Skip to main content

Evidence program · Snapshot 2026-09-25

Broker Evidence Roadmap

This page explains how OfflistMe builds a source-maintained, updateable data broker knowledge base. Every profile separates provider-published facts, registry context, read-only observations, derived classifications, user-authorized outcomes, and unknown fields.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 25, 2026

Current evidence snapshot

1,043

Broker profiles

captured catalog records

182,654

Evidence facts

source-linked facts and observations

817

Registry context

matched public-registry profiles

537

Route observations

read-only web checks

541

Independent routes

route semantics observed

468

Semantics pending

provider URLs needing review

471

Semantic dispositions

read-only classifications; no auto-promotion

34

Failed/recheck queue

independent rechecks pending

505

DNS-checked email routes

mailbox not verified

277 / 277

Fresh High-impact profiles

source-checked within 90 days

1,039

Promotion gate passes

explicit approval still required

These counts describe routing and provenance. They do not prove request submission, mailbox acceptance, broker response, deletion, monitoring, or non-republication.

The 461 previously semantics-pending URLs now have explicit read-only dispositions. First-party candidates still require route-role review; cross-domain and processor candidates still require entity confirmation; ambiguous and blocked pages remain manual work.

The freshness and source-depth gates are publication safeguards: a High-impact profile must have a recent source check and usable non-registry HTTPS source context before it is treated as ready for deeper editorial work.

Controlled catalog handoff

Verified records have an explicit promotion gate

The current manifest covers 1,043 captured catalog records. 1,039 pass the minimum evidence gate, and 4 are blocked in this snapshot. A passing gate means the record can enter an explicitly approved promotion decision; it does not authorize automatic writes or prove complete field coverage, request acceptance, delivery, deletion, monitoring, or non-republication.

1,039

Gate passes

bounded evidence conditions satisfied

1,039

Catalog-present gate passes

present in the catalog; field review remains separate

1,043

Approval required

human approval remains mandatory

1,026

Open field reviews

unknown enrichment fields remain bounded

20% focus rule

Start with the highest-impact evidence gaps

209 of 1,043 profiles

This first tranche includes 209 explicitly High-impact catalog records. Lower tracked-field completeness raises evidence-work priority; it does not make a record less useful or prove a broker outcome. A dated Search Console snapshot now informs page and intent ordering; it does not estimate competitor share or removal outcomes.

50

Advertising & Adtech

40

B2B & Sales Intelligence

41

Credit, Risk & Identity

64

Marketing & Audience Data

14

People Search & Public Records

Selection rule: Explicit High-impact catalog records are selected first. Ties are ordered by category priority, lower tracked-field completeness, and current route evidence. This is an evidence-work priority, not a live search-volume, ranking, removal-success, or competitor-share estimate.

209

Workflow sources

profiles with source URLs

207

Named gaps

profiles with open evidence fields

187

Registry context

matched public-registry records

155

Route evidenced

current provider routes

48

Semantics pending

manual route-role review

32

Review queue

review-only enrichment records

These are readiness signals for source maintenance, not broker-quality scores. The full tranche list includes each profile's named gaps and next evidence pass in the machine-readable plan.

Representative profileCategoryImpactEvidence depthReadinessNext evidence pass
PayNet (Equifax)current_route_evidencedCredit, Risk & IdentityHigh32.56%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
The Trade Desk, Inc.current_route_evidencedAdvertising & AdtechHigh27.52%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
Quantcastcurrent_route_evidencedAdvertising & AdtechHigh27.91%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
Nielsen Consumer LLC (NielsenIQ)current_email_route_recordedMarketing & Audience DataHigh28.29%route semantics reviewReview the page role and host relationship before treating the URL as a request route.
Appilycurrent_route_evidencedMarketing & Audience DataHigh30.62%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
Phunware, Inc.current_email_route_recordedAdvertising & AdtechHigh28.68%route semantics reviewReview the page role and host relationship before treating the URL as a request route.
Nexsales Solutions Inc. (RightLeads)current_route_evidencedB2B & Sales IntelligenceHigh31.4%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
Reality Media, Inc.current_route_evidencedAdvertising & AdtechHigh31.78%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
700Credit, LLCcurrent_route_evidencedCredit, Risk & IdentityHigh41.86%source depth reviewFill only the named evidence gaps from dated provider, registry, or regulator sources.
Acquire Media U.S., LLC (Moody's Analytics NewsEdge)current_route_evidencedB2B & Sales IntelligenceHigh32.17%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
RelSci (Altrata)current_route_evidencedB2B & Sales IntelligenceHigh32.17%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.
Tandem Marketing, LLCcurrent_route_evidencedMarketing & Audience DataHigh32.17%entity and source reviewSeek an official registry or regulator record, while preserving an explicitly unmatched state if none is found.

Next evidence tranche

Continue with the remaining High-impact profiles

68 profiles · 6.52% of catalog

This tranche contains explicitly High-impact records outside the first 20%. It is an evidence and publication priority, not a live search-volume estimate, competitor-share claim, removal-success metric, or provider-outcome guarantee.

16

Advertising & Adtech

9

B2B & Sales Intelligence

29

Marketing & Audience Data

14

Social, Marketplaces & Platforms

48.32%

Evidence depth

average tracked-field completeness

68

Registry context

matched public-registry records

22

Routes evidenced

current provider routes

45

Semantics pending

manual route-role review

14

Review queue

review-only enrichment records

Selection rule: Explicit High-impact catalog records outside the first 20% tranche, ordered by the same evidence-work score. This is a research and publication priority, not a live search-volume, ranking, removal-success, or competitor-share estimate.

Representative profileCategoryEvidence depthRoute stateNext evidence pass
Unearth Campaigns LLCHighMarketing & Audience Data48.84%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.
Interactive Data, LLCHighMarketing & Audience Data46.9%current_email_route_recordedReview the page role and host relationship before treating the URL as a request route.
Complete Mailing Lists LLCHighB2B & Sales Intelligence49.22%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.
Dataline, Inc.HighMarketing & Audience Data49.22%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.
Tunnl, LLCHighMarketing & Audience Data49.22%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.
UnacastHighAdvertising & Adtech49.22%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.
Demand ScienceHighB2B & Sales Intelligence47.29%current_email_route_recordedReview the page role and host relationship before treating the URL as a request route.
VideoAmp, Inc.HighAdvertising & Adtech47.29%current_email_route_recordedReview the page role and host relationship before treating the URL as a request route.
WINR DataHighMarketing & Audience Data47.29%current_email_route_recordedReview the page role and host relationship before treating the URL as a request route.
Reveal Mobile, Inc.HighAdvertising & Adtech49.61%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.
Veraset, LLCHighAdvertising & Adtech49.61%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.
Webbula, LLCHighMarketing & Audience Data49.61%current_route_evidencedFill only the named evidence gaps from dated provider, registry, or regulator sources.

