Wind-downs and transitions
Privacy policy says 'we never sell data': can a closing company still license records?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A closing company whose privacy policy says 'we never sell data' can sometimes still license records, but only those the promise does not cover or that are properly de-identified, because the promise still binds data collected under it, including in bankruptcy. Read every policy version, map records to the audience each addressed, and exclude anything in scope.
Key takeaways
- A privacy promise follows the data collected under it; closing or filing for bankruptcy does not cancel it.
- Every historical version of the policy matters, because data collected under an older version may carry that version's promise.
- Business transfer clauses usually contemplate a successor running the business, not a license to an unrelated third party.
- Records that were never about the policy's audience, or that are properly de-identified, may fall outside the promise, assessed with counsel.
Does a 'we never sell' promise survive a shutdown?#
A 'we never sell your data' promise survives a shutdown in the sense that matters: it continues to govern the personal information collected while it was in force. Consumer protection regulators, including the FTC and state attorneys general, treat privacy statements as promises to the people who relied on them, and they have objected in past bankruptcies when customer data was offered for sale against such promises.
Closing changes who holds the data, not what was promised about it. Whoever controls the data next, whether the company's own wind-down officers, an assignee or a bankruptcy trustee, holds it subject to those commitments. The practical question is therefore not whether the promise binds, but exactly what it covers.
What did the policy actually promise?#
What a privacy policy promised depends on its exact words, its definitions and the version in force when each record was collected. Collect every version with the dates it was live, then read each one for the data it covers, the act it rules out and the exceptions it allows.
Also note whom each policy addressed. A website privacy policy typically speaks to visitors, users and customer contacts. It usually does not govern employees, whose information falls under handbooks and employee notices, or a company's internal records about its own processes.
| Policy wording | What it likely covers | What to check |
|---|---|---|
| We never sell your personal information | Personal information as the policy defines it | Whether de-identified or aggregated data is excluded from the definition |
| We do not share your data with third parties | Broader than selling; may reach licensing | Exceptions for service providers, legal requests and business transfers |
| Information may transfer in a merger, acquisition or sale of assets | A transfer to a successor that continues the business | Whether the recipient must honor the same promises |
| We may use aggregated or de-identified data for any purpose | Data that no longer identifies a person | How de-identification was defined and whether it was done |
| We do not use your content to train AI models | Customer content and possibly data derived from it | Whether it applies to all records or only certain services |
Is licensing de-identified records a 'sale'?#
Whether licensing de-identified records counts as a sale depends on the policy's definitions and on the privacy laws that may apply. Some state privacy laws, including the CCPA, define selling personal information broadly enough to cover sharing it for something of value, while treating information that meets their de-identification standard differently.
De-identification is a technical and contractual standard, not a label. It generally involves removing direct identifiers, reducing the chance that individuals can be re-identified and binding the recipient not to re-identify anyone. Whether a specific dataset meets a specific law's standard is decided with privacy counsel for each deal, and a policy that promised never to share data at all may restrict even well-prepared datasets.
Which records may fall outside the promise?#
Records that may fall outside a 'never sell' promise are those that were never personal information about the policy's audience, or that no longer identify anyone after preparation. Records that sit squarely inside the promise are the data people handed over as users or customers.
Two traps catch closing companies. Support tickets from business customers often contain end users' names, emails and phone numbers pasted into the conversation, so a business record can still hold personal information about the very people the policy addressed. Engineering issues can also carry customer data copied in to reproduce a bug, which needs the same treatment as the source system.
| Record family | Exposure to the privacy promise | Other limits to check |
|---|---|---|
| Consumer account and profile data | High; usually excluded | State privacy laws, consent records |
| Customer content and uploads | High; usually excluded | Terms of service, customer contracts |
| Support tickets from business customers | Medium; personal details removed if used | Customer contracts and NDAs |
| Internal engineering issues and code reviews | Low; mostly about the company's own work | Employee notices, secrets in code |
| Process documents and playbooks | Low | Client confidential material |
| Aggregated operational statistics | Low if properly aggregated | Re-identification risk in small groups |
Steps before licensing anything#
The steps before licensing anything under a restrictive privacy policy are about narrowing scope until every remaining record can be defended to a buyer, a court or a regulator.
