Monitored company
Paddle
clause.watch tracks 2 legal documents published by Paddle, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy
Privacy Policy Overview
1. Data Collection and Use
Paddle may collect or generate personal data when you:
- Purchase digital products or use Paddle’s sites/services
- Register for an account or interact with Paddle
- Communicate with Paddle or post publicly about it
- View or interact with advertising, content, cookies, or similar technologies
- Deal with Paddle as a customer, supplier representative, job applicant, visitor, or employee representative
- Provide data through third parties
Types of data collected
Depending on your relationship with Paddle, this may include:
- Identity and contact data: names, online identifiers, IP address, passport, driver’s licence, and—in some cases—social security or national identification numbers
- Demographic and background data: gender, date of birth, nationality, language, education, employment and professional history
- Purchase and financial data: order history, prices, billing address, payment method, card/account identifiers, payment dates and amounts
- Device and usage data: device type, operating system, browser, login/security details, connection times, IP address, browsing and usage information
- Advertising data: ads or content viewed, clicks, mouse/touch interactions, and partially completed forms
- Location and delivery data: geolocation and consignee details
- CCTV and visitor records
- Sensitive data: potentially health, criminal, biometric, political, religious, racial/ethnic, trade-union, or national-identification information if legally necessary or provided
Paddle uses data to process purchases, provide services, operate its business, comply with law, perform identity and sanctions checks, prevent fraud, manage security and IT, communicate and market—including behavioural advertising—improve services, recruit employees, and handle legal claims.
Paddle states that it does not sell personal data, although certain cookies or advertising technologies may legally count as “selling” or “sharing” under California law.
2. User Rights
Rights depend on your location and applicable law. Potential rights include requesting access to, correction of, deletion of, or information about the use of your data, and objecting to certain processing. The policy’s supplied text does not provide the full detailed list of EEA rights, so users should confirm the exact rights available in their jurisdiction.
California residents may also have rights to:
- Opt out of the sale or sharing of personal information
- Limit use and disclosure of sensitive personal information
- Avoid discrimination for exercising privacy rights
- Appeal a denied request
- Use an authorised agent
Requests can be submitted through https://preferences.paddle.com. Paddle may require identity verification and, for an authorised agent, proof of authority.
3. Third-Party Sharing and International Transfers
Paddle may share data with:
- Paddle group companies
- Third-party service providers processing data for Paddle
- Payment, fraud-prevention, credit-reference, compliance, security, advertising, IT, and other business providers
- Law-enforcement, regulators, or other parties where legally required or necessary for legal claims
Processors must be subject to contractual obligations. However, data may be transferred to countries with weaker or different privacy protections, including countries where authorities may access data. For UK/EEA transfers to non-adequate countries, Paddle says it uses Standard Contractual Clauses and other safeguards.
The specific categories or names of third parties are not fully set out in the provided Section E, which limits transparency.
4. AI/ML Training
The policy does not state whether personal data is used to train artificial-intelligence or machine-learning models. It refers generally to improving sites, products, and services, but that wording should not be assumed to authorize AI training. Users seeking certainty should ask Paddle directly.
5. Key User Obligations and Restrictions
- You must ensure you are legally permitted to provide any sensitive personal data to Paddle.
- You should avoid sending unnecessary sensitive information.
- Paddle says it is not responsible for the security of the method you use to transmit data to it.
- You are responsible for managing cookie choices; non-essential cookies may be used for analytics, advertising, and marketing, generally with consent where required.
6. Liability and Disputes
The notice describes security measures but disclaims responsibility for the security of how users transmit data to Paddle. It does not provide a comprehensive liability cap, warranty disclaimer, governing-law clause, arbitration requirement, or dedicated privacy-dispute procedure.
Data may be retained for the relationship’s duration, legal limitation periods, and while claims or investigations continue. Users may complain to an applicable data-protection regulator, including a state regulator in California.
7. Changes to the Policy
Paddle may amend the notice for changes in law or processing practices and encourages users to check it regularly. For material changes, Paddle says it will provide notice and seek consent where legally required. It does not promise individual notice for every change, so periodic review is important.
Terms of use
Paddle Master Services Agreement: Key User Terms and Risks
> Scope: This agreement is primarily for businesses (“Suppliers”) using Paddle to resell software or digital products. It incorporates Paddle’s separate Privacy Policy, Data Sharing Addendum, Acceptable Use Policy, Buyer Terms, and terms for optional services. Those documents may contain important additional provisions.
1. Data Collection & Usage
Paddle may collect:
- Supplier and business information, including financial status, creditworthiness, business activities, shareholders and ultimate beneficial owners.
- Product information, such as descriptions, pricing, tax classification, URLs, and other information requested by Paddle.
- Account and transaction information, including sales, payments, refunds, chargebacks, currencies, and amounts due.
- Buyer personal data, which is shared between Paddle and the Supplier to provide checkout, fulfilment, customer support, refunds, tax handling, and related services.
- Information submitted or accessed through the Supplier Account.