The complete tranche list, named evidence gaps, and source-bound next actions remain available in the machine-readable authority plan.

After High-impact coverage

Expand into the next evidence tranche

209 profiles · 20.04% of catalog

This queue covers profiles without an explicit High-impact label. It is ordered for source-backed research and publication after the High-impact set, not presented as a market ranking or removal-outcome claim.

35.64%

Evidence depth

average tracked-field completeness

82

Registry context

matched public-registry records

105

Routes evidenced

current provider routes

208

Named gaps

records with open evidence fields

39

Review queue

review-only enrichment records

Medium: 86Not recorded: 123

Selection rule: Profiles outside the explicit High-impact set, ordered by evidence gaps, category relevance, route state, and tracked-field completeness. This is a research and publication priority, not a ranking, market-share estimate, or removal-outcome claim. The full profile list and named next actions remain in the machine-readable authority plan.

Bounded research · 2026-09-25

Recent official-source reviews

These four reviews add current provider context to the next High-impact research queue. They remain review-only: an official policy or privacy form supports a documented claim, but does not by itself certify entity ownership, route semantics, request delivery, acceptance, or deletion.

Dataline, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-08) Dataline identifies itself as a provider of consumer marketing information. The policy directs consumers to its Privacy Portal for opt-out requests and describes California access, deletion, and sale/sharing rights.
  • Official source ↗ The policy links to this page as the Do Not Sell / Privacy Portal route. Limitation: The route returned a 404/cache miss in the bounded research environment; retain it as an unpromoted candidate until independently rechecked.

Next review action: Review the current portal and entity relationship, then promote only after the route and workflow are independently confirmed.

Reveal Mobile, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-11-08) The policy describes an opt-in mobile location-data product and identifies IDFA/AdID as device identifiers used for matching. It directs consumers to a privacy request form and privacy@revealmobile.com for access, deletion, and sale opt-out requests.
  • Official source ↗ The official form states that it accepts access, deletion, and sale opt-out requests and responds within the timeframe required by applicable law.

Next review action: Confirm the current form route and record the device-identifier requirement as workflow context without implying a completed removal.

Tunnl, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-21) The policy identifies Tunnl, LLC and states that it processes information for clients, including people with whom it has no direct relationship. It describes GPC recognition and directs rights requests to an interactive webform or 1-866-498-2784.
  • Official source ↗ The linked official privacy-request portal is the provider-stated request channel.

Next review action: Confirm route semantics and jurisdiction scope before updating the customer-ready workflow record.

Unacast

Reviewed 2026-09-25
  • Official source ↗ Unacast states that its products use aggregated data and that it honors mobile users’ requests not to accept location data, sharing those requests with partners. Limitation: The linked privacy statement was blocked by robots.txt in the research environment, so the underlying policy was not independently reviewed.

Next review action: Recheck the provider privacy statement through an accessible first-party source before promoting any route or workflow detail.

Xcelerated Data LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-01) The policy identifies Xcelerated LLC and distinguishes its own database from data processed for dealer or client entities. It describes a database opt-out process and says that opting out of Xcelerated’s database does not opt out of client databases.

Next review action: Confirm the current opt-out form URL and entity/client boundary before updating workflow fields.

Veraset, LLC

Reviewed 2026-09-25
  • Official source ↗ The policy describes GPS location and device-level data products and identifies hashed email and mobile advertising identifiers among the data-solution opt-out context. It links to a provider opt-out form and states that a device-specific opt-out may need to be repeated for other devices or after an advertising-ID reset.
  • Official source ↗ The provider-stated opt-out and Do Not Sell form linked from the privacy policy.

Next review action: Confirm the live form and record device-level scope without implying universal or completed removal.

Webbula, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-03-26) The privacy notice identifies Webbula’s data services and says its direct database opt-out suppresses associated information rather than selling it. It identifies a direct opt-out page and privacy contact.
  • Official source ↗ The official privacy center presents opt-out, data-access, appeal, GDPR, and CCPA paths and identifies Webbula as a data broker under Texas law.
  • Official source ↗ The privacy notice names this page as the direct opt-out route and also provides a phone alternative.

Next review action: Confirm current form behavior and exact identity fields before promoting the route or suppression wording.

Azerion US Inc.

Reviewed 2026-09-25
  • Official source ↗ The global notice identifies Azerion Group N.V. and affiliates/subsidiaries as responsible parties and says specific services may have supplemental privacy notices. It directs service-specific information requests to dpo@azerion.com. Limitation: The global notice is not by itself a specific consumer data-broker opt-out route; service and entity scope require further review.

Next review action: Identify the relevant Azerion service/entity and its specific privacy notice before considering any route promotion.

Belardi Ostroy, ALC, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-27) The Belardi Wong policy describes state privacy rights, direct-marketing opt-out choices, and privacy-officer contact details. It describes marketing-data categories and says requests may require identity verification. Limitation: The current provider policy uses the Belardi Wong brand; the legal-entity relationship to the catalog name still requires explicit entity review.

Next review action: Confirm the legal-entity and brand relationship, then review the linked request routes before promoting any workflow detail.

Convex Labs LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-30) The policy identifies Convex Labs LLC and states that Convex is a division of ServiceTitan, Inc.; it distinguishes Convex processing from Customer User Data processed for customers.
  • Official source ↗ The official privacy-choices page offers opt-out, access, correction, and deletion request types and lists support@convexlabs.io as an alternative contact.

Next review action: Confirm whether the request route covers Convex’s own records or customer-user data before updating the catalog workflow.

Cybba Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2022-06-14) The policy describes Cybba digital-marketing services and distinguishes cookie/device opt-outs from marketing-email unsubscribe controls.
  • Official source ↗ (source date 2026-06-29) The current California notice supplements the older general policy and provides jurisdiction-specific disclosure context.

