Monitored company
Salsify
clause.watch tracks 2 legal documents published by Salsify, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview
*This is a plain-English summary, not legal advice. The policy appears to omit some detailed lists—particularly under “legitimate interests” and “Your Rights”—so users may need to consult the linked pages or request clarification.*
1. Data Collection and Use
Salsify may collect:
- Information you provide: name, email, address, company, country, job title, phone number, account information, feedback, customer-service communications, and public-forum posts.
- Customer account information: the above details, plus voice recordings and information voluntarily provided during calls.
- Third-party business information: professional contact details obtained from purchased databases, company websites, professional networks, press releases, partners, or event organizers.
- Event/webinar information: contact details, company, emergency contacts, dietary preferences, health and safety information, and billing or credit-card information.
- Automatically collected data: IP address, browser and ISP details, timestamps, referring and exit pages, pages clicked, and other browser-provided information. Cookies and similar technologies may also be used.
Purposes include:
- Providing and supporting Salsify products and services;
- Managing customer accounts and responding to inquiries;
- Marketing, advertising, and tailoring communications;
- Updating and analyzing business records and identifying prospective customers;
- Organizing events and webinars;
- Website operation, security, fraud prevention, and analytics;
- Legal compliance, dispute handling, and enforcement of terms.
Salsify relies on contract performance, legitimate interests, consent, and legal obligations. Strictly necessary cookies are always enabled; other cookies require a preference choice, which can later be changed.
2. User Rights
Depending on location, users may have rights to:
- Access or obtain a copy of their data;
- Correct inaccurate information;
- Delete information;
- Restrict or object to certain processing;
- Withdraw consent;
- Request data portability;
- Opt out of marketing communications; and
- Lodge a complaint with a data-protection regulator.
The policy says these rights may be limited by law or legitimate interests, but it does not provide a complete rights list in the text supplied.
California residents receive additional rights to know categories and specific pieces of data, request deletion or correction, appoint an authorized agent, and avoid discrimination for exercising privacy rights. Requests may be submitted through Salsify’s privacy request portal or by mail. Salsify generally acknowledges requests within 10 business days and responds within 45 days, with a possible extension to 90 days after notice.
3. Third-Party Sharing
Data may be shared with:
- Salsify affiliates;
- Service providers performing hosting, analytics, marketing, support, payment, or similar services;
- Business partners involved in jointly offered products or services;
- Event sponsors and participating vendors;
- Authorities or other parties for legal compliance, security, fraud prevention, or protection of rights and safety; and
- A successor entity in a merger, acquisition, sale, or change of control.
Partners and event sponsors may use data under their own privacy policies, creating potential additional uses outside Salsify’s direct control. The policy states that Salsify does not “sell” or “share” covered data under the CCPA’s defined terms, but it may still disclose information to partners and sponsors in specified circumstances.
4. AI/ML Training
The policy does not state that personal data is used to train artificial-intelligence or machine-learning models, nor does it expressly prohibit such use. Users should seek clarification, especially regarding customer communications, public-forum posts, call recordings, analytics data, and information provided to service providers.
5. Key User Obligations and Risks
- Users should avoid posting confidential or sensitive information in public forums or communications.
- Users under 18 should not use the Site; the Site is not intended for them.
- Users are responsible for reviewing third-party websites, advertisements, partner policies, and event-sponsor practices.
- Marketing may rely on consent or legitimate interest, so users may need to actively opt out.
- Data may be transferred internationally, including to the United States, using safeguards such as Standard Contractual Clauses.
- Salsify retains data as long as needed for stated purposes or legal compliance; backups may remain securely stored after deletion is otherwise requested.
6. Liability and Disputes
This Privacy Policy contains no detailed dispute-resolution procedure, governing-law clause, arbitration requirement, or specific liability cap. It also states that absolute security cannot be guaranteed. Any contractual liability limits or dispute terms may instead appear in Salsify’s Terms of Use, customer agreement, or service contract.
7. Policy Changes
Salsify may change the policy at its discretion. The latest update date appears on the Site. Material changes may receive notice when appropriate, but—unless legally required—changes apply immediately when posted. Users should periodically review the policy and linked cookie and provider notices.
