Terms of service (also known as terms of use and terms and conditions, commonly abbreviated as TOS or ToS, ToU or T&C) are the legal agreements between a service provider and a person who wants to use that service. The person must agree to abide by the terms of service in order to use the offered service. [1] Terms of service can also be merely a disclaimer, especially regarding the use of websites. Vague language and lengthy sentences used in these terms of service have caused concerns about customer privacy and raised public awareness in many ways.
A terms of service agreement is mainly used for legal purposes by companies which provide software or services, such as web browsers, e-commerce, web search engines, social media, and transport services.
A legitimate terms of service agreement is legally binding and may be subject to change. [2] Companies can enforce the terms by refusing service. Customers can enforce by filing a lawsuit or arbitration case if they can show they were actually harmed by a breach of the terms. There is a heightened risk of data going astray during corporate changes, including mergers, divestitures, buyouts, downsizing, etc., when data can be transferred improperly. [3]
A terms of service agreement typically contains sections pertaining to one or more of the following topics:
Among 102 companies marketing genetic testing to consumers in 2014 for health purposes, 71 had publicly available terms and conditions: [4]
Among 260 mass market consumer software license agreements in 2010: [5]
Among the terms and conditions of 31 cloud-computing services in January-July 2010, operating in England: [6]
The researchers note that rules on location and time limits may be unenforceable for consumers in many jurisdictions with consumer protections, that acceptable use policies are rarely enforced, that quick deletion is dangerous if a court later rules the termination wrongful, that local laws often require warranties (and UK forced Apple to say so).
Among the 500 most-visited websites which use sign-in-wrap agreements in September 2018: [7]
Among 260 mass market consumer software license agreements which existed in both 2003 and 2010: [5]
A 2013 documentary called Terms and Conditions May Apply publicized issues in terms of services. It was reviewed by 54 professional critics [8] and won for Best Feature Documentary at the Newport Beach Film Festival 2013 and for Best Documentary at the Sonoma Valley Film Festival 2013. [9]
Clickwrapped.com rates 15 companies on their policies and practices with respect to using users' data, disclosing users' data, amending the terms, closing users' accounts, requiring arbitration, fining users, and clarity.
Terms of Service; Didn't Read is a group effort that rates 67 companies' terms of service and privacy policies, though its site says the ratings are "outdated." [10] It also has browser add-ons that deliver the ratings while at the website of a rated company. Members of the group score each clause in each terms of service document, but "the same clause can have different scores depending on the context of the services it applies to." [11] The Services tab lists companies in no apparent order, with brief notes about significant clauses from each company. In particular, competitors are not listed together so that users can compare them. A link gives longer notes. It does not typically link to the exact wording from the company. The Topics tab lists topics (like "Personal Data" or "Guarantee"), with brief notes from some companies about aspects of the topic.
TOSBack.org, supported by the Electronic Frontier Foundation, lists changes in terms and policies sequentially, 10 per page, for 160 pages, or nearly 1,600 changes, for "many online services." [12] There does not seem to be a way to find all changes for a particular company, or even which companies were tracked in any time period. It links to Terms of Service; Didn't Read, though that typically does not have any evaluation of the most recent changes listed at TOSBack.org.
Terms of services are subject to change and vary from service to service, so several initiatives exist to increase public awareness by clarifying such differences in terms, including:
In 1994, the Washington Times reported that America Online (AOL) was selling detailed personal information about its subscribers to direct marketers, without notifying or asking its subscribers. That article led to the revision of AOL's terms of service three years later.