Next review action: Reconcile the older general policy with the current California notice and identify the current consumer request route before promotion.

Datonics LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-05-05) The technology policy describes cookies, hashed email addresses, and mobile advertising IDs and explains that opt-out choices can be browser- or device-specific. It states how Datonics treats Global Privacy Control and other opt-out preference signals where applicable.
  • Official source ↗ The privacy-choices page presents browser, mobile-device, and email privacy-rights paths and explains identifier-specific limitations.

Next review action: Confirm the live request controls and preserve browser/device/email scope separately before updating the workflow record.

MediaWallah Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-09-17) The policy describes MediaWallah services, opt-out paths for cookies and mobile advertising identifiers, and an opt-out portal for other identifiers or personal information. It provides privacy@mediawallah.com and a verifiable-request phone channel.

Next review action: Confirm the current portal URL and keep browser, mobile, CTV, and personal-information routes separate before promotion.

MULTIMEDIA LISTS, INC.

Reviewed 2026-09-25
  • Official source ↗ The policy identifies Multimedia Lists as a provider of data marketing and consumer analytics products used across direct mail, email, online, and connected-TV channels. Limitation: The page was not sufficient in the bounded review to confirm the current consumer request form or exact route semantics.
  • Official source ↗ The provider describes data licensing, appends, list brokerage, and list-management services and links to its privacy and Do Not Sell paths.

Next review action: Locate and independently review the current Do Not Sell / consumer request route before adding workflow details.

Nexxen Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-01) The services policy distinguishes Nexxen controller/business processing from client processor/service-provider processing. It describes industry tools, browser/device controls, Global Privacy Control, and a privacy-rights request page for opt-out, access, and deletion requests.
  • Official source ↗ The provider-stated privacy data-subject request route linked from the current services policy.

Next review action: Confirm the current privacy-center behavior and controller-versus-client scope before promoting the route.

Semcasting, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-04-01) The policy covers Semcasting and related services and describes consumer rights, Do Not Sell, and industry opt-out controls.
  • Official source ↗ The provider offers online, phone, and email privacy-choice channels and states a 10-to-30-day processing timeline for recorded selections.

Next review action: Confirm the current PrivacyChoice route, jurisdiction scope, and source date discrepancy before workflow promotion.

Taboola, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-04-10) The policy describes user access, correction, deletion, and targeted-advertising or sale opt-out rights. It states that opt-out choices operate at the browser and device level and distinguishes contextual recommendations from interest-based recommendations.

Next review action: Confirm the current access-request portal and preserve browser/device scope before updating the workflow record.

Viant US LLC

Reviewed 2026-09-25
  • Official source ↗ The privacy center is marked last updated July 2026, distinguishes platform privacy from website privacy, and presents separate opt-out and access/deletion/correction request paths. It describes targeted-advertising and sale/sharing choices and provides privacy@viantinc.com for certain business-contact requests.

Next review action: Confirm the platform privacy policy and live request controls, keeping business-contact and consumer platform scope separate.

VideoAmp, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-08) The offerings policy describes VideoAmp media measurement and optimization services and links to a specific personal-information opt-out path. It distinguishes browser, mobile-device, and connected-device advertising choices.
  • Official source ↗ The official privacy-rights request page records requests and responses under applicable privacy laws and provides privacy@videoamp.com for questions.
  • Official source ↗ The U.S. notice states that VideoAmp currently responds to browser-based Global Privacy Control signals.

Next review action: Confirm the form’s current request types and distinguish GPC handling from direct request submission before promotion.

Zeta Global

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-08-29) The policy separates website privacy from services privacy and describes access, deletion, sale/sharing, sensitive-data, email, and online-behavioral-advertising choices. It states that GPC and other universal opt-out signals are processed for sale/sharing requests.
  • Official source ↗ The privacy choices page distinguishes email-address and cookie-ID databases and instructs users to use the relevant mechanisms for each.
  • Official source ↗ The rights-request page allows a user to view, download, or request deletion of data associated with the current browser or mobile advertising identifier.

Next review action: Preserve the separate email and cookie/device route semantics and verify current request behavior before workflow promotion.

Clickagy

Reviewed 2026-09-25
  • Official source ↗ The privacy center separates access, deletion, do-not-sell/share, and correction choices and explains that requests are tied to the browser or device used. It identifies Clickagy as a data broker under Texas law and points to privacy@clickagy.com for correction questions.
  • Official source ↗ The privacy policy identifies Clickagy’s B2B buyer-intent and advertising technology context and links directly to the privacy center.

Next review action: Confirm the current request controls and preserve browser/device identity scope before workflow promotion.

i360, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-30) The current policy identifies i360, LLC and describes a consumer request portal for opting out of potential sale of covered information.

Next review action: Confirm the portal’s current request types and jurisdiction scope before updating the catalog workflow.

Path2Response, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-01) The policy describes Path2Response data marketing services and provides access, correction, deletion, and sale/sharing opt-out choices. It gives a Consumer Rights Portal and phone route and states that Data Services requests are limited to U.S. consumers.
  • Official source ↗ The provider describes its consumer privacy approach and points to the Consumer Rights Portal and phone PIN route.

Next review action: Confirm the current portal URL and preserve U.S.-only scope, identity verification, and request-type distinctions before promotion.

33 Mile Radius LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-04-01) The policy identifies 33 Mile Radius among the Ignite Visibility affiliates covered by the notice and describes personal-information practices across websites, communications, and offline interactions.
  • Official source ↗ The official page offers a do-not-sell/delete form and states that it responds to verifiable consumer requests from California residents.

Next review action: Confirm the affiliate/entity scope and preserve California-only route semantics before workflow promotion.

33Across, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2023-10-04) The policy describes 33Across advertising and publisher technology and explains cookie-based and cookie-less data collection. It says the provider opt-out applies to 33Across collection and uses persistent browser/device signals, while separate email and mobile-advertising-ID choices are limited to the submitted identifier.
  • Official source ↗ The official User Data Portal presents browser, email, access, erase, and do-not-sell choices and warns that browser/device changes can require a new opt-out.
  • Official source ↗ (source date 2025-07-08) The California notice links to the consumer request form and states that identity verification is required for certain requests.

