clause.watch Contracts Recent changes Start monitoring

Monitored company

Squareup

clause.watch tracks 2 legal documents published by Squareup, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Notice

32,435 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Terms of Service

51,858 characters · Read the original

Square Privacy Notice: Key Points and Risks

> Scope: This is primarily a Privacy Notice, not a complete Terms of Service. It explains data practices but does not set out most contractual rules, fees, indemnities, arbitration terms, or service liability provisions.

1. Data Collection & Usage

Square may collect:

  • Identity data: Name, email, address, phone number, signature, government ID, Social Security/Taxpayer ID, passport or driver’s-license details.
  • Sensitive verification data: Photo ID, facial scans, biometric information, proof of address, and financial statements where needed.
  • Financial and tax data: Bank-account details, payment-card numbers, tax status, and withholding information.
  • Contact data: Payment recipients’ contact details and, if you permit it, contacts uploaded from your phone.
  • Usage and device data: IP address, cookies, device identifiers, browser and operating-system details, login information, precise location, and activity on Square websites, apps, and hardware.
  • Business and employee data: Inventory, appointments, staffing, payroll, job titles, and timecard information.
  • Customer data: Names, contact details, payment information, transaction details, item-level purchases, device/location data, communications, and notes entered by a seller.
  • External data: Credit reports, identity-verification information, employment/financial relationships, fraud signals, and compliance information.

Square uses this information to:

  • Create and operate accounts and process payments.
  • Verify identity and comply with AML/KYC, sanctions, tax, and other legal obligations.
  • Prevent fraud, investigate security incidents, manage chargebacks, and collect fees.
  • Provide support, notices, statements, and marketing.
  • Personalize and improve services, conduct analytics, develop products, and create aggregated/deidentified economic reports.
  • Determine geographic eligibility and customize language or services.

Risk: Square may retain account and usage data for the life of the account and longer where needed for legal compliance, fraud prevention, contract enforcement, or legal claims.

2. User Rights and Choices

Depending on location, users may request:

  • Access to personal information and a portable copy.
  • Correction of inaccurate information.
  • Deletion, subject to legal and operational exceptions.
  • Restriction or cessation of processing, objection to profiling, and data portability under EU/UK law.
  • Withdrawal of consent where processing relies on consent.
  • Opt-out of targeted advertising or “sale/share” of data under applicable U.S. laws.
  • Limits on the use or disclosure of sensitive personal information, including under California law.
  • Deactivation of the account.

Requests can generally be submitted through privacy.block.xyz or, in some cases, by phone. Square may verify your identity before responding.

You may disable location access, manage cookies, and opt out of promotional communications. However, disabling location or cookies may impair functionality. Transactional and account-related communications will continue.

3. Third-Party Sharing

Square may share information with:

  • Identity-verification vendors, credit bureaus, wireless carriers, fraud-prevention providers, and compliance providers.
  • Analytics providers such as Google Analytics, Facebook, BugSnag, and Crashlytics.
  • Advertising and marketing partners for interest-based or targeted advertising.
  • Business partners and referral partners, including limited account activation or transaction-volume information for referral-fee reporting.
  • Square affiliates and Block companies, including Cash App, Afterpay/Clearpay, TIDAL, and Square Financial Services.
  • Other users involved in payments, appointments, transfers, or franchise accounts.
  • Government agencies, law enforcement, courts, creditors, and regulators when legally required or reasonably necessary to protect rights, property, security, or the public.
  • Buyers or successors in mergers, sales, restructurings, or financing transactions.

Square says it does not “sell” personal information in the ordinary sense, but acknowledges that Usage Data may have been “sold or shared” under California law for targeted advertising.

4. AI/ML Training

The notice states that Square may use commercial or other personal information you provide, or ask Square to analyze, with artificial-intelligence technologies to generate personalized business features.

It does not clearly state that user data is used to train general-purpose AI models, nor does it provide a specific opt-out from AI processing. Users should therefore not assume that information submitted to Square tools or chatbots is excluded from AI-related processing.