On July 1, 1997, AOL posted their revised terms of service to take effect July 31, 1997, without formally notifying its users of the changes made, most notably a new policy which would grant third-party business partners, including a marketing firm, access to its members' telephone numbers. Several days before the changes were to take effect, an AOL member informed the media of the changes and the following news coverage incited a large influx of internet traffic on the AOL page which enabled users to opt out of having their names and numbers on marketing lists. [1]
In 2011, George Hotz and other members of failOverflow were sued by Sony Corporation. Sony claimed that Hotz and others had committed breach of contract by violating the terms of service of the PlayStation Network and the Digital Millennium Copyright Act. [13]
On December 17, 2012, Instagram and Facebook announced a change to their terms of use that caused a widespread outcry from its user base. The controversial clause stated: "you agree that a business or other entity may pay us to display your username, likeness, photos (along with any associated metadata), and/or actions you take, in connection with paid or sponsored content or promotions, without any compensation to you".
There was no apparent option to opt out of the changed terms of use. [14] The move garnered severe criticism from privacy advocates as well as consumers. After one day, Instagram apologized, saying that it would remove the controversial language from its terms of use. [15] Kevin Systrom, a co-founder of Instagram, responded to the controversy, stating:
Our intention in updating the terms was to communicate that we’d like to experiment with innovative advertising that feels appropriate on Instagram. Instead, it was interpreted by many that we were going to sell your photos to others without any compensation. This is not true and it is our mistake that this language is confusing. To be clear: it is not our intention to sell your photos. We are working on updated language in the terms to make sure this is clear. [16]
Some terms of services are worded to allow unilateral amendment, where one party can change the agreement at any time without the other party's consent. A 2012 court case In re Zappos.com, Inc., Customer Data Security Breach Litigation held that Zappos.com's terms of use, with one such clause, was unenforceable. [17]
On October 5, 2023, a 42-year-old woman named Kanokporn Tangsuan (who worked as a doctor at NYU Langone Health) was killed at Raglan Road Irish Pub at Disney Springs in Walt Disney World after going into anaphylactic shock due to increased levels of dairy and nuts in her system. Her widower, Jeffery Piccolo, filed a wrongful death lawsuit against Disney in February 2024, claiming that she had alerted staff to her severe allergy to both multiple times, but was ignored. [18] On May 31, Disney filed a motion to get the lawsuit dismissed, citing the terms of service of both the My Disney Experience app (which they booked tickets from) and Disney+ (which they had used a free trial of in the past). This term would require all legal disputes against Disney and its affiliates to be held in an individual binding arbitration. [19] The story's publicization in August 2024 prompted severe backlash against the Walt Disney Company, with many moving to cancel their subscriptions to Disney+ and for a boycott of other Disney products and services. Piccolo's legal team also argued against Disney's claims, first stating that the terms of service on both platforms were "effectively invisible", and that Piccolo "would have had no notice" of the conditions. They also argued that Piccolo's use of these services should have no effect on Tangsaun's right to be represented in this case. [19] [20] Disney responded by claiming to be "deeply sorry" of the death, and that they were only defending themselves against a lawsuit towards the entire corporation. [21] The motion for the dismissal of the case was later withdrawn by Disney on August 20, 2024. [22]
Arbitration, in the context of the law of the United States, is a form of alternative dispute resolution. Specifically, arbitration is an alternative to litigation through which the parties to a dispute agree to submit their respective evidence and legal arguments to a third party for resolution. In practice, arbitration is generally used as a substitute for litigation. In some contexts, an arbitrator has been described as an umpire. Arbitration is broadly authorized by the Federal Arbitration Act. State regulation of arbitration is significantly limited by federal legislation and judicial decisions applying that law.
In contract law, an indemnity is a contractual obligation of one party to compensate the loss incurred by another party due to the relevant acts of the indemnitor or any other party. The duty to indemnify is usually, but not always, coextensive with the contractual duty to "hold harmless" or "save harmless". In contrast, a "guarantee" is an obligation of one party to another party to perform the promise of a relevant other party if that other party defaults.
An end-user license agreement or EULA is a legal contract between a software supplier and a customer or end-user.
