Fixture
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Discloses that online data partners or vendors may associate website visit and login activities with other personal information, including by association with email, and that the company or service providers may send communications and marketing to those email addresses; provides an opt-out mechanism and a separate opt-out for data collection.
Disclaims that personal information is sold for money, restricting the company from engaging in monetary sale of personal information — a user-favorable limitation on data-sharing practices.
Establishes a procedure by which customers may request a Data Processing Agreement or current subprocessor information by contacting the specified email address, defining the mechanism for exercising data-processing-related rights.
How to read this page: Overall risk rates what Fixture's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 32 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 32 citationsLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Defines the roles of Fixture as processor/service provider and the Customer as controller/business when Customers use Fixture to manage CRM data, establishing the legal relationship governing how Customer data is handled.
" When Customers use Fixture to manage their CRM data, we generally act as a processor/service provider and the Customer acts as the controller/business ."
Specifies that account and workspace data is retained while active plus a reasonable period for legal and operational needs, defining the retention period for this category of data.
" Account/workspace data is retained while active, plus a reasonable period for legal and operational needs"
Permits sharing of information with marketing, analytics, attribution, and visitor-identification partners for purposes of understanding website usage, identifying business visitors, enriching records, and supporting outreach and campaign measurement, establishing broad third-party data-sharing permissions for commercial and marketing analytics purposes.
" With marketing, analytics, attribution, and visitor-identification partners that help us understand website usage, identify business visitors, enrich records, or support outreach and campaign measurement"
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout . You also have the option to opt out of the collection of your personal data in compliance with GDPR by visiting https://www.rb2b.com/rb2b-gdpr-opt-out ."
Discloses that online data partners or vendors may associate website visit and login activities with other personal information, including by association with email, and that the company or service providers may send communications and marketing to those email addresses; provides an opt-out mechanism and a separate opt-out for data collection.
AI-generated interpretation, not legal advice.
" We do not sell personal information for money."
Disclaims that personal information is sold for money, restricting the company from engaging in monetary sale of personal information — a user-favorable limitation on data-sharing practices.
AI-generated interpretation, not legal advice.
" The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16."
Restricts the services from being directed to children under 16 and prohibits knowingly collecting personal information from children under 16, establishing a protective age-based restriction on data collection.
AI-generated interpretation, not legal advice.
" Customers that need a Data Processing Agreement (DPA) or current subprocessor information can request it at the same email address."
Establishes a procedure by which customers may request a Data Processing Agreement or current subprocessor information by contacting the specified email address, defining the mechanism for exercising data-processing-related rights.
AI-generated interpretation, not legal advice.
" Visitors to fixture.app or sites that use Fixture tracking/forms"
Defines a third category of covered persons — visitors to fixture.app or sites using Fixture tracking/forms — establishing the scope of data subjects subject to tracking and form data collection.
AI-generated interpretation, not legal advice.
" When Customers use Fixture to manage their CRM data, we generally act as a processor/service provider and the Customer acts as the controller/business ."
Defines the roles of Fixture as processor/service provider and the Customer as controller/business when Customers use Fixture to manage CRM data, establishing the legal relationship governing how Customer data is handled.
AI-generated interpretation, not legal advice.
" When we process data for our own operations (for example, account administration, security, support, and compliance), we act as a controller ."
Defines Fixture's role as a controller when it processes data for its own operations such as account administration, security, support, and compliance, distinguishing this processing mode from its processor role.
AI-generated interpretation, not legal advice.
" We collect and process categories of information such as:"
Introductory statement indicating that the company collects and processes categories of information, framing the enumeration that follows.
AI-generated interpretation, not legal advice.
" CRM data that Customers choose to store (for example, people, companies, leads, deals, notes, and activity data)"
Defines a category of data collected — CRM data that Customers choose to store, including people, companies, leads, deals, notes, and activity data — establishing what Customer-controlled records are processed by Fixture.
AI-generated interpretation, not legal advice.
" Website and form data processed for Customers (for example, visitor identifiers, page/form interaction data, submission metadata)"
Defines a category of data collected for Customers — website and form data including visitor identifiers, page and form interaction data, and submission metadata — establishing the scope of tracking-related data processed.