5. Key User Obligations

Sellers are responsible for:

  • Providing accurate information and completing identity/compliance checks.
  • Obtaining necessary permissions to provide and use customer data through Square.
  • Using customer and employee information lawfully.
  • Protecting account credentials and complying with Square’s separate Terms of Service and product rules.
  • Obtaining consent where required for contacts, location, marketing, or other processing.

6. Liability & Disputes

This notice says Square uses reasonable security safeguards but does not guarantee absolute security. It acknowledges risks of hacking, unauthorized access, and interception.

It contains no meaningful dispute-resolution procedure, governing-law clause, arbitration requirement, indemnity, warranty disclaimer, or limitation of damages. Those terms must be reviewed in Square’s separate Terms of Service and product agreements.

7. Changes

Square may revise the Privacy Notice and update its effective date. For material changes to how information is used, it says it will provide reasonable prior notice, potentially by email. If users disagree, they may cancel their account, although cancellation may not immediately eliminate legally retained data.

Change history

2026-09-05 · Terms of Service

shrank 10.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-05 · Terms of Service

grew 12.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-04 · Privacy Notice

shrank 16.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-03 · Privacy Notice

grew 19.2% · Observed by clause.watch

No

2026-09-02 · Privacy Notice

shrank 16.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Terms of Service

shrank 10.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Privacy Notice

grew 19.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Terms of Service

grew 12.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Privacy Notice

shrank 16.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-31 · Privacy Notice

grew 19.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-30 · Terms of Service

shrank 10.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-30 · Privacy Notice

shrank 16.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-29 · Privacy Notice

grew 19.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-29 · Terms of Service

grew 12.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-29 · Privacy Notice

shrank 16.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-28 · Privacy Notice

grew 19.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-28 · Terms of Service

shrank 10.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-27 · Privacy Notice

grew 1038.5% · Observed by clause.watch

Summary of Important Changes and Risks

1. Major restructuring and scope expansion

  • The prior text was primarily a cookie-consent banner covering analytics, advertising, personalization, and sharing with ad partners.
  • The replacement is a comprehensive “General Privacy Notice for Square Sellers” covering:
  • Website visitors;
  • Sole proprietors and businesses applying for or using Square Services;
  • Certain consumers who provide information to Square, use Square Pay, receive digital receipts, or sign up for marketing.
  • Consumers shopping at Square-enabled businesses are directed to a separate privacy notice, creating a more complex, cross-referenced privacy framework.

Risk: Important terms are moved from a short cookie notice into a broad privacy notice, potentially expanding the purposes and categories of processing beyond what users previously saw.

2. Expanded categories of data

The new notice expressly covers:

  • Financial data, including bank account and payment-card information;
  • Tax information;
  • Government identification, including passports, driver’s licenses, Social Security numbers, and taxpayer identification numbers;
  • Precise geolocation;
  • Device, online activity, cookie, and advertising data;
  • Employee and payroll information;
  • Contacts uploaded from a mobile device;
  • Survey responses, chatbot disclosures, referrals, and support-related information;
  • In some cases, photographs, facial scans, and extracted biometrics.

Risk: Processing and sharing facial scans and biometric information creates heightened privacy, consent, security, retention, and regulatory exposure. The notice does not appear to provide detailed biometric-specific retention or deletion rules in the supplied text.

3. Expanded sharing and profiling

Square may share data with:

  • Identity-verification, credit-reporting, fraud-prevention, analytics, advertising, and other service providers;
  • Affiliates, including Cash App, Afterpay/Clearpay, and TIDAL;
  • Referral partners, including transaction-volume information;
  • Potential business partners and corporate transaction participants.

Square may combine transaction, identity, risk, usage, and profile information for identity verification, fraud prevention, personalization, product development, and marketing.

Risk: Cross-service sharing and profiling may create broader secondary uses and increased exposure to inaccurate inferences or automated decisions.