Step-Saver Data Systems, Inc. v. Wyse Technology was a case in the U.S. Court of Appeals for the Third Circuit primarily concerned with the enforceability of box-top licenses and end user license agreements (EULA) and their place in U.S. contract law. During the relevant period, Step-Saver Data Systems was a value-added reseller, combining hardware and software from different vendors to offer a fully functioning computer system to various end users. Step-Saver's products included software produced by Software Link, Inc (TSL), computer terminals produced by Wyse Technology, and main computers produced by IBM. The fundamental question raised in this case was whether the shrinkwrap licenses accompanying TSL's software were legally binding, given that different terms were negotiated over the phone with Step-Saver prior to receiving physical copies of the software. The case was first heard in the United States District Court for the Eastern District of Pennsylvania, where the court ruled that the shrinkwrap licenses were legally binding. However, the U.S. Court of Appeals for the Third Circuit subsequently reversed this decision, ruling that the shrinkwrap licenses were not legally binding.
A software license is a legal instrument governing the use or redistribution of software.
Internet privacy involves the right or mandate of personal privacy concerning the storage, re-purposing, provision to third parties, and display of information pertaining to oneself via the Internet. Internet privacy is a subset of data privacy. Privacy concerns have been articulated from the beginnings of large-scale computer sharing and especially relate to mass surveillance.
A privacy policy is a statement or legal document that discloses some or all of the ways a party gathers, uses, discloses, and manages a customer or client's data. Personal information can be anything that can be used to identify an individual, not limited to the person's name, address, date of birth, marital status, contact information, ID issue, and expiry date, financial records, credit information, medical history, where one travels, and intentions to acquire goods and services. In the case of a business, it is often a statement that declares a party's policy on how it collects, stores, and releases personal information it collects. It informs the client what specific information is collected, and whether it is kept confidential, shared with partners, or sold to other firms or enterprises. Privacy policies typically represent a broader, more generalized treatment, as opposed to data use statements, which tend to be more detailed and specific.
A clickwrap or clickthrough agreement is a prompt that offers individuals the opportunity to accept or decline a digitally-mediated policy. Privacy policies, terms of service and other user policies, as well as copyright policies commonly employ the clickwrap prompt. Clickwraps are common in signup processes for social media services like Facebook, Twitter or Tumblr, connections to wireless networks operated in corporate spaces, as part of the installation processes of many software packages, and in other circumstances where agreement is sought using digital media. The name "clickwrap" is derived from the use of "shrink wrap contracts" commonly used in boxed software purchases, which "contain a notice that by tearing open the shrinkwrap, the user assents to the software terms enclosed within".
The Video Privacy Protection Act (VPPA) is a bill that was passed by the United States Congress in 1988 as Pub. L. 100–618 and signed into law by President Ronald Reagan. It was created to prevent what it refers to as "wrongful disclosure of video tape rental or sale records" or similar audio visual materials, to cover items such as video games. Congress passed the VPPA after Robert Bork's video rental history was published during his Supreme Court nomination and it became known as the "Bork bill". It makes any "video tape service provider" that discloses rental information outside the ordinary course of business liable for up to $2,500 in actual damages unless the consumer has consented, the consumer had the opportunity to consent, or the data was subject to a court order or warrant.
Specht v. Netscape, 306 F.3d 17, is a ruling at the United States Court of Appeals for the Second Circuit regarding the enforceability of clickwrap licenses under contract law. The court held that merely clicking on a download button does not show consent with license terms, if those terms were not conspicuous and if it was not explicit to the consumer that clicking meant agreeing to the license.
Browsewrap is a term used in Internet law to refer to a contract or license agreement covering access to or use of materials on a web site or downloadable product. In a browse-wrap agreement, the terms and conditions of use for a website or other downloadable product are posted on the website, typically as a hyperlink at the bottom of the screen. Unlike a clickwrap agreement, where the user must manifest assent to the terms and conditions by clicking on an "I agree" box, a browse-wrap agreement does not require this type of express manifestation of assent. Rather, a web-site user purportedly gives their consent simply by using the product — such as by entering the website or downloading software.
