may no longer clearly disclose cookie categories, purposes, partners, user choices, or the consequences of refusing consent. If this text is intended to function as a consent notice, it may be inadequate under applicable privacy and electronic-marketing laws, including GDPR/ePrivacy-style requirements.

2. Broader AI and personalization references

New language promotes:

  • An “AI future”
  • “AI-powered personalization”
  • “AI-native commerce search”
  • “Loomi intelligence”
  • AI “Agents,” including Marketing and Shopping Agents
  • Autonomous marketing, search, and shopping functionality
  • Integrations with “175 more” systems

Risk: These references may imply that customer or visitor data is processed by AI systems, agents, integrations, or third-party providers. The text does not identify the data involved, purposes, legal basis, retention period, model providers, geographic transfers, or customer controls.

3. AI model training

The diff contains no express statement authorizing or prohibiting the use of customer data to train, fine-tune, evaluate, or improve AI models.

The deleted cookie language referred generally to using data to analyze site usage, improve functionality, and tailor experiences. The new text refers to “Loomi intelligence” and AI-powered products, but does not say whether customer data is:

  • Used to train Bloomreach’s general models;
  • Used only to operate customer-specific models or workflows;
  • Aggregated or de-identified before model development;
  • Shared with AI vendors or subprocessors; or
  • Excluded from model training by default.

Risk: The absence of a clear training restriction or permission creates material ambiguity. Existing contract terms, privacy notices, or data-processing addenda should be checked for explicit AI-training rights and limitations. If none exist, the parties should clarify this in writing.

4. Possible loss of contractual/privacy references

References to the Cookie Policy, Privacy Notice, consent preferences, and “Control Your Data” functionality appear altered, fragmented, or replaced by navigation labels.

Risk: Users or customers may have difficulty locating operative privacy terms or exercising rights. Website text should not unintentionally override or contradict the governing agreement, DPA, cookie policy, or privacy notice.

Recommended Action

Confirm whether this is merely a website-content migration rather than a contractual change. If AI functionality processes customer data, add express terms addressing permitted uses, model training, subprocessors, security, retention, de-identification, opt-out rights, and deletion of data from training datasets.

2026-08-22 · Privacy at Bloomreach

grew 47.5% · Observed by clause.watch

Important Changes

1. Website content was substantially replaced
  • The previous marketing, navigation, product, and company-page content has largely been replaced with cookie-consent language and related interface text.
  • The revised content adds or expands references to:
  • “Accept All,” “Customize,” “Decline,” and “Consent Preferences”
  • Cookie categories and settings
  • Cookie Policy and Privacy Notice
  • “Control Your Data,” “Cookie Settings,” and DPO contact information
  • The diff appears to contain repeated and possibly malformed content, including duplicated sections and a lengthy 404/error-page block. This may create ambiguity about which disclosures and controls are actually presented to users.
2. Expanded cookie purposes and data uses

The new language states that cookies may be used to:

  • Help users navigate the website and perform functions.
  • Remember user choices, maintain site functionality, and support security and regulatory compliance.
  • Personalize the browsing experience.
  • Analyze website usage and improve functionality.
  • “Cater your experience” to the user.
  • Partner with companies to serve advertisements relevant to the user’s interests.

Risk: The revised wording broadens the described purposes from general website optimization to personalization, analytics, targeted advertising, and sharing/use involving partner companies. The categories and purposes should be clearly defined and consistently reflected in the Cookie Policy and Privacy Notice.

3. Consent and opt-out mechanics
  • Strictly necessary cookies are described as permitted without consent and cannot be disabled.
  • Users may choose which other cookie categories to allow or reject.
  • A “Customize” option and consent-preference mechanism are added.

Risk: The notice should explain whether consent is granular by category, how withdrawal works, whether previously collected data is affected, and whether rejecting cookies limits access to services. Any “Accept All” presentation should not improperly pressure users or bundle unrelated purposes.

4. AI-related changes

The revised content adds extensive marketing references to AI products and “Loomi intelligence,” including:

  • AI-powered personalization across email and SMS.
  • Autonomous marketing, search, and shopping agents.
  • Custom agents and workflows connected to more than 175 integrations.
  • Use of browsing data for personalization and advertising.

No express AI-training provision identified: The diff does not expressly state that customer data, cookie data, prompts, outputs, or other personal information will be used to train, fine-tune, or improve general AI models. It also does not state that such data will not be used for training.

Risk: If customer data may be used for model training or product improvement, that disclosure is absent and should be addressed expressly, including purposes, data types, retention, de-identification, customer controls, and whether data is shared with model providers or used across customers.

2026-08-21 · Privacy Policy

shrank 32.2% · Observed by clause.watch

Summary

The diff states only that approximately 284 words were removed from the document. The actual deleted language is not provided, so the legal and operational impact cannot be determined reliably.