- Assemble every version of the privacy policy and terms of service, with the dates each was live.
- Map each record family to the policy audience it came from and the version in force when it was collected.
- Exclude records collected under promises that rule out the intended use.
- Remove personal details from the remaining records and document the method.
- Check customer contracts, data processing agreements and NDAs for separate limits.
- Consider whether notice or consent is feasible for any record group.
- In bankruptcy, expect a consumer privacy ombudsman and a court hearing before any sale or lease of customer personal information that the policy does not allow, and follow that process rather than working around it.
- Write down the analysis and decisions so they can be reviewed later.
Illustrative: a closing booking platform narrows its scope#
Illustrative: a fictional software company that ran an online booking platform for home services contractors is winding down. Its privacy policy, written for homeowners who booked through the app, said the company would never sell or share their personal information. Its contractor customers signed separate business agreements.
Counsel concludes that homeowner profiles, booking histories and messages fall inside the promise and excludes them entirely. Internal Jira issues, engineering design documents and support escalations between the company and its contractor customers are reviewed separately. After contractor names and any homeowner details in tickets are removed, those records are assessed for a non-exclusive license, and the decision memo is kept with the wind-down file.
The company's Slack workspace and HR records are left out of this review entirely, because the homeowner policy never addressed them. They go through a separate review under the employee handbook and monitoring notice, with direct messages and HR channels excluded by default.
How SourceX handles restrictive privacy promises#
SourceX starts the Rights step of the SourceX five-step transaction with the company's privacy policy versions and the records each one governed, and excludes data covered by a promise that rules out the intended use rather than trying to work around it. Personal and confidential details are removed in Preparation, and the privacy record in the SourceX Evidence Packet documents which policy versions applied and what was excluded.
Frequently asked questions
Can we change the privacy policy now to allow licensing?
A change generally applies to data collected after the new version takes effect. Applying a materially less protective policy to data already collected usually requires the affected people's consent, and US regulators have treated material retroactive changes made without consent as unfair or deceptive. A closing company rarely has a practical way to obtain that consent at scale.
What if the privacy policy never mentioned selling or AI at all?
Silence is not permission. The policy's described purposes and any limits on sharing still apply, along with any state privacy laws that cover the data. Records that fall outside personal information, or that are properly de-identified, may be easier to license, but counsel should confirm the conclusion for each record family.
Does the business transfer clause cover a license to an AI developer?
Usually not on its own. Business transfer clauses are written for a successor that acquires and continues the business, often subject to the same privacy commitments. A license of records to an unrelated company for a new purpose is a different act, so read the clause narrowly unless counsel advises otherwise.
Do employee records fall under the website privacy policy?
Usually not. Employee information is typically governed by the employee handbook, monitoring notices, employment law and, in some states, privacy laws that cover workers. Those documents need their own review before any workplace communications or HR-related records are considered.
Are aggregated statistics safe to share?
Aggregated statistics carry less risk than record-level data, but small groups can still reveal individuals, especially in niche markets. Set minimum group sizes, drop rare categories and review outputs before release. A policy that promised no sharing of anything derived from user data may still limit even aggregates.
Related resources
- QuestionDo AI labs buy spreadsheets?
- InsightCan financial advisors sell their data to AI companies?
- InsightLicensing vs selling data assets in bankruptcy: why non-exclusive licenses matter
- InsightAI interest in bankrupt companies' data: what courts check before a lot sells
- IndustryHealthcare administration data
- IndustryHealthcare data
See if your company qualifies
A short company assessment. No data uploads are needed.