Snapshot of the source text at fetch time, not a live mirror of the policy page.
Plain-English summary
The Zendesk Privacy Notice includes several notable clauses regarding data handling and company practices:
* **Non-specific data retention** (risk_flags-1): The company may retain your personal data after the end of your relationship for various business and compliance reasons, without a specified retention period.
* **No 'Do Not Track' signal honor** (risk_flags-2): The service does not honor 'Do Not Track' signals, meaning your online activity may still be tracked across other sites.
* **Broad sharing of identifiers with affiliates and various third parties** (data_use-1): Your personal identifiers such as name, email, and device IDs can be widely shared, including for marketing.
* **Collection and sharing of commercial information** (data_use-2): Commercial and transactional data, including banking details, are collected and may be shared with affiliates and service providers.
* **Collection and sharing of internet activity and device information** (data_use-3): Your online activity and device information are collected and shared, potentially with marketing partners.
* **Collection and sharing of geolocation information** (data_use-4): Your approximate location data can be shared with various parties.
* **Collection and sharing of sensitive personal data** (data_use-5): Sensitive data like proof of vaccination or ethnicity may be collected and shared under certain conditions.
* **Inferences as defined by California law are collected and shared** (data_use-6): The company collects and shares inferences about your marketing preferences.
* **External links may lead to unknown privacy practices** (data_use-7): The company is not responsible for the privacy policies of external sites linked from their services.
* **Company may update privacy notice, user must check for updates and stop interacting if they disagree.** (gotchas-1): You are responsible for staying informed about policy changes and must cease using services if you disagree with updates.
90% confidence
Ask Verbaterm
Follow up on findings with grounded answers from this review. Not legal advice.
Risks
2 findings
Critical issues and red flags: These items often represent material, hard-to-reverse harm. They include money you cannot easily recover, lasting privacy exposure, loss of account access, weakened dispute rights, or broad ownership/control of user content by the service.
high95% confidence
Non-specific data retention
The company may retain your personal data for legitimate business purposes or to comply with legal, tax, or accounting requirements even after you terminate your relationship.
Why it matters: Your personal data may be retained indefinitely by the company after you end your relationship, for reasons such as fulfilling contractual obligations, evidencing business practices, or complying with legal, tax, or accounting requirements.
Once you and/or your company have terminated the contractual relationship with us or otherwise ended your relationship with us, we may retain your personal data in our systems and records to ensure adequate fulfillment of surviving provisions in terminated contracts or for other legitimate business purposes, such as to evidence our business practices and contractual obligations, to provide you with information about our products and services, or to comply with applicable legal, tax, or accounting requirements.
Security and Retention, paragraph 2 · Citation strength: strong
medium95% confidence
No 'Do Not Track' signal honor
This site does not honor 'Do Not Track' (DNT) signals from web browsers.
Why it matters: Activating 'Do Not Track' in your browser will not prevent this company from tracking your device activity across devices and websites.
While some browsers have incorporated Do Not Track or DNT preferences, we do not honor such signals from web browsers at this time.
Cookies and Tracking Technologies, paragraph 1 · Citation strength: strong
Data Use & Sharing
7 findings
Practices concerning the collection, use, and sharing of your personal data. These findings aren't necessarily negative, but refer to broad grants, one-sided terms, or otherwise notable uses of data that you might want to consider.
medium90% confidence
Broad sharing of identifiers with affiliates and various third parties
Identifiers such as name, email, postal address, phone, and device identifiers (e.g., advertising identifiers and IP address) may be shared with affiliates, service providers, third parties for transactions (e.g., credit card processors), business partners, event sponsors, professional advisors, entities involved in corporate transactions, and companies operating cookies and tracking technologies (e.g., marketing and advertising partners).
Why it matters: Your identifying information can be broadly shared with a range of other companies, including for marketing and advertising purposes, which may lead to more targeted ads or communications.
| * Affiliates and subsidiaries within the Zendesk Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Zendesk Group * Service providers, such as security and platform vendors * With third parties that are necessary to complete a transaction, such as credit card processors * Business partners who we partner with to jointly market or sell our products and Services, such as channel partners * With third parties at your direction, such as event sponsors * Professional advisors, such as lawyers, accountants, and auditors * Entities involved in a corporate
Personal Data We Collect and Disclose, paragraph 2 · Citation strength: strong
medium90% confidence
Collection and sharing of commercial information
Commercial information, including purchasing history, tendencies, and transactional information like banking details, is collected and may be disclosed to affiliates, service providers, third-party transaction processors, professional advisors, and entities involved in corporate transactions.
Why it matters: Your commercial and financial transactional information, including purchasing history and banking information, can be shared with various entities, such as affiliates, service providers, and in the event of a corporate sale or merger.
| * Affiliates and subsidiaries within the Zendesk Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Zendesk Group * Service providers, such as security and platform vendors * With third parties that are necessary to complete a transaction, such as credit card processors * Professional advisors, such as lawyers, accountants, and auditors * Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets * To which you have consented to the disclosure
Personal Data We Collect and Disclose, paragraph 2 · Citation strength: strong
medium90% confidence
Collection and sharing of internet activity and device information
The company collects internet or other electronic network activity information and device information, such as browsing history, search history, device information, and interaction data, and may disclose it to affiliates, service providers, companies operating cookies and tracking technologies (e.g., marketing and advertising partners), and entities involved in corporate transactions.
