Skip to main contentSkip to footer
All companies
Privacy PolicyAnalyzed 2026-08-30

eBay

56score
Risk level
Medium Risk

Weighted across nine legal categories. Lower is worse.

Executive summary

This document is a comprehensive privacy policy heavily focused on biometric data collection, retention, and state-specific compliance (CPRA/CCPA, Illinois BIPA), but it functions solely as a privacy notice rather than a full Terms and Conditions agreement. While it provides robust consumer data rights and clear usage limitations for sensitive information, it relies on passive browsewrap consent for acceptance and modifications, lacks account management or dispute resolution provisions, and permits broad third-party sharing with lengthy retention periods.

Category breakdown

6 of the nine categories are not addressed by this document, so they are left out rather than scored.

Acceptance of Terms & Scope

Contract formation and service boundaries

45

The document relies on passive browsewrap consent rather than explicit clickwrap acknowledgment, and provides no age verification or plain-language summary of covered services.

Key findings

  • Consent triggered by mere use of the service
  • No explicit agreement mechanism or age gating
  • Scope limited strictly to data practices

Evidence from the document

By using our Services, you agree to the practices described in this Privacy Policy.

Recommendations

  • Implement explicit clickwrap 'I agree' buttons
  • Provide a concise plain-language summary
  • Clarify the exact scope of covered products and services

Data Privacy

Data collection, usage, and protection

72

The policy provides robust state-compliant rights and clear biometric usage limits, but weakens consumer control through broad third-party sharing, lengthy retention periods, and passive consent mechanisms.

Key findings

  • Explicit CPRA/CCPA rights honored including access, delete, correct, and limit use
  • Biometric data shared with government agencies and lenders
  • Retention period extends up to seven years absent legal compulsion
  • Passive consent used for policy changes

Evidence from the document

Caramel will transfer your Biometric Information third-party partners including state DMV’s where required...
under no circumstances will Caramel retain this information for longer than seven (7) years absent a subpoena, warrant, or other legally compelling justification.
Your continued use of the Services following the effective date of any posted revisions constitutes your consent to any changes to this Privacy Policy.

Recommendations

  • Shorten biometric retention periods to match actual business needs
  • Require explicit opt-in for non-essential third-party data transfers
  • Replace passive consent with active acknowledgment for material changes

Modification of Terms

How agreements can be changed

30

The company reserves the right to modify terms unilaterally with only a vague posting notice, relying on passive continued-use consent without advance warning or opt-out rights.

Key findings

  • Unilateral modification right with no fixed advance notice period
  • Passive consent via continued use deemed acceptance
  • No version history, changelog, or refund mechanism for rejected changes

Evidence from the document

Any revisions will be posted in a timely manner. Your continued use of the Services following the effective date of any posted revisions constitutes your consent to any changes to this Privacy Policy.

Recommendations

  • Provide 14-30 days advance email or in-app notice of material changes
  • Allow explicit rejection with pro-rated refunds or account closure
  • Maintain dated versions with a public changelog
Read the source documentSee the full interactive report

Ex-TerCo provides automated analysis of legal documents for informational purposes. This is not legal advice. Terms can change at any time.