News
Gist from Forbes

Forbes Advisor Privacy Policy: What the Site Collects and How It Uses Your Data

Summarized June 15, 2026
Jump to key takeaways

Forbes Advisor — operated by Forbes Digital Marketing Inc., a distinct entity from Forbes Media — runs its own privacy framework governing a wide network of financial product subpages. The policy, effective April 1, 2026, spells out a broad data collection regime that goes well beyond basic account details, capturing names, addresses, email addresses, phone numbers, IP addresses, mouse movements, clicks, scrolling behavior, and form inputs. Session-recording tools log how visitors physically navigate the site, effectively creating a behavioral replay of each visit.

The data isn't just used internally. Forbes Advisor explicitly reserves the right to share Personal Information with business partners, advertising networks, and affiliate networks — particularly when users fill out questionnaires or product-matching surveys. In those cases, third-party advertisers receive personal details including name, email, gender, and date of birth, and those advertisers' own privacy policies then govern subsequent use. The policy notes that Online Tool Providers — companies whose APIs or SDKs are embedded in the site — may also use personal data for their own business purposes, not just Forbes Advisor's.

State-specific rights vary significantly. California residents are pointed to a separate, superseding notice under the CCPA/CPRA. Residents of 14 other states — including Virginia, Colorado, Texas, and New Jersey — get their own supplemental notice as well. Users in the UK and EEA are told the GDPR does not apply because Forbes Advisor doesn't market to those regions, a notable carve-out that removes a robust layer of international privacy protection.

Cookie use is extensive, relying on cookies, local browser storage, web beacons, pixels, and tags. Non-essential cookies can be declined via a footer link, but essential cookies cannot be opted out of. Users can request access to, correction of, or deletion of their personal data, though the company retains the right to keep data for legal or business reasons even after a deletion request. Identity verification is required before any access request is honored, and the company can decline requests deemed repetitive, impractical, or technically burdensome.

Key Takeaways

  • Session-recording tools capture mouse clicks, scrolling, and form inputs
  • Personal data shared with advertisers includes name, email, gender, date of birth
  • Third-party API/SDK providers may use your data for their own purposes
  • GDPR explicitly does not apply to UK or EEA users
  • California and 14 other states get separate, superseding privacy notices
  • Deletion requests can be denied for legal or business reasons
Read original article at Forbes

Summarize any article in seconds

Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.

Get Gist — Free
⚡ Instant summaries 💬 Chat with articles 🔒 Privacy-first