AI Training and Data Use

  • No specific AI-related amendment can be identified from the information supplied.
  • It is therefore impossible to determine whether the removed text:
  • Authorized or prohibited using customer data to train, fine-tune, or improve AI models;
  • Limited training to aggregated, anonymized, or de-identified data;
  • Required customer consent or provided an opt-out;
  • Addressed use of prompts, inputs, outputs, telemetry, or other customer content;
  • Restricted human review or disclosure of customer data;
  • Created deletion, retention, confidentiality, or data-segregation obligations; or
  • Clarified whether data could be used by affiliates, subprocessors, or third-party AI providers.

Potential Risks

Because the deleted wording is unavailable, the principal risk is loss of protections or ambiguity. If the removed provisions addressed data use, their deletion could potentially:

  • Expand the provider’s discretion to use customer data;
  • Remove limitations on AI model training or product improvement;
  • Eliminate consent, notice, opt-out, or deletion rights;
  • Make it unclear whether customer data may be retained after termination;
  • Weaken confidentiality, security, or data-processing commitments; or
  • Create conflicts with privacy laws, sector-specific rules, or the parties’ data-processing agreement.

Conversely, the deletion could also remove overly broad permissions and therefore benefit the customer. Its effect cannot be assessed without the deleted text and the surrounding provisions.

Recommended Follow-Up

Obtain a redline showing the actual 284 deleted words, preferably with the relevant section headings and surrounding language. Confirm specifically whether the revised document:

1. Permits training or improvement of general-purpose or customer-specific AI models;

2. Defines “customer data,” “content,” “usage data,” and “de-identified data”;

3. Requires consent or provides an opt-out;

4. Restricts use to service delivery and security;

5. Addresses retention, deletion, subprocessors, and human access; and

6. Preserves confidentiality and applicable privacy-law obligations.

2026-08-18 · Privacy at Bloomreach

shrank 32.2% · Observed by clause.watch

Structured Summary of Important Changes

1. Overall nature of the changes

The diff appears to replace a substantial cookie-consent and privacy notice interface with Bloomreach marketing and website-navigation content. Much of the replacement text is unrelated to cookies, consent, or privacy and instead promotes products, AI agents, email marketing, ecommerce search, and other services.

This may indicate a serious implementation or content-management error: users could receive incomplete, misleading, or nonfunctional privacy disclosures and consent controls.

2. Changes to cookie and tracking disclosures

Deleted or materially reduced disclosures

The previous text explained that:

  • Cookies are used to optimize communications, enhance customer experience, and personalize advertising.
  • Users could accept, decline, or customize cookie categories.
  • Strictly necessary cookies are always active.
  • Functional cookies personalize browsing.
  • Analytical cookies are used to analyze website usage and improve functionality.
  • Marketing cookies may be used with other companies to serve relevant advertisements.

Much of this language has been removed or replaced with product-navigation content.

New or substituted content

The replacement includes references to:

  • “AI future with intent-driven personalization”
  • “AI-native commerce search”
  • “Marketing Agent,” “Shopping Agent,” and other autonomous or AI-powered products
  • “Control Your Data”
  • “AI Cookie Email Settings”

However, the replacement does not clearly explain what data is collected, the purposes of processing, the legal bases, retention periods, sharing arrangements, or how consent can be withdrawn.

Risks
  • Consent may not be informed or legally valid if the cookie categories and purposes are no longer clearly presented.
  • Users may be unable to exercise granular choices or withdraw consent.
  • Marketing, analytics, personalization, and advertising processing could occur without adequate notice or consent.
  • The apparent replacement of privacy text with marketing text creates a risk of regulatory noncompliance and consumer deception.
  • Broken or misleading navigation could prevent access to the Cookie Policy, Privacy Notice, DPO contact, or preference center.

3. Customer data and AI-model training

No express training authorization identified

The diff does not expressly add language stating that customer data, personal data, cookie data, prompts, content, usage data, or customer materials may be used to train, fine-tune, evaluate, or improve AI models.

Similarly, it does not expressly prohibit such use.

Important ambiguity

The new references to “Loomi intelligence,” AI-powered personalization, autonomous agents, and AI-native products expand the apparent AI functionality, but they do not establish:

  • Whether customer data is used to train Bloomreach’s general models;
  • Whether data is used only to provide the customer’s service;
  • Whether data is aggregated, anonymized, or shared with third-party model providers;
  • Whether customers can opt out;
  • Whether customer data is retained for model development;
  • Whether outputs or prompts become part of a training dataset.

This issue should be addressed expressly in the applicable agreement, DPA, product terms, and privacy notice.

4. Recommended actions

  • Restore clear cookie-consent categories and purposes.
  • Confirm that consent buttons and preference controls function correctly.
  • Add explicit AI data-use and training terms.
  • Identify third-party AI providers, retention, security, opt-out rights, and deletion procedures.
  • Conduct a legal and technical review before publishing the revised content.

2026-08-18 · Privacy Policy

shrank 90.8% · Observed by clause.watch

Structured Summary

1. No apparent contractual or privacy-policy amendments
  • The diff does not show changes to contractual terms, customer agreements, terms of service, data-processing terms, or the Privacy Policy text.
  • “Privacy Policy,” “DPO,” “Control Your Data,” and “Cookie Settings” remain navigation links rather than amended legal provisions.
  • The page appears to be a Bloomreach website/page-rendering or routing change, including a “404” page and substantial replacement of navigation and JavaScript content.
2. AI products and messaging

New or prominent website references include:

  • “Loomi AI”
  • “Marketing Agent”
  • “Shopping Agent”
  • “AI-powered Shopping Assistant”
  • “Autonomous Marketing”
  • “Autonomous Search”

These appear to be product descriptions and marketing labels, not legal commitments governing customer data. They do not expressly state that customer data is used to train AI models, nor do they impose restrictions on such use.