Register.com v. Verio, 356 F.3d 393, was a decision of the United States Court of Appeals for the Second Circuit that addressed several issues relevant to Internet law, such as browse wrap licensing, trespass to servers, and enforcement of the policies of the Internet Corporation for Assigned Names and Numbers (ICANN). The decision upheld the ruling of a lower court which prevented a provider of web development services from automatically harvesting publicly available registration data from a domain name registrar's servers for advertising purposes.
In the middle of 2009 the Federal Trade Commission filed a complaint against Sears Holdings Management Corporation (SHMC) for unfair or deceptive acts or practices affecting commerce. SHMC operates the sears.com and kmart.com retail websites for Sears Holdings Corporation. As part of a marketing effort, some users of sears.com and kmart.com were invited to download an application developed for SHMC that ran in the background on users' computers collecting information on nearly all internet activity. The tracking aspects of the program were only disclosed in legalese in the middle of the End User License Agreement. The FTC found this was insufficient disclosure given consumers expectations and the detailed information being collected. On September 9, 2009 the FTC approved a consent decree with SHMC requiring full disclosure of its activities and destruction of previously obtained information.
Lane vs. Facebook was a class-action lawsuit in the United States District Court for the Northern District of California regarding internet privacy and social media. In December 2007, Facebook launched Beacon, which resulted in users' private information being posted on Facebook without the users' consent. Facebook ended up terminating the Beacon program and created a $9.5 million fund for privacy and security. There was no monetary compensation awarded to Facebook users affected negatively by the Beacon program.
AT&T Mobility LLC v. Concepcion, 563 U.S. 333 (2011), is a legal dispute that was decided by the United States Supreme Court. On April 27, 2011, the Court ruled, by a 5–4 margin, that the Federal Arbitration Act of 1925 preempts state laws that prohibit contracts from disallowing class-wide arbitration, such as the law previously upheld by the California Supreme Court in the case of Discover Bank v. Superior Court. As a result, businesses that include arbitration agreements with class action waivers can require consumers to bring claims only in individual arbitrations, rather than in court as part of a class action.
Harris v. Blockbuster, Inc., 622 F. Supp. 2d 396, established precedent in the district that when a contract has a clause that authorizes one party to make changes to the "contract" without notification, that it is illusory and hence the entire "contract" is void.
A digital marketing system (DMS) is a method of centralized channel distribution used primarily by SaaS (Software as a service) products. It combines a content management system (CMS) with data centralization and syndication across the web, mobile, scannable surface, and social channels.
In re Zappos.com, Inc., Customer Data Security Breach Litigation, 893 F. Supp. 2d 1058, was a United States District Court for the District of Nevada case in which the Court held that Zappos.com's customers were not held to the browsewrap terms of use because of their obscure nature. The courts also held that the agreement was unenforceable because Zappos had reserved the right to change it at any time without informing the customers. This court decision set a precedent for businesses that use browsewrap agreements and/or include a clause in their agreements that allow them to change the agreements at any time. The decision encouraged conversation on how a business should most fairly display its terms of use and how to avoid unfairness and ambiguity when writing them.
Nguyen v Barnes & Noble, Inc., 763 F.3d 1171, was a United States Court of Appeals for the Ninth Circuit decision in which the Court ruled that Barnes & Noble's 2011 Terms of Use agreement, presented in a browsewrap manner via hyperlinks alone, was not enforceable since it failed to offer users reasonable notice of the terms. The decision set an important precedent on the future design and presentation of online contracts for consumer-facing e-commerce sites.
Search engine privacy is a subset of internet privacy that deals with user data being collected by search engines. Both types of privacy fall under the umbrella of information privacy. Privacy concerns regarding search engines can take many forms, such as the ability for search engines to log individual search queries, browsing history, IP addresses, and cookies of users, and conducting user profiling in general. The collection of personally identifiable information (PII) of users by search engines is referred to as tracking.
{{cite journal}}
: CS1 maint: multiple names: authors list (link){{cite journal}}
: CS1 maint: multiple names: authors list (link){{cite journal}}
: Cite journal requires |journal=
(help)