Next review action: Confirm the current portal controls and preserve browser, device, and submitted-email scope separately before workflow promotion.

Anchor Computer Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-01) The policy identifies ANCHOR Computer and its affiliates as providers of consumer and business marketing data products sourced from data partners. It offers an ANCHOR database opt-out through a first-party link, email, or toll-free phone route and describes identity-verification fields.
  • Official source ↗ The policy links to this provider-controlled opt-out destination for ANCHOR database requests. Limitation: The bounded source review did not independently confirm the form’s current fields or completion behavior.

Next review action: Recheck the live opt-out form and preserve the provider-stated limitation that opting out of Anchor does not opt out of client or other-source databases.

AtData, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-16) The policy identifies AtData, LLC and describes collection from public sources, customers, data compilers, data brokers, resellers, advertising networks, and other partners. It describes marketing, identity-resolution, data-hygiene, anti-fraud, and analytics services and identifies AtData as a data broker under Texas law.
  • Official source ↗ The official opt-out form accepts requests concerning targeted advertising or cross-context behavioral advertising, sale, certain profiling, and direct marketing.
  • Official source ↗ (source date 2026-07-16) The policy separately provides a privacy-rights form, an opt-out page, mail, and phone channels and reports 2025 consumer-request metrics. Limitation: The source supports request channels and scope, not mailbox acceptance, delivery, completion, or deletion outcomes.

Next review action: Confirm the live privacy-rights form and preserve the distinction between general rights requests and sale/sharing or marketing opt-outs before promotion.

Audience Acuity

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-12-29) The policy describes Audience Acuity audience-data services for analytics, enrichment, direct mail, online display, and email marketing. It states that an opt-out of Audience Acuity’s proprietary database does not opt a person out of client databases and may retain information for risk, compliance, or anti-fraud purposes.
  • Official source ↗ The official consumer-rights form presents delete and access choices and requires identity-matching information such as name plus address, email, or phone.
  • Official source ↗ The privacy policy links to a separate opt-out-of-sale form for sale or targeted-advertising choices.

Next review action: Confirm the separate sale opt-out and rights-request form behavior, preserve client-database and retention exceptions, and only then assess workflow promotion.

Bookyourdata

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-25) The policy identifies Bookyourdata and describes business-to-business marketing data processing and privacy requests for access, deletion, and opt-out. It states that verified requests have separate response expectations and publishes 2025 California request metrics.
  • Official source ↗ The provider-controlled form offers do-not-sell/share and deletion choices, requires email confirmation before action, identifies the operator as A Direct Marketing Inc., and states a 15-business-day target for verified sale/sharing opt-outs.

Next review action: Recheck the live form and preserve the distinction between provider-stated response targets, request processing, and any independently verified outcome before workflow promotion.

Choreograph LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-10-02) The global policy identifies Choreograph as a WPP data and technology business and describes both online and offline data handling. It links to a Consumer Preference Portal for privacy rights, future-processing opt-out, and deletion requests and states that portal choices apply to the specific browser or device used.
  • Official source ↗ The provider-linked Consumer Preference Portal is the stated route for exercising rights through the preference center. Limitation: The bounded review confirms the provider-stated portal relationship but does not certify acceptance, delivery, or completion of a request.

Next review action: Confirm the portal’s current request types and preserve browser/device scope, offline-versus-online distinctions, and regional entity rules before promotion.

Exact Customer

Reviewed 2026-09-25
  • Official source ↗ (source date 2022-11-16) The California Department of Justice data-broker registration identifies Exact Customer, lists privacy@exactcustomer.com, and describes a California Privacy Notice and Do Not Sell path in the provider’s landing-page footers. The registration lists Exact Customer’s Connecticut address and records a phone opt-out route.
  • Official source ↗ The official California registration identifies this as the provider website. Limitation: The live provider site and the exact current privacy-request URL were not independently confirmed in the bounded review; retain the record as a registry-supported research candidate.

Next review action: Recheck the provider domain and locate the current first-party privacy notice or request form before adding any customer-ready route or timing detail.

Keyword Connects LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-07-25) The policy identifies Keyword Connects LLC and describes contact, device, cookie, marketing, affiliate, and third-party partner processing. It provides access, correction, erasure, export, California rights, identity-verification, and marketing-unsubscribe choices and reports California request metrics.
  • Official source ↗ The marketing policy provides unsubscribe instructions and privacy@keywordconnects.com for marketing-communication opt-out requests. Limitation: These pages describe site, marketing, and privacy-rights controls but do not by themselves confirm a current standalone data-broker suppression route for records held outside the Sites.

Next review action: Identify and independently review any broker-database or Do Not Sell route, keeping site-marketing unsubscribe separate from suppression of data held for third parties.

Minerva

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-03-31) The policy identifies Minerva BI Inc. and describes personal-information processing across online and offline Services, including data from customers, public records, data brokers, and other providers. It designates a webform at preferences.minerva.io and a toll-free number for access, correction, deletion, and sale/sharing opt-out requests and states that requests sent through other channels are redirected to the webform.
  • Official source ↗ The provider-stated preferences domain is the designated consumer-rights submission route. Limitation: The bounded review confirms the provider-stated destination but does not certify acceptance, delivery, or completion of a request.

Next review action: Confirm the current preferences form and preserve the designated-channel, identity-verification, and statutory timing details before workflow promotion.

DataPartners

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-02-10) The policy identifies Data Partners Inc. and describes direct-marketing information sourced from public records, subscriptions, warranties, surveys, point-of-sale information, website activity, mobile applications, affiliates, and partners. It provides a Manage Your Privacy Preferences route and a toll-free phone route for database opt-out requests.
  • Official source ↗ The official privacy-preferences page distinguishes sale, targeted-advertising, profiling, and deletion choices and provides 866-423-1818 for assistance.
  • Official source ↗ The California privacy page supplements the general policy with jurisdiction-specific rights context. Limitation: DataPartners explicitly says email and general contact forms are not valid privacy-request channels; retain the designated web and phone routes separately.

Next review action: Confirm the current preference-form behavior and preserve the provider-only database scope, suppression-versus-deletion distinction, and designated-channel rule before promotion.

