📄 Policy Information
⚠️ Data Sensitivity: Tier 2 (Highly Sensitive)
Payment apps process financial data, transaction history, bank account information, and government IDs. This data requires heightened privacy protections under our methodology.
Privacy Score Breakdown
Collects PII, financial info, device data; "not limited to product requirements"
Shares with service providers, partners; third parties collect data for their own purposes
No data retention policy specified per Common Sense
Users cannot opt out of personalized advertising; no privacy settings documented
CFPB found "weak security protocols"; data breach settlement in 2023
⚖️ Regulatory Enforcement History
CFPB Consent Order - $175 Million (January 2025)
The Consumer Financial Protection Bureau ordered Block to pay $175 million for Cash App security and fraud failures:
Key findings:
- $120 million refunds to consumers
- $55 million civil penalty
- Directed users to banks to reverse transactions, then denied them
- Deployed tactics to suppress users from seeking help
Multistate Settlement - $80 Million (AML Violations)
State regulators ordered Block to pay $80 million for Bank Secrecy Act and anti-money laundering law violations.
Data Breach Settlement - $15 Million (2023)
Cash App agreed to a $15 million settlement after a data breach exposed user information, prompting claims of weak cybersecurity practices.
Federal Criminal Investigation (2024)
Federal prosecutors are investigating long-term compliance lapses:
📊 Data Collection Scope (Cited)
Personal and Financial Information
Cash App collects comprehensive personal data upon signup:
Tracking Technologies
Beyond direct collection, Cash App tracks user behavior:
Collection Exceeds Product Requirements
Common Sense Privacy's evaluation found:
👥 Third-Party Sharing (Cited)
Business Partner Data Sharing
Cash App shares data broadly with various third parties:
Third Parties Collect Data for Own Purposes
Common Sense Privacy identified a concerning practice:
Marketing Data Use
Data is used for marketing with limited opt-out:
🎯 Advertising & User Control (Cited)
Personalized Advertising with No Opt-Out
Common Sense Privacy found major concerns about advertising:
No Privacy Settings Documented
Users have limited control over their data:
No Data Retention Policy
Unclear how long your data is kept:
🔒 Security Concerns (Cited)
CFPB: "Weak Security Protocols"
The federal regulator's findings on Cash App security:
Encryption Status Unclear
Common Sense Privacy could not verify encryption practices:
No Customer Identification Procedure
Whistleblower allegations about user verification:
Analysis