3. Customer data used to train AI models
  • No express change was identified concerning the use of customer data to train, fine-tune, evaluate, or improve AI models.
  • The diff contains no language granting or removing a license to use customer data for AI training.
  • It also contains no apparent change to:
  • opt-in or opt-out rights;
  • requirements to anonymize or de-identify data;
  • restrictions on using customer content or personal data in shared models;
  • model ownership or output rights; or
  • deletion, retention, or customer-specific model-isolation obligations.

Risk: The absence of a visible change does not establish that Bloomreach will not use customer data for AI-related purposes. Any relevant rights may exist in the linked Privacy Policy, product terms, order form, or data-processing agreement, which are not included in this diff. Those documents should be reviewed separately.

4. Analytics and tracking changes

The replacement code includes functionality that may process website visitor or form-interaction data, including:

  • forwarding experiment events to Hotjar when analytics cookies are accepted;
  • HubSpot form callbacks and submission tracking;
  • pushing form, navigation-click, performance, and experiment data to a data layer;
  • cookie-based analytics checks and prefetching of internal links.

These changes may increase or clarify website analytics and third-party tracking, but they do not state that the collected data is used to train AI models.

5. Operational and legal risks
  • The apparent 404/page-content issue could cause users to encounter incorrect or incomplete notices, consent controls, or privacy links.
  • Tracking implementations should be checked against applicable consent requirements, disclosures, vendor arrangements, and data-minimization obligations.
  • The malformed or heavily altered JavaScript may create accessibility, functionality, or consent-management defects.

2026-08-18 · Terms of Service

shrank 93.8% · Observed by clause.watch

Summary

The provided diff states only that “approximately 15 words” were added, but it does not show the actual wording of those additions.

Legal and Commercial Impact

  • No substantive changes can be identified from the information provided.
  • It is not possible to determine whether the added language affects:
  • Customer rights or obligations
  • Fees, renewals, termination, or liability
  • Confidentiality or data security
  • Intellectual property ownership
  • Use of customer data
  • Service-provider permissions or restrictions

AI Training and Customer Data

The diff does not disclose whether the added language:

  • Permits the provider to use customer data, prompts, outputs, or usage information to train, fine-tune, evaluate, or improve AI models;
  • Restricts such use to aggregated, de-identified, or anonymized data;
  • Requires customer consent or provides an opt-out;
  • Allows subcontractors or third-party AI providers to use customer data;
  • Grants the provider ownership or broad usage rights in customer content; or
  • Requires deletion or return of data used for AI-related purposes.

Accordingly, no conclusion can be reached about whether the contract’s AI-training provisions became more permissive or restrictive.

Risk Assessment

Assessment: Unable to determine. The actual 15 added words are necessary to evaluate the legal effect and identify any new risk.

2026-08-18 · Privacy at Bloomreach

shrank 90.4% · Observed by clause.watch

Summary of Changes

Scope of the Diff

The diff indicates that approximately 3,854 words were removed from the document. However, the deleted language is not provided, so the specific contractual changes cannot be reliably analyzed.

Key Legal Implications

  • Material terms may have been removed. The deletions could affect obligations relating to payment, confidentiality, data protection, intellectual property, warranties, liability limits, termination, audit rights, or dispute resolution.
  • Risk allocation may have changed. Removing indemnities, disclaimers, security commitments, or liability limitations could materially increase either party’s exposure.
  • Customer protections may have been reduced. Deleted service levels, data return/deletion requirements, restrictions on subcontractors, or compliance obligations could weaken the customer’s position.
  • Provider obligations may have been reduced. Conversely, deletions could remove limitations on the provider’s use of data or operational flexibility.

AI Training and Customer Data

The available diff does not identify whether any language concerning AI models or training was added, removed, or changed. In particular, it is not possible to determine whether the document now:

  • Permits or prohibits using customer data, prompts, outputs, or metadata to train AI models;
  • Limits training to aggregated, de-identified, or anonymized data;
  • Requires customer consent or provides an opt-out;
  • Allows use of customer data to improve services or third-party models;
  • Restricts human review or disclosure of customer content;
  • Provides deletion, retention, or model-unlearning commitments; or
  • Allocates ownership of training data, inputs, outputs, or model improvements.

Recommended Review

The full prior and revised versions should be compared, with particular attention to sections titled:

  • Data Use and Privacy
  • Confidentiality
  • Artificial Intelligence or Machine Learning
  • Intellectual Property
  • Security and Data Retention
  • Service Improvement
  • Subprocessors
  • Liability and Indemnification

Until the deleted text is available, no definitive conclusion can be reached regarding the legal or commercial effect of the changes, including any impact on customer-data training rights.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free