Why it matters: Your online activities and device information are collected and can be shared with various third parties, including marketing and advertising partners, potentially leading to targeted advertising.
rs * Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets
Personal Data We Collect and Disclose, paragraph 2 · Citation strength: strong
medium90% confidence
Collection and sharing of geolocation information
Geolocation information, including approximate location based on IP address, mobile device location, or user-provided data, is collected and may be shared with affiliates, service providers, entities involved in corporate transactions, and companies operating cookies and tracking technologies (e.g., marketing and advertising partners).
Why it matters: Your location data may be shared with various third parties, including marketing and advertising partners, which could be used for targeted services or ads.
that operate Cookies and Tracking Technologies, described in [Section 5](https://www.zendesk.com/company/agreements-and-terms/privacy-notice/#cookies-and-tracking-technologies), such as marketing and advertising partners
Personal Data We Collect and Disclose, paragraph 2 · Citation strength: strong
medium90% confidence
Collection and sharing of sensitive personal data
Sensitive personal data, such as proof of vaccination or race and ethnicity (if optional), may be collected and disclosed to affiliates, service providers, entities involved in corporate transactions, or with your consent.
Why it matters: Sensitive personal data, such as vaccination status or racial/ethnic information, may be collected and shared with affiliated companies, service providers, or in the context of corporate events.
**Sensitive Personal Data**, such as proof of vaccination or race and ethnicity (optional) (where permissible under applicable law). | * Affiliates and subsidiaries within the Zendesk Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Zendesk Group * Service providers, such as platform vendors * Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets * To which you have consented to the disclosure
Personal Data We Collect and Disclose, paragraph 2 · Citation strength: strong
low90% confidence
Inferences as defined by California law are collected and shared
Inferences, as defined by California law (e.g., marketing you are likely to react positively to), are collected and may be disclosed to affiliates, service providers, and entities involved in corporate transactions.
Why it matters: The company creates and shares inferences about your potential reactions to marketing, which they can use for targeted advertising or share with affiliated entities and service providers.
* Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets
Personal Data We Collect and Disclose, paragraph 2 · Citation strength: strong
low95% confidence
External links may lead to unknown privacy practices
When interacting with the service, you may encounter links to external sites or online services, including third-party advertisements, for which the company is not responsible for their privacy and data collection policies.
Why it matters: Clicking external links or advertisements may take you to websites or services with different privacy practices than this service, and this company is not responsible for their data collection methods or policies.
When interacting with us, you may encounter links to external sites or other online services, including those embedded in third-party advertisements. We do not control and are not responsible for privacy and data collection policies for such third-party sites and services. You should consult such third parties and their respective privacy notices for more information or if you have any questions about their practices.
Key financial terms such as automatic renewals, free trial to paid conversion, and cancellation-related clauses.
✓
Looking good
No billing surprises spotted
Verbaterm only flags concerns it can cite. No cancellation, auto-renewal, or refund terms needed attention here.
Gotchas
1 finding
Less obvious but potentially important clauses. These could include one-sided terms, automatic consent to new policies, or other terms that a user might not typically notice.
medium90% confidence
Company may update privacy notice, user must check for updates and stop interacting if they disagree.
The company may update the Privacy Notice periodically, and it is your responsibility to check for updates. If you do not agree with any changes, you should stop interacting with the company.
Why it matters: You are responsible for regularly checking for updates to the Privacy Notice. If you continue to use the service after an update, you will be deemed to have accepted the new terms, even if you were unaware of the changes.
We may update this Notice from time to time. Please check back periodically for updates. If you do not agree with any changes we make, you should stop interacting with us. When required under applicable law, we will notify you of any changes to this Notice by posting an update on our Site or in another appropriate manner.
Explicit, source-backed consumer benefits and user-friendly clauses. This helps to balance the review and build trust.
Protection95% confidence
Right to exercise data subject rights
Zendesk commits to honoring data subject rights as required by law, including the right to access, correct, update, and, in some cases, request deletion of personal data.
Why it helps: Users have explicit rights to manage their personal data, including accessing, correcting, updating, and requesting deletion, which provides control over their information.
Zendesk will honor data subject rights to the extent required by law. You may have the right to access, correct, update, and, in some cases, request deletion of your personal data (subject to exceptions). You may submit a request [here](https://www.zendesk.com/datasubjectrequest/).
How We Process Personal Data, paragraph 3 · Citation strength: strong
Protection95% confidence
Commitment to security procedures
Zendesk maintains appropriate security procedures and technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, disclosure, alteration, or use.
Why it helps: The company explicitly states its commitment to protecting user data through security procedures and measures against unauthorized access or breaches.
We maintain appropriate security procedures and technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, disclosure, alteration, or use.
Security and Retention, paragraph 1 · Citation strength: strong
Protection95% confidence
Children's privacy protection
The service's sites and services are not directed to children under 16, and the company states it does not knowingly collect online personal data directly from children.
Why it helps: The company declares it does not target children under 16 and doesn't knowingly collect their personal data, helping protect minors' privacy.
Our Sites and Services are not directed to children under the age of 16, and we do not knowingly collect online personal data directly from children.