Terms of Service
Salsify Terms of Service — User-Focused Overview
*This is a business-to-business agreement governing Salsify’s cloud solutions. It is not a complete privacy policy. Privacy-specific details and individual rights are primarily deferred to Salsify’s separate Data Processing Addendum (“DPA”) and applicable Privacy Laws.*
1. Data Collection & Usage
Data Salsify may process
- Customer Content: Any data or information the customer uploads or makes available through the Solutions. This may include product information, business data, files, and potentially personal information.
- Personal Information: Information identifying a natural person—such as a name, identification number, or location data—processed by Salsify as a processor.
- Usage Data: Technical and log information, including IP address, browser type, internet service provider, timestamps, referring and exit pages, and pages clicked.
- Aggregated Data: Technical or other data derived from use of the platform and aggregated or deidentified.
Permitted uses
The customer gives Salsify a worldwide, royalty-free, sublicensable license during the contract term to host, reproduce, display, distribute, perform, and modify Customer Content, but only to provide and operate the Solutions and related Salsify products, services, and technologies.
Salsify may use Usage Data and deidentified Aggregated Data to develop, analyze, improve, support, and operate its products and services. The agreement does not clearly promise that all supposedly deidentified data can never be reidentified.
Salsify states that it maintains commercially reasonable security measures. The detailed security commitments are located at an external security webpage, and privacy processing terms are in the separate DPA.
2. User Rights
The agreement does not provide a detailed list of individual data rights—such as access, correction, deletion, portability, objection, or restriction.
Those rights and procedures are expected to be addressed through:
- Applicable Privacy Laws; and
- The separate DPA.
The customer, rather than individual Authorized Users, generally controls the relationship with Salsify. Customers should confirm that the DPA covers applicable GDPR, UK GDPR, U.S. state privacy laws, breach notification, international transfers, subprocessors, and assistance with data-subject requests.
After termination, Salsify retains Customer Content for 30 days, during which the customer may export or request delivery of it. Salsify states it will delete the content after that period.
3. Third-Party Sharing
If the customer enables third-party apps, integrations, implementation providers, or other Third-Party Services:
- Salsify may allow the provider to access and use Customer Content as needed for interoperability.
- Data may be transmitted, transferred, modified, deleted, or stored on the third party’s or its vendors’ systems.
- The third party’s separate agreement governs its handling of the data.
- Salsify disclaims responsibility for the third party’s privacy, security, availability, support, or acts and omissions.
This is a significant risk: enabling an integration may expand the data-access chain beyond Salsify’s direct control.
Salsify may also disclose confidential information to employees, contractors, service providers, advisors, and others with a need to know, subject to confidentiality obligations, or when legally required.
4. AI/ML Training
Salsify and its subcontractors will not use Customer Content to train AI models supporting Salsify’s AI-Powered Capabilities without the customer’s prior permission.
Exception: Salsify may use Customer Content to train a model isolated solely for that customer’s use.
AI access may be provided if purchased, if the customer does not opt out after reasonable notice to administrators, or if administrators opt in. Administrators should monitor notices and explicitly opt out where appropriate.
The customer owns Generated Output, but outputs may not be unique. The customer is solely responsible for checking accuracy, completeness, suitability, and legal or regulatory compliance. Salsify disclaims liability for Generated Output, and human review is required before relying on it for regulated or legally important purposes.
5. Key Obligations and Restrictions
The customer must:
- Use the Solutions only for internal business purposes and within purchased entitlements.
- Ensure Affiliates and Authorized Users comply; the customer is responsible for their conduct.
- Review all content for accuracy, completeness, legality, and compliance before exporting or publishing it.
- Own or obtain all rights, permissions, and consents for uploaded content and personal data.
- Pay fees, including possible overage charges; annual fees are generally billed in advance and nonrefundable.
The customer may not reverse engineer, resell, commercially exploit, scrape, benchmark for competitive purposes, disrupt the service, upload malware, or submit unlawful or infringing content.
6. Liability and Disputes
- Services are generally provided “as is”, with limited warranties.
- Salsify does not guarantee uninterrupted, error-free, secure, accurate, or complete service.
- Neither party is liable for indirect, consequential, punitive, special damages, lost profits, revenue, data, or business interruption, subject to stated exceptions.
- General liability is capped at fees paid or payable for the relevant order during the prior 12 months.
