Terms of Service and Privacy Policy

Terms of Service and Privacy Policy

Definition: Two legal documents nearly every software product needs: Terms of Service (ToS) governs the rules of using the product, Privacy Policy discloses what data is collected and how it’s used.

How It Works

  • ToS: defines acceptable use, liability limits, dispute resolution (including arbitration clauses), intellectual property ownership, and the company’s rights to suspend accounts or change the service
  • Privacy Policy: discloses what personal data is collected, why, who it’s shared with, how long it’s retained, and how users can exercise rights like access or deletion, required in more detail by laws like GDPR and CCPA
  • Both documents form a contract only if there’s a valid mechanism for the user to actually agree to them, not just a link sitting somewhere on the page
  • Clickwrap: an explicit, affirmative action, checking a box or clicking “I Agree”, required before proceeding
  • Browsewrap: terms are simply posted (often in a footer link), with continued use of the site treated as implied consent, no explicit action required
  • Courts weigh notice and assent when deciding enforceability, clickwrap gives much stronger evidence of both than browsewrap does
  • Sign-in-wrap: a hybrid, a link to the terms sits near a “Sign Up” or “Continue” button without a separate checkbox, courts evaluate these case by case based on how conspicuous the link and language are
  • A EULA (End User License Agreement) is a close cousin of ToS, used specifically for licensed software rather than an ongoing web service, it grants a license to use the software rather than governing account-based access
  • The underlying legal concept is the same one behind open source licensing: MIT License and GPL License are also permission grants, just for source code instead of a hosted service
  • Standard ToS clauses beyond the basics: severability (if one clause is struck down, the rest still stands), assignment rights, governing law/venue, and a limitation-of-liability cap
  • Privacy policies typically distinguish between data the company collects directly (account info, usage logs) and data received from third parties (ad networks, data brokers, integrations), since disclosure obligations can differ for each

Under the Hood

Worked example 1: clickwrap enforceability

  • Given: an app requires users to check an explicit “I agree to the Terms of Service” box, with the ToS linked directly above it, before an account can be created
  • Step 1: the user takes an affirmative action to proceed, there’s a clear record of assent (a timestamped click) tied to a specific version of the document
  • Step 2: a dispute later arises over an arbitration clause buried in the ToS
  • Step 3: because the format shows reasonable notice plus an affirmative action, courts are generally more willing to enforce the clause
  • Answer: clickwrap gives the company strong evidence the terms were seen and accepted, meaningfully improving enforceability

Worked example 2: browsewrap enforceability

  • Given: a website has a small “Terms of Use” link in the footer, no checkbox, no click, nothing interrupts browsing
  • Step 1: the user never actively acknowledges the terms, they’re simply available if she happens to scroll down and click
  • Step 2: a dispute arises over a liability limitation clause
  • Step 3: without an affirmative action or strong evidence of actual notice, enforceability is much weaker
  • Answer: browsewrap terms are frequently struck down in court for lack of adequate notice, a footer link alone is often not enough to form a binding contract

Worked example 3: material change re-consent

  • Given: a company that originally didn’t share user data with advertisers decides to start sharing it with an ad partner, and updates the Privacy Policy accordingly
  • Step 1: this is a material change, existing users’ reasonable expectations at signup are being altered, not just cosmetic wording
  • Step 2: simply changing the “Last Updated” date at the bottom of the page isn’t enough to bind existing users to the new terms
  • Step 3: the company sends an email notice and requires active users to click “I accept the updated Privacy Policy” before continuing
  • Answer: material changes require fresh notice and, typically, fresh affirmative consent, not a silent document swap

Worked example 4: ToS against a scraper

  • Given: a company’s ToS explicitly prohibits automated scraping, and a third party scrapes public-facing profile pages anyway
  • Step 1: the company argues the scraper violated its ToS by accessing the site in a prohibited manner
  • Step 2: the scraper argues it never created an account or clicked “I agree” to anything, so no contract was ever formed with them specifically
  • Step 3: courts have split on this exact question, whether ToS can bind a party who never affirmatively agreed to it, especially for data that’s otherwise publicly visible
  • Answer: ToS enforceability against non-signing third parties (like scrapers) is far weaker and more contested than enforceability against a company’s own registered users

Why It Matters

  • These aren’t boilerplate: they’re the actual legal contract between a company and its users, and gaps in them create real liability
  • The ToS is often the only thing standing between a company and an abusive user, without clear acceptable-use and termination clauses, banning bad actors gets legally murky
  • A privacy policy that doesn’t match actual data practices is itself a violation in many jurisdictions, regulators treat a misleading policy as a form of deceptive practice
  • How consent is captured (clickwrap vs browsewrap) directly affects whether an arbitration clause or liability cap will actually hold up if a user sues
  • ToS is also the tool companies use to enforce acceptable use against scrapers, bots, and API abuse, its enforceability against outside parties (not just signed-up users) is a live and contested legal question
  • A clear, accurate privacy policy is often the first thing enterprise security and legal teams check during vendor review, alongside things like SOC 2 reports
  • Clear termination and suspension language in the ToS gives a company a documented, defensible basis for banning accounts, instead of an ad hoc decision that looks arbitrary if challenged
  • Getting consent capture right once, at signup, is far cheaper than retrofitting a compliant flow after a regulator or plaintiff’s attorney flags a gap
  • The distinction between direct and third-party data sources in a privacy policy shapes what a product can even legally do with data it didn’t collect itself

Common Pitfalls

This is general information, not legal advice, have a lawyer review your actual ToS and privacy policy before launch.