4. AI-related changes

The new notice expressly states that Square may use:

  • Commercial Information; and
  • Other personal information that the user inputs or asks Square to analyze

“in connection with artificial intelligence technologies” to generate personalized business features.

The stated legal bases are contract performance and legitimate interests, including improving and personalizing Services in ways Sellers reasonably expect.

The notice also includes information voluntarily disclosed to Square chatbots.

Training analysis: The supplied language does not expressly say that customer data will be used to train general-purpose AI models, nor does it clearly prohibit such training. However, the wording is broad enough to permit AI analysis and potentially model improvement unless another policy or contract limits it. Customer data appears otherwise usable only to provide requested Services, as disclosed in the separate consumer notice, or as instructed by customers. This distinction should be clarified, especially regarding model training, retention, human review, and use of identifiable customer data.

5. Customer-data responsibility

Square may process “Your Customers’ Data” as a service provider to deliver requested Services. The seller is expressly responsible for obtaining any permissions necessary for Square’s use of that data.

Risk: This shifts consent and compliance responsibility to the seller, including for customer data used in AI-enabled features.

2026-08-27 · Privacy Notice

shrank 92.6% · Observed by clause.watch

Summary of Important Changes

1. Privacy Notice Replaced by Cookie-Consent Content

The diff appears to replace substantial portions of the prior Privacy Notice with a cookie-consent interface and Cookie Policy references. The revised text focuses on website cookies, rather than clearly presenting the full prior disclosures about collection, use, retention, sharing, international transfers, and user rights.

Risk: This may make important privacy terms less visible or potentially create uncertainty about which document governs. Confirm that the complete Privacy Notice remains available and that the cookie banner does not inadvertently replace legally required privacy disclosures.

2. Expanded Cookie and Tracking Activities

The new language states that Square and its partners use cookies and similar technologies to:

  • Maintain security and website functionality;
  • Measure performance and analyze usage;
  • Personalize the user experience;
  • Personalize and deliver advertising;
  • Track activity across websites;
  • Measure advertising campaigns, conversions, and ad frequency; and
  • Support ad billing.

It also expressly permits disclosure of data to analytics partners and advertising partners for these purposes.

Users are offered “Accept all,” “Reject all” (except strictly necessary cookies), and category-level controls. Strictly necessary cookies are always active, while performance, functional, and targeting/advertising cookies are initially inactive.

Risks:

  • Broader sharing with analytics and advertising partners;
  • Cross-site tracking and interest-based advertising;
  • Potential regulatory exposure if consent is not freely given, sufficiently informed, granular, and properly recorded;
  • The wording “by accepting these cookies, you consent” may not be sufficient in jurisdictions requiring specific consent standards.

3. Broader Scope of Covered Services

The language changes references from visiting the “website” to interacting with Square’s broader “services,” including online services, mobile applications, and potentially hardware or other Square offerings.

Risk: The cookie and tracking disclosures may now apply across a wider range of products and interactions than before.

4. AI-Related Data Use

The underlying privacy language states that Square may use:

  • Commercial Information; and
  • Other personal information that users input or request Square to analyze

“in connection with artificial intelligence technologies” to generate personalized business features. It also permits technology providers to operate automated systems, including AI technologies, to help provide the Services.

Important limitation: The diff does not expressly state that customer data will be used to train AI models, nor does it grant a clearly defined right to use data for model training, generalized model development, or sharing data with AI model providers for training.

However, the wording is broad enough to permit AI-based analysis and personalization, and potentially service-provider processing. It does not clearly explain whether inputs are retained, used to improve models, de-identified, or excluded from training datasets.

Recommended clarification: Square should expressly state whether Seller or customer data may be used to train or improve AI models, identify the data covered, describe retention and human access, and provide opt-out or consent mechanisms where required.