Paddle and the Supplier are stated to be independent data controllers, rather than processor and controller. Each must comply with applicable data protection laws and the Data Sharing Addendum. Paddle promises administrative, physical, and technical safeguards, but the agreement does not specify detailed retention periods, international transfer mechanisms, or all processing purposes. Those details are left primarily to the incorporated Privacy Policy and Data Sharing Addendum.
2. User Rights
The agreement itself does not list specific data-subject rights such as access, correction, deletion, portability, restriction, or objection.
Those rights will depend on applicable law—particularly the UK GDPR—and Paddle’s Privacy Policy and Data Sharing Addendum. Users should review those documents for:
- How to submit privacy requests;
- Which party handles Buyer or Supplier requests;
- Data retention and deletion rules;
- International data transfers;
- Marketing and communications choices; and
- Complaint rights with a data protection regulator.
On termination, Paddle may return or destroy Supplier confidential information, but may retain information where necessary for ongoing subscriptions or legal compliance.
3. Third-Party Sharing
Data may be shared with or disclosed to:
- KYC and verification partners assessing the Supplier and its business;
- Paddle’s affiliate entities, including for payment or self-billing arrangements;
- Payment providers, acquirers, banks, card schemes, and payment-method providers;
- Authorities or regulators where legally required;
- Relevant providers where fraud, excessive refunds, or chargebacks are suspected; and
- Buyers, to facilitate fulfilment, support, and transactions.
Paddle may share information about the Supplier or its accounts with payment providers and card schemes if chargebacks or refunds are excessive. The agreement does not provide a complete list of third parties or a detailed data-sharing schedule; the Data Sharing Addendum and Privacy Policy are essential.
4. AI/ML Training
The agreement contains no express provision stating that Supplier or Buyer data will—or will not—be used to train artificial intelligence or machine-learning models.
Users should not assume that data is excluded from AI training. The Privacy Policy, Data Sharing Addendum, and any product-specific terms should be checked for language concerning analytics, service improvement, automated decision-making, profiling, or model training. If this is commercially sensitive, obtain written clarification from Paddle.
5. Key Obligations and Restrictions
Suppliers must:
- Provide accurate, complete, and current business and product information;
- Give at least 30 days’ written notice of material information changes;
- Comply with applicable law, privacy laws, payment-scheme rules, and Paddle policies;
- Sell only through approved Supplier URLs;
- Clearly identify Paddle as reseller and display the full, unaltered Paddle Checkout;
- Provide product delivery, technical support, and agreed service levels;
- Avoid fraud, unlawful products, excessive chargebacks, and prohibited outbound telemarketing;
- Not issue invoices or demand payment directly from Buyers; refunds must be handled through Paddle; and
- Indemnify Paddle for claims, penalties, taxes, legal fees, and disputes arising from the Supplier’s products, information, or legal noncompliance.
Paddle may reject products, suspend accounts, withhold funds, or terminate immediately based on risk, suspected fraud, policy violations, chargebacks, or third-party rights concerns.
6. Liability, Financial Exposure & Disputes
Paddle may deduct refunds, chargebacks, related fees, fines, and other liabilities from amounts owed to the Supplier, without further notice. Chargebacks can include the full transaction amount, expenses, and a fee of up to 20 GBP/USD/EUR or 40 AUD/CAD.
Paddle may retain funds after suspension or termination to cover future refunds and chargebacks—potentially until six months after termination or expiry of the last subscription.
The Services are provided “as is”, with broad warranty disclaimers. Paddle generally excludes indirect and consequential losses, and its total liability is capped at the Paddle Discounts paid during the preceding six months. Mandatory legal liabilities, such as fraud or death/personal injury caused by negligence, are not excluded.
Disputes are governed by English law, with exclusive jurisdiction in the English courts. The applicable version is the version in effect when the dispute arose.
7. Changes to the Agreement
Changes are:
- Effective immediately for new Suppliers signing up after publication;
- Effective 30 days after publication for existing Suppliers; and
- For material changes, notified by email on or before publication to the Supplier Account address.
Continued use after the 30-day period constitutes acceptance. Suppliers who disagree may terminate under the agreement’s termination procedure. Changes to linked policies and URLs may also occur, so users should monitor those documents and account emails.
Change history
2026-09-06 · Privacy
2026-09-05 · Privacy
2026-09-05 · Privacy
2026-09-04 · Privacy
2026-09-03 · Privacy
2026-09-01 · Privacy
2026-08-30 · Privacy
2026-08-29 · Privacy
2026-08-29 · Privacy
2026-08-26 · Privacy
2026-08-23 · Privacy
2026-08-23 · Privacy
2026-08-22 · Privacy
2026-08-20 · Privacy
2026-08-18 · Privacy
Between 2025-07-13 and 2025-11-13 · Terms of use
No
Between 2025-04-03 and 2025-07-13 · Terms of use
No
Between 2024-10-15 and 2025-04-03 · Terms of use
No
Between 2022-04-09 and 2023-01-28 · Terms of use
No
Between 2022-03-06 and 2022-08-21 · Privacy