- For certain Salsify data-security/privacy breaches causing unauthorized access, the cap increases to five times that amount.
- The customer indemnifies Salsify for claims involving Customer Content, customer products, or misuse of the Solutions. Salsify provides narrower intellectual-property indemnity.
Disputes are governed by Delaware law and must be brought exclusively in state or federal courts in Wilmington, Delaware.
7. Changes and Renewal
The agreement may be amended only by a written document signed by both parties. However:
- Orders automatically renew annually unless either party gives non-renewal notice at least 60 days before term end.
- Salsify may change renewal pricing or add fees with at least 90 days’ notice, by email or through the platform.
- Salsify may continuously develop or modify features; additional functionality may incur additional fees.
Practical takeaway: review the DPA, external support/SLA/security policies, Order/SOW, integration terms, and renewal notices carefully.
Change history
2026-09-06 · Terms of Service
2026-09-05 · Terms of Service
2026-09-01 · Terms of Service
2026-08-31 · Terms of Service
2026-08-30 · Terms of Service
2026-08-29 · Terms of Service
Structured Summary of Important Changes
1. Cookie Consent and Tracking
- The revised text adds a more complete cookie-consent interface:
- Users may “choose which cookies to accept.”
- New options include “Manage Preferences,” “Accept,” and “Decline.”
- The notice directs users to Cookie Settings for information about the types of cookies used.
- The earlier wording merely stated that cookies were used to provide a better user experience and primarily offered an acceptance statement.
- Legal significance: This appears intended to strengthen consent and transparency practices, potentially supporting requirements under laws such as the GDPR, UK GDPR, ePrivacy rules, and certain U.S. state privacy laws.
- Risk: The diff only changes the website language. It does not establish whether:
- non-essential cookies are blocked before consent;
- consent is granular and freely given;
- consent can later be withdrawn;
- cookie vendors, purposes, retention periods, or international transfers are disclosed; or
- “Decline” is as easy to use as “Accept.”
- The cookie notice is repeatedly inserted into site content, creating a risk of confusing or defective user-facing disclosures if implemented literally.
2. New Agentic Commerce and AI Marketing Content
The revised page adds or emphasizes:
- “Agentic Commerce” and AI-powered shopping;
- autonomous agents using deep PXM data to compare, recommend, and purchase products;
- use of product data to improve AI-driven visibility and performance across the omnichannel;
- references to AI-fueled growth and an “Agentic Shelf.”
These changes are primarily marketing and educational claims rather than operative contractual terms.
3. Customer Data Use and AI Model Training
- No express provision is added stating that customer data may be used to train, fine-tune, evaluate, or improve AI models.
- The new language refers to “deep PXM data” being used by autonomous agents for product comparisons, recommendations, and purchases. This describes a product or commercial use case, but it does not clearly authorize training on customer data.
- The diff also does not clarify:
- whether customer content is used only to provide the service or also for generalized model improvement;
- whether data is aggregated, anonymized, or de-identified;
- whether data is shared with model providers or other customers;
- ownership of inputs, outputs, or trained models;
- opt-out rights; or
- confidentiality and security protections for AI processing.
Risk: If the underlying agreement or privacy policy separately permits broad AI training, these new marketing references could make the scope of data use appear broader or less controlled. The contract should expressly distinguish service-generated AI processing from training or product-improvement use.
4. Overall Contract Risk
The diff substantially changes website messaging and cookie disclosures but does not appear to amend clear contractual rights or obligations. The main legal concern is ambiguity: AI-related data use is promoted, while safeguards and training limitations remain unstated.
2026-08-29 · Privacy Policy
No
2026-08-29 · Terms of Service
2026-08-28 · Terms of Service
2026-08-28 · Privacy Policy
2026-08-27 · Privacy Policy
2026-08-26 · Privacy Policy
2026-08-26 · Privacy Policy
2026-08-23 · Privacy Policy
2026-08-21 · Privacy Policy
2026-08-20 · Terms of Service
Between 2025-07-04 and 2025-09-15 · Terms of Service
Between 2022-06-28 and 2024-04-02 · Privacy Policy
2023-03-29 · Privacy Policy
The publisher records this document as revised on this date (“Last Modified: March 29, 2023”).
Between 2014-09-19 and 2022-06-28 · Privacy Policy