NFocus

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-12-16) The policy identifies NFocus Consulting Inc., describes business and consumer data services, and identifies NFocus as a data broker under Texas law. It provides deletion and Do Not Sell request pages, a phone route, identity verification context, and 2024 California request metrics.
  • Official source ↗ The provider-linked page is the stated Do Not Sell or Share request route. Limitation: The bounded review confirms the policy-linked route but does not independently certify form acceptance, delivery, or completion.

Next review action: Confirm the live request pages and preserve address verification, state scope, statutory exceptions, and provider-versus-client boundaries before promotion.

Venntel

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01) The policy identifies Venntel, Inc. and describes location data received from partners, including latitude/longitude, mobile advertising IDs, IP address, application data, and device information. It describes data-services use, customer sharing, sale opt-out rights, a four-year retention period for data-services personal information, and a device-specific opt-out limitation.
  • Official source ↗ The official Opt Out & Delete Request page is the provider-stated route for location-data choices.
  • Official source ↗ (source date 2026-01) The provider publishes 2025 privacy-request metrics and states that the reported figures cover all individuals regardless of jurisdiction.

Next review action: Confirm the current form’s required mobile-advertising identifier and preserve device-specific scope, partner/customer boundary, retention exceptions, and request metrics as separate facts before promotion.

Wiland Direct

Reviewed 2026-09-25
  • Official source ↗ The policy identifies Wiland, Inc. and describes consumer-data use in marketing products and services, including information obtained from sources other than the Wiland website.
  • Official source ↗ (source date 2026-07-01) The current privacy-choice page offers opt-out, deletion, and access paths for U.S. consumers, provides a toll-free telephone route, and states that choices apply specifically to Wiland and the personal information it collects. The page documents identity and authorized-agent requirements and says requests should use the designated forms or phone channel.

Next review action: Confirm the current form destinations and preserve request-type, identity-verification, authorized-agent, and Wiland-only scope before workflow promotion.

Consumerbase, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2022-07-13) The California Department of Justice registration identifies Consumerbase LLC doing business as Exact Data, lists privacy@exactdata.com, and describes an email or website Do Not Sell route.
  • Official source ↗ The current Exact Data privacy page identifies Data Axle Inc. and affiliates as providers of consumer and B2B marketing data services and directs consumers to a Do Not Sell route or privacy email for rights requests. Limitation: The current policy is branded around Data Axle while the California registry names Consumerbase LLC d/b/a Exact Data; the legal-entity and route relationship requires explicit reconciliation.
  • Official source ↗ The provider describes Exact Data as a consumer and business data service and links to its privacy policy.

Next review action: Resolve the Consumerbase, Exact Data, and Data Axle entity relationship and recheck the live Do Not Sell route before adding customer-ready workflow details.

Lead Me Media LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-01-16) The policy identifies Lead Me Media, LLC and describes consumer-information collection through surveys, order forms, registrations, third-party sources, email, and SMS. It provides a dedicated policy portal, phone, and mailing route for privacy-rights requests and describes opt-out-of-sale/sharing, targeted-advertising, profiling, and marketing choices.
  • Official source ↗ The provider’s website privacy page separately describes email-list and SMS unsubscribe controls and notes that third-party websites and clients may have separate practices. Limitation: The older website policy and newer policy portal should not be merged into one route without confirming the current request destination and scope.

Next review action: Confirm the policy portal’s current form behavior and keep database, email, SMS, browser-signal, and third-party/client controls separate before promotion.

Cengage Learning, Inc. (Gale Directories)

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-02-17) The current Cengage Privacy Notice identifies Cengage Learning, Inc. and subsidiaries including Gale and provides general privacy-rights, sale/sharing, targeted-advertising, and deletion routes. It specifically directs consumers to a separate sale/sharing form for Gale Directory products and lists a privacy-rights form and phone route.
  • Official source ↗ (source date 2023-02-08) The California Department of Justice registration identifies Gale, lists privacy@cengage.com, and directs consumers to gale.com/privacy for CCPA requests and deletion requests. Limitation: The catalog record uses the Cengage domain and Gale Directories label; the exact current Gale product route and entity mapping require reconciliation before promotion.

Next review action: Confirm the current Gale Directory opt-out form and map the Gale/Cengage entity relationship, keeping product-specific sale/sharing choices separate from general Cengage account deletion.

Alliant Cooperative Data Solutions LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-29) The data-products policy identifies Alliant Cooperative Data Solutions, LLC and its subsidiaries and affiliates, including Analytics IQ, and expressly separates licensed Data Products from website visitor data. It describes identifiers, contact information, purchase behavior, interests, and other consumer information used in Data Products and links to Do Not Sell and sensitive-information controls.
  • Official source ↗ The current Alliant policy footer links to this provider-controlled privacy web form for Do Not Sell or Share and sensitive-information choices. Limitation: The form is hosted on a privacy-portal domain and its dynamic fields were not independently validated in the bounded review.
  • Official source ↗ Alliant publishes consumer-request statistics and identifies the website entity as a data broker under Texas law.

Next review action: Confirm the live portal fields and preserve Alliant-versus-AnalyticsIQ, website-versus-Data-Products, and FCRA-specific route boundaries before promotion.

Data Axle Inc

Reviewed 2026-09-25
  • Official source ↗ The policy identifies Data Axle as a data broker under Texas law, describes consumer and B2B data from public and third-party sources, and lists Exact Data among Data Axle affiliates. It recognizes Global Privacy Control and provides consumer and authorized-agent rights-request routes.
  • Official source ↗ The official consumer form presents access, sale/sharing opt-out, deletion, and correction choices and requires identifying contact information for verification.
  • Official source ↗ The provider offers a separate authorized-agent form and requires authority documentation for delegated requests.

Next review action: Reconcile Data Axle’s parent/affiliate routing with Exact Data and other catalog aliases, then preserve GPC, verification, and authorized-agent scope before promotion.

Altrata, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06) The Product Privacy Notice identifies Altrata people-intelligence products including BoardEx, RelSci, Wealth-X, and WealthEngine and states that information is processed for client-facing products. It provides access, correction, deletion, portability, objection, and sale/sharing choices, with identity verification and a California phone route.
  • Official source ↗ (source date 2026-06) The separate Online Privacy Notice covers website and online-platform data and identifies Altrata as part of Delinian. Limitation: The online notice and product notice cover different processing contexts; the product-data request route must not be inferred from website-cookie or marketing controls.