2026-08-26 · Privacy Notice

grew 19.2% · Observed by clause.watch

Summary of Changes

Overall change
  • Approximately 5,545 words were removed from the document.
  • No replacement language or added language is shown.
  • Because the actual deleted text is not provided, it is not possible to determine which contractual rights, obligations, limitations, or protections were removed.
Potential legal significance

A deletion of this size may materially affect:

  • Data ownership and permitted uses
  • Confidentiality and security obligations
  • Intellectual-property rights
  • Service warranties and disclaimers
  • Liability limits and indemnities
  • Termination rights and data-return/deletion obligations
  • Audit, compliance, and regulatory provisions
  • Governing law and dispute-resolution terms
  • Customer remedies and provider obligations

The deletion should not be treated as merely editorial unless the removed provisions have been reviewed individually.

AI-model training and data use
  • The provided diff does not identify whether any language concerning AI-model training was added, removed, or modified.
  • In particular, the available information does not show whether the contract now:
  • Permits or prohibits using customer data to train, fine-tune, or improve AI models;
  • Distinguishes between customer content, prompts, outputs, telemetry, or aggregated/de-identified data;
  • Requires customer consent or provides an opt-out;
  • Limits use to service improvement or permits broader commercial use;
  • Applies different rules to human review, subcontractors, or third-party AI providers; or
  • Requires deletion or segregation of data used for model training.
Key risk

If the deleted text contained restrictions on AI training or secondary data use, its removal could broaden the provider’s ability to use customer data. Conversely, if the deleted text granted such rights, its removal could restrict that use. The direction of the risk cannot be determined from the redacted diff alone.

Recommended follow-up

Obtain:

1. The full prior and revised versions; and

2. A redline showing the actual deleted provisions.

The AI/data-use clauses should be reviewed specifically for express language addressing training, fine-tuning, model improvement, retention, de-identification, aggregation, human review, and third-party model providers.

2026-08-25 · Privacy Notice

shrank 16.1% · Observed by clause.watch

Summary

Key Limitation

The supplied diff states only:

> “Added approximately 4606 words to the document”

It does not include the actual added contractual language, deleted language, or replacement text. As a result, it is not possible to identify the legal or commercial effect of the changes reliably.

AI Training and Customer Data

No conclusions can be drawn about whether the new language:

  • Permits the provider to use customer data to train, fine-tune, test, or improve AI models;
  • Restricts training to de-identified, aggregated, or anonymized data;
  • Allows use of prompts, inputs, outputs, metadata, usage data, or personal information for model development;
  • Gives the provider ownership or license rights in customer data or AI-generated outputs;
  • Allows data to be shared with affiliates, subprocessors, or third-party model providers;
  • Provides an opt-out or requires the customer’s prior consent;
  • Requires deletion or exclusion of customer data from training datasets; or
  • Creates confidentiality, security, privacy, or regulatory risks associated with AI processing.

Other Legal Risks That Cannot Yet Be Assessed

The missing text prevents review of possible changes involving:

  • Intellectual-property ownership and licensing;
  • Confidentiality and permitted disclosures;
  • Data protection and international transfers;
  • Security obligations and breach notification;
  • Subprocessors and third-party services;
  • Warranties, indemnities, and limitations of liability;
  • Retention, deletion, and return of data;
  • Audit rights and compliance obligations;
  • Suspension, termination, and post-termination access; and
  • Changes to governing law, dispute resolution, or renewal terms.

Required Information

Please provide the actual redline text, including:

1. The added provisions;

2. Any deleted provisions;

3. Replacement language showing both the old and new text; and

4. The surrounding section headings or clause numbers.

Once provided, the changes can be analyzed for their practical effect, with particular focus on whether customer data may be used to train or improve AI models and whether the customer has meaningful controls over that use.

2026-08-25 · Terms of Service

grew 12.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-24 · Privacy Notice

grew 19.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-24 · Terms of Service

shrank 10.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-24 · Privacy Notice

shrank 16.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-23 · Privacy Notice

grew 19.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-23 · Terms of Service

grew 12.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-23 · Privacy Notice

shrank 16.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-22 · Privacy Notice

grew 19.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-22 · Terms of Service

shrank 10.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free