  • Copy-pasting a generic template without adapting it to what the product actually does or what data it actually collects, creating a document that doesn’t match reality
  • Not updating the privacy policy when the product starts collecting new types of data or integrating new third-party tools
  • Relying on browsewrap when the arbitration clause or liability limits actually matter, weak notice can make the whole clause unenforceable exactly when it’s needed most
  • Making a “material change” to the ToS (new fees, new data sharing) without renotifying users, several jurisdictions require fresh consent for material changes, not just an updated effective date
  • Treating the Privacy Policy as a one-size-fits-all document when the product operates in multiple jurisdictions with different legal requirements (GDPR vs CCPA vs sector-specific rules)
  • Burying an arbitration or class-action waiver clause deep in dense text, which increases the odds a court finds it wasn’t reasonably noticed
  • Using a sign-in-wrap flow where the terms link is small, low-contrast, or far from the action button, weakening the notice argument if it’s ever challenged
  • Assuming a ToS clause can override statutory rights, consumer protection and data privacy laws generally can’t be waived away by a private contract
  • Applying US-style consent patterns (implied consent, opt-out defaults) to EU users, where GDPR generally requires clear, affirmative, opt-in consent instead
  • Forgetting that a EULA and a ToS aren’t interchangeable, shipping desktop or embedded software with only a web-style ToS can leave the actual license terms undefined
  • Lumping first-party and third-party data sources together in the privacy policy, obscuring where data received from ad networks or partners actually came from
  • Writing the acceptable-use policy so vaguely that enforcement against a genuinely bad actor becomes a judgment call instead of a clear contractual breach

Comparison

Terms of ServicePrivacy PolicyEULA
GovernsRules of using a serviceData collection, use, and sharingRules of using licensed software
Typical forWeb apps, SaaS platforms, marketplacesAny product handling personal dataInstalled, downloaded, or embedded software
Legally requiredNot always, but standard practiceOften legally required (GDPR, CCPA, state laws)Not always, common for licensed (not sold) software
Core contentAcceptable use, liability, disputes, IPData types collected, sharing, retention, user rightsLicense grant, restrictions, warranty disclaimer
Consent mechanismClickwrap or browsewrapUsually referenced/linked at signup, same mechanismsTypically clickwrap, “I accept” before install
Change processUpdate plus notice, re-consent if materialUpdate plus notice, re-consent if materialOften re-accepted on each major version update
Governs relationship withThe company’s own users/accountsAnyone whose data is processed, users or notThe specific licensee of the software
Common enforcement fightArbitration clauses, scraping/bot accessData sharing scope, retention, deletion rightsReverse engineering bans, redistribution limits

Many products need all three at once: a SaaS platform with a downloadable desktop client typically ships a ToS for the web account, a Privacy Policy for data handling, and a EULA for the installed client software, each governing a different part of the relationship.

Example

Nguyen v. Barnes & Noble (9th Circuit, 2014) is a widely cited real case on browsewrap enforceability: a customer sued over a canceled order, and Barnes & Noble tried to compel arbitration under its website’s Terms of Use. The court refused to enforce the terms, holding that a browsewrap link, without any prompt requiring the user to view or assent to it, didn’t give reasonable notice, so no valid contract was formed. It’s a standard example cited when explaining why clickwrap is the safer design for any clause a company actually wants to enforce.

A similar outcome played out in the Zappos.com Customer Data Security Breach Litigation (9th Circuit, 2012), where a federal court declined to enforce Zappos’ browsewrap arbitration clause against customers after a data breach, for the same core reason: no clear evidence users had actually agreed to it.

The scraping question from worked example 4 played out in real life in hiQ Labs, Inc. v. LinkedIn Corp. (9th Circuit, 2019, later revisited after a 2021 Supreme Court remand). LinkedIn tried to block hiQ from scraping public profile data, partly by pointing to its ToS. The courts largely sided with hiQ on the specific access question, underscoring how much weaker ToS enforcement is against parties who never clicked “agree” to anything, compared to enforcement against a company’s own signed-up users.

A company handling health data still needs a Privacy Policy layered on top of its HIPAA obligations, HIPAA governs PHI specifically, while the Privacy Policy covers the full scope of personal data the product touches, patients and non-patients alike.

Dig deeper