Next review action: Confirm the current product-rights contact and map Altrata, Delinian, and named product entities before adding a customer-ready route.

Claritas LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-05-08) The current notice identifies Claritas, LLC as a data-driven marketing company and a registered data broker under California, Oregon, Texas, and Vermont law. It separates offline marketing-database opt-out, digital/browser opt-out, marketing-email unsubscribe, access, correction, deletion, and appeal routes and states that U.S. scope applies to Claritas services.
  • Official source ↗ The policy links to a provider-controlled portal for offline and digital privacy choices. Limitation: The portal is dynamic and the bounded review did not independently validate its current field set or completion behavior.

Next review action: Confirm the current portal controls and keep offline database, digital identifier, email, GPC, and U.S.-only scope distinct before workflow promotion.

First Direct, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2020-01-30) The California Department of Justice registration identifies First Direct, Inc., lists support@firstdirectmarketing.com, and states that consumers may search and submit CCPA requests or protected-person deletion requests through alerts.com. Limitation: This is a historical registration record; the registry states that legacy California registrations cover 2020-2023, so the current operating entity and live route require a fresh check.
  • Official source ↗ The provider hosts a first-party privacy policy and links it from the current First Direct site. Limitation: The bounded review did not independently validate the current request workflow or reconcile the provider policy with the registry-listed Alerts.com route.
  • Official source ↗ The California registration names Alerts.com as the search and request destination for First Direct consumers. Limitation: The route is hosted on a separate domain; its current relationship to First Direct and request completion behavior were not independently validated.

Next review action: Recheck the current Alerts.com relationship and preserve the historical registry date, provider identity, and request-route uncertainty before promotion.

Speedeon Data LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-21) The Data Products Privacy Policy identifies Speedeon Data LLC and describes consumer information assembled and provided to customers primarily for marketing purposes. It documents privacy rights and opt-out choices for sale, sharing, targeted advertising, profiling, and sensitive personal information, plus authorized-agent and contact routes.
  • Official source ↗ The provider-controlled opt-out form offers deletion, opt-out, and sensitive-data choices and states that an approved request adds the submitted name and address to a suppression file; the form limits each request to one name and address. Limitation: The bounded review confirms provider-stated form behavior only and does not certify acceptance, delivery, deletion, or suppression completion.

Next review action: Recheck the live form and preserve the distinction between suppression, deletion, sale/sharing, sensitive-data, identity, and U.S.-address scope before promotion.

WINR Data

Reviewed 2026-09-25
  • Official source ↗ The provider describes WINR as an identity-resolution, identity-verification, address-intelligence, KYC, and fraud-prevention data business with coverage across multiple geographies.
  • Official source ↗ The provider’s contact page directs data-subject access or suppression requests to privacy@winrdata.com or a secure web form.
  • Official source ↗ The provider-linked OneTrust form presents consumer, household, parent or guardian, and authorized-agent request roles and asks for jurisdiction and identity details. Limitation: The dynamic portal and its current legal-entity, geography, and request-completion behavior were not independently validated in the bounded review.

Next review action: Locate and date the current first-party privacy notice, confirm the portal’s live controls, and keep identity verification, fraud prevention, digital advertising, and jurisdiction scope separate before promotion.

Yes

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07) The current Platform Privacy Policy identifies PubMatic, Inc. and global subsidiaries and describes SSP and advertising-platform processing involving online identifiers, device and browser information, audience segments, geolocation, behavioral information, and ad interactions. It separates platform privacy from PubMatic website privacy and PubMatic US, Inc. policy contexts and documents state-law opt-out and data-rights choices.
  • Official source ↗ (source date 2026-05) The provider’s opt-out page describes browser- or device-specific choices for interest-based advertising, mobile advertising IDs, and cross-device targeting and states that opting out does not stop all advertising.
  • Official source ↗ The current PubMatic legal pages link to this provider-controlled opt-out tool for platform advertising choices. Limitation: The dynamic tool was not independently tested for acceptance or completion. The catalog name was corrected from "Yes" (a CA registry DBA-column artifact) to PubMatic on 2026-09-06; the legal entity mapping to PubMatic Inc. was already correct.

Next review action: Preserve browser, device, mobile-advertising-ID, CTV, platform, and website-policy scope before promotion.

Dataline, Inc.

Reviewed 2026-09-25
  • Official source ↗ The policy identifies Dataline as a data broker under Texas law and describes opt-out choices for sale, sharing, limited use, and online targeted advertising. It states that Dataline treats opt-out of sale, sharing, and limited use as deletion requests and distinguishes browser or device advertising opt-outs from its direct privacy route.
  • Official source ↗ The provider privacy portal presents access, delete or Do Not Sell, cross-contextual behavioral advertising, and correction choices and provides a verification step for the request. Limitation: The bounded review confirms the provider-stated portal and request types but does not certify submission acceptance, delivery, deletion, or suppression completion.
  • Official source ↗ (source date 2020-02-27) The California Department of Justice registration identifies Dataline, Inc., lists privacy.officer@datalinedata.com, and records the provider website and California request-verification process. Limitation: This is a historical registration record; the current operating details and request behavior must be rechecked against the live provider policy.

Next review action: Confirm the current portal fields and preserve sale, sharing, limited-use, browser-advertising, California-verification, and deletion semantics as separate facts before promotion.

Reveal Mobile, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-11-08) The policy identifies Reveal Mobile, Inc. and describes its location-measurement business, mobile-product data, device identifiers, and website processing. It states that the Mobile Product is opt-in, describes device and app-level controls, and offers a U.S. privacy form for access, deletion, and sale opt-out requests.
  • Official source ↗ The provider’s consumer privacy form states that consumers may request that location data not be used or sold and offers optout@revealmobile.com as an alternate contact route. Limitation: The bounded review confirms the provider-stated form and email route but does not certify acceptance, delivery, device matching, deletion, or sale-opt-out completion.
  • Official source ↗ (source date 2021-12-10) The California Department of Justice registration identifies Reveal Mobile, lists privacy@revealmobile.com, and records the historical CCPA route and privacy policy. Limitation: The registry points to a legacy /ccpa/ path; the current privacy form should be treated as the live candidate only after route reconciliation.

Next review action: Reconcile the historical /ccpa/ route with the current privacy form and preserve opt-in, mobile-advertising-ID, location, device, customer, and website scope before promotion.