AI-generated interpretation, not legal advice.
" Cookie and similar technology data (for example, session identifiers, persistent visitor identifiers, referrer information, geolocation, and related attribution or identity-resolution data)"
Defines a category of data collected — cookie and similar technology data including session identifiers, persistent visitor identifiers, referrer information, geolocation, and attribution or identity-resolution data — describing the scope of tracking technologies used.
AI-generated interpretation, not legal advice.
" Browser extension capture data from supported sources when a user chooses to capture data"
Defines a category of data collected — browser extension capture data from supported sources when a user chooses to capture data — establishing the scope of data gathered through the browser extension.
AI-generated interpretation, not legal advice.
" Support visitor identification, attribution, audience enrichment, marketing measurement, and related outreach workflows"
States that information is used for visitor identification, attribution, audience enrichment, marketing measurement, and related outreach workflows, establishing broad permitted marketing and analytics processing purposes.
AI-generated interpretation, not legal advice.
" Depending on the tool, configuration, and jurisdiction, some of this processing may be considered "sharing" for cross-context behavioral advertising or targeted advertising under applicable law."
Disclaims certainty by noting that, depending on tool, configuration, and jurisdiction, certain processing may qualify as sharing for cross-context behavioral advertising or targeted advertising under applicable law, without definitively characterizing the practice.
AI-generated interpretation, not legal advice.
" You can control cookies through your browser settings and, where available, through our cookie banner or consent manager. Disabling some cookies may affect functionality."
Grants users the right to control cookies through browser settings and, where available, through a cookie banner or consent manager, and notes that disabling some cookies may affect functionality.
AI-generated interpretation, not legal advice.
" If you use our AI assistant, we process conversation content and related context to provide responses."
States that use of the AI assistant results in processing of conversation content and related context to provide responses, describing a specific data-processing activity tied to AI feature usage.
AI-generated interpretation, not legal advice.
" We use technical and organizational safeguards designed to protect personal information, including encryption in transit, access controls, and security monitoring."
States that technical and organizational safeguards are used to protect personal information, including encryption in transit, access controls, and security monitoring, describing implemented protective measures.
AI-generated interpretation, not legal advice.
" Depending on where you live, you may have rights such as access, correction, deletion, portability, restriction, objection, withdrawal of consent, and opting out of certain sales, sharing, or targeted advertising."
States that depending on where a user lives, they may have rights including access, correction, deletion, portability, restriction, objection, withdrawal of consent, and opting out of certain sales, sharing, or targeted advertising, defining the scope of potentially available individual rights.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Fixture's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Fixture's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Fixture's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Fixture requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Fixture's published policies yet.
What the policies actually cover
0 topicsNone of Fixture's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Cross-clause notes
Verified retention clauses point in different directions: the Privacy Policy, § 8 (Data Retention) describes broad or open-ended retention, while the Privacy Policy, § 8 (Data Retention) describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“We do not sell personal information for money.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Some of these technologies are set by us or by vendors acting on our behalf, including first-party cookies used to recognize returning visitors, maintain sessions, store referral information, and support identity-resolution functionality.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Customers that need a Data Processing Agreement (DPA) or current subprocessor information can request it at the same email address.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | audit rights dpa residency | conditional | MEDIUM | 1 |
| All applicable tiers | subprocessors data sharing | worsens | HIGH | 3 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on subprocessors data sharing
“We do not sell personal information for money.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Some of these technologies are set by us or by vendors acting on our behalf, including first-party cookies used to recognize returning visitors, maintain sessions, store referral information, and support identity-resolution functionality.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout . You also have the option to opt out of the collection of your personal data in compliance with GDPR by visiting https://www.rb2b.com/rb2b-gdpr-opt-out .”Open timeline citation
Latest stance: third party or vendor sharing on audit rights dpa residency
“Customers that need a Data Processing Agreement (DPA) or current subprocessor information can request it at the same email address.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
33 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Fixture's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Fixture's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Fixture's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.