Tunnl, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-21) The current policy identifies Tunnl, LLC, is effective as of June 2026, and expressly covers individuals without a direct relationship whose information is processed through client services. It describes rights to opt out of targeted advertising, sale, and certain profiling and provides notice@tunnldata.com for a privacy request context.
  • Official source ↗ (source date 2022-01-28) The California Department of Justice registration identifies Tunnl, LLC and records historical CCPA opt-out, information, and deletion routes using dedicated email addresses and a toll-free number. Limitation: The registry routes are historical; the current policy and live request-channel relationship require explicit reconciliation before using the older email or phone details in customer-facing workflow.
  • Official source ↗ The current privacy policy identifies the provider CCPA page as a source for data-collection and privacy-rights information. Limitation: The bounded review did not independently validate the current CCPA page fields or request-completion behavior.

Next review action: Confirm the current designated request channel and preserve direct-relationship, client-service, targeted-advertising, sale, profiling, jurisdiction, and legacy-contact boundaries before promotion.

Unacast

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01) The current policy identifies Unacast, Inc. and separates Data Services from website processing, including information received from third-party data suppliers. It provides sale opt-out, access, deletion, and privacy-request choices and states that Data Services opt-out is specific to the submitted device and may need to be repeated after a mobile-advertising-ID reset.
  • Official source ↗ The provider’s Opt Out & Delete Request page offers a form for sale opt-out and related privacy questions and identifies privacy@unacast.com as an alternate route. Limitation: The bounded review confirms the provider-stated form but does not certify acceptance, delivery, device matching, deletion, or opt-out completion.
  • Official source ↗ (source date 2022-02-10) The California Department of Justice registration identifies Unacast, Inc., lists privacy@unacast.com, and records the provider webform for know, delete, and sale opt-out requests. Limitation: The registration is historical; retain it as registry context rather than proof that a current request was accepted or completed.

Next review action: Confirm the current form and preserve Data Services versus website scope, device-specific location choices, mobile-advertising-ID reset behavior, supplier/customer boundaries, and request outcome limits before promotion.

Xcelerated Data LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-01) The policy identifies Xcelerated LLC and its subsidiaries and affiliates and describes data products used for direct mail, email, display, social, television, and radio marketing. It provides access, correction, deletion, sale/sharing, targeted-advertising, and profiling rights and says the database opt-out applies to Xcelerated’s proprietary database rather than clients’ databases.
  • Official source ↗ (source date 2026-01-01) The provider’s alternate privacy page describes the Xcelerated database opt-out and states that an opt-out is forward-looking and may not remove data from client databases or risk, compliance, and anti-fraud products. Limitation: The provider exposes both xcelerated.com and www.xcelerated.com privacy URLs; the exact live form destination and request-completion behavior were not independently validated.

Next review action: Reconcile the two provider privacy URLs and current form destination, then preserve proprietary-database, client-database, risk/compliance, marketing-channel, verification, and forward-looking scope before promotion.

Veraset, LLC

Reviewed 2026-09-25
  • Official source ↗ The policy identifies Veraset, LLC and describes GPS location and device-level point-of-interest data products supplied to clients for advertising, research, urban planning, customer insights, and analytics. It provides device settings and a provider form for hashed email, mobile advertising identifiers, location data, and related data, and states that the choice is device-specific and must be repeated after a mobile-advertising-ID reset.
  • Official source ↗ The provider’s request page presents consumer sale, sharing, and targeted-advertising choices and identifies a mobile-advertising-ID workflow for the data-solution opt-out. Limitation: The dynamic request flow was not independently tested for acceptance, device matching, deletion, or completion.
  • Official source ↗ (source date 2020-03-23) The California Department of Justice registration identifies Veraset, lists privacy@veraset.com, and records a historical opt-out path requiring email and mobile advertising ID. Limitation: The registry references a legacy /do-not-sell-my-info path; reconcile it with the current legal request page before using either URL as a customer-ready route.

Next review action: Confirm the current form destination and preserve hashed-email, mobile-advertising-ID, location, device-specific, reset, client, and legacy-registry route boundaries before promotion.

Webbula, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-03-26) The current notice identifies Webbula, LLC, describes online and offline data services, and distinguishes its direct database opt-out from cookie-based industry opt-outs. It states that a direct opt-out suppresses personal information from Webbula’s active marketing databases and identifies a provider form and phone route.
  • Official source ↗ The provider privacy center offers opt-out, data access, appeal, and privacy-notice paths and states that an opt-out removes information from data services and adds the person to a forever suppression. Limitation: The bounded review confirms provider-stated suppression language but does not certify acceptance, delivery, or suppression completion.
  • Official source ↗ (source date 2020-02-07) The California Department of Justice registration identifies Webbula, LLC, records its privacy center, email, phone, and mailing routes, and describes its data hygiene and customer-insight services. Limitation: The registration is historical and contains older address and phone details; prefer the current provider privacy center after reconciliation.

Next review action: Confirm the current privacy-center form and preserve direct-database, active-marketing, forever-suppression, cookie-based advertising, data-hygiene, and historical-registry scope before promotion.

Azerion US Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-07-01) The current global notice identifies Azerion Group N.V. and its affiliates and subsidiaries and covers services, advertisements, mobile applications, products, and data received from business partners. It provides access, correction, deletion, objection, portability, and data-protection-officer contact through dpo@azerion.com.
  • Official source ↗ The provider’s Inskin-specific notice describes a service-specific privacy context, direct-marketing controls, and data-subject rights through dpo@azerion.com. Limitation: The Inskin notice is product-specific and must not be generalized to every Azerion or Azerion US processing context.
  • Official source ↗ (source date 2022-09-01) The website notice provides separate website-processing, deletion, and data-subject-rights context and identifies Azerion Services B.V. as the website operator. Limitation: The notice is older and website-specific; it is supporting context only, not proof of a current advertising-data or Azerion US request route.

Next review action: Map Azerion Group, Azerion Services B.V., Azerion Technology B.V., Inskin, and the catalog’s Azerion US label, then confirm the current service-specific request route before promotion.

Belardi Ostroy, ALC, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-27) The current policy identifies Belardi Wong and states that it is limited mainly to website collection except for the State Privacy Rights section. It describes direct-marketing opt-out choices for U.S. residents, site advertising and analytics controls, and a Privacy Officer contact at privacy.officer@belardiwong.com and 800-252-5478. Limitation: The policy expressly excludes most offline and service processing; it cannot by itself establish the route for data held in Belardi Wong’s marketing services.
  • Official source ↗ The provider’s alternate privacy URL is retained as a first-party route candidate for the Belardi Wong privacy context. Limitation: The bounded review did not independently confirm whether this alternate URL is current or whether its direct-marketing form differs from the canonical policy page.

Next review action: Resolve the Belardi Ostroy, Belardi Wong, and Acxiom relationship and locate the current service or offline-database request route, keeping website, direct-marketing, and client-service controls separate before promotion.

Convex Labs LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-01-30) The policy identifies Convex Labs LLC, states that Convex is a division of ServiceTitan, Inc., and covers the Convex and Atlas websites, applications, products, services, tools, and features. It describes consumer privacy choices and directs users to the provider request-removal route for applicable rights.
  • Official source ↗ The provider request form offers access, deletion, correction, and sale opt-out request types, asks for user type and state, and provides support@convexlabs.io as an alternate route with possible identity verification. Limitation: The bounded review confirms the provider-stated request form but does not certify acceptance, delivery, entity matching, or completion.
  • Official source ↗ Convex’s privacy-compliance page states that it maintains a California data-broker registration and offers a Do Not Sell form. Limitation: This page is provider context rather than an independently verified registry record; preserve the California registration claim separately until the current registry entry is matched.

Next review action: Reconcile Convex Labs, Convex, ServiceTitan, and the Atlas product entities, then verify the current data-broker registration and request route before promotion.

Cybba Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-12-04) The current California notice identifies Cybba Inc., describes identifiers, commercial and online activity, geolocation, client and advertising-network disclosures, and lists access, deletion, and opt-out rights. It provides a current Do Not Sell route and a phone route with verification requirements and response-timing information.
  • Official source ↗ (source date 2022-06-14) The general policy describes Cybba’s digital-marketing services and distinguishes website, mobile, cookie, client, and interest-based-advertising choices. Limitation: The general policy is older than the California notice; use the newer jurisdiction-specific notice for current California request semantics and keep general marketing unsubscribe separate.
  • Official source ↗ (source date 2021-05-06) The California Department of Justice registration identifies Cybba Inc. and records a historical OneTrust request flow, email verification, and phone fallback for CCPA opt-out requests. Limitation: The registry route and phone details are historical; reconcile them with the current CCPA notice before using the flow as a customer-ready route.

Next review action: Confirm the current OneTrust destination and preserve California verification, client versus Cybba processing, cookie/mobile scope, marketing unsubscribe, and historical phone-route boundaries before promotion.

Datonics LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-05-05) The current Technology Privacy Policy identifies Datonics as a New York-based advertising-technology company and states that it is considered a data broker under certain state laws. It describes cookies, hashed emails, mobile advertising IDs, browsing and search data, partner sources, targeted advertising, cross-device association, and Global Privacy Control treatment.
  • Official source ↗ The privacy-choices page offers browser, mobile-device, hashed-email, access, deletion, correction, sale/sharing, targeted-advertising, and sensitive-information choices. It documents browser-cookie, mobile-advertising-ID, and particular-email scope and explains that choices may need to be repeated after cookie, browser, device, or advertising-ID changes. Limitation: The dynamic form behavior was not independently tested for acceptance, delivery, or completion.
  • Official source ↗ The provider privacy center separates website, technology, Data Privacy Framework, Shopify app, and privacy-choice contexts. Limitation: Do not merge the website and technology policies into one request route; the catalog record requires technology-data scope.

Next review action: Confirm the current privacy-choice form and preserve browser, mobile-advertising-ID, hashed-email, cookie, cross-device, GPC, website, and technology-policy boundaries before promotion.

MediaWallah

Reviewed 2026-09-25
  • Official source ↗ The provider policy describes MediaWallah services involving cookies, mobile and CTV identifiers, hashed email, device linkage, advertising measurement, audience targeting, and data shared with clients and partners. It distinguishes promotional-email unsubscribe from service-level tracking and identifies a cookie opt-out, industry opt-outs, and a separate portal for other identifiers or personal information. Limitation: The bounded review did not resolve the linked portal destination or independently validate the current form behavior.
  • Official source ↗ The first-party domain is retained as the provider context for MediaWallah’s privacy policy and service materials. Limitation: A website or marketing unsubscribe must not be presented as proof of removal from MediaWallah’s service data or client databases.

Next review action: Resolve and verify the current service-data privacy portal, then preserve cookie, mobile, CTV, hashed-email, device-linkage, client, partner, website, and marketing-email boundaries before promotion.

Multimedia Lists, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2021-12-14) The policy identifies Multimedia Lists, Inc. and describes consumer and analytics data used for direct mail, email, online, connected-TV, and other marketing channels. It distinguishes opt-out of sale or marketing-database suppression from deletion of information collected directly from a consumer and notes that service-provider requests may need to go through the named client. Limitation: The policy is dated and the live Do Not Sell form destination was not independently resolved in the bounded review.
  • Official source ↗ The California Department of Justice registration identifies Multimedia Lists, Inc. and records an Alerts.com route for opt-out and deletion requests. Limitation: The registry route is historical and must be reconciled with the current provider privacy page before promotion.
  • Official source ↗ The provider contact page supplies current first-party business contact context for Multimedia Lists. Limitation: General sales contact is not a verified privacy-request route.

Next review action: Recheck the current Do Not Sell destination and preserve marketing-database suppression, direct-collection deletion, client-service, connected-TV, and historical Alerts.com scope before promotion.

Nexxen Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-01) The current Services Privacy Policy describes Nexxen’s global advertising technology services across web, mobile, CTV, linear television, and digital channels and identifies device, browsing, location, ad-interaction, inferred-segment, and transaction data. It separates controller or business processing from client processor or service-provider processing and documents access, deletion, correction, sale/sharing opt-out, authorized-agent, and appeal contexts.
  • Official source ↗ The provider-linked Privacy Center is the stated route for consumer privacy rights and targeted-advertising opt-out requests. Limitation: The dynamic privacy center was not independently tested for acceptance, delivery, entity matching, or completion.
  • Official source ↗ (source date 2023-09-15) The California Department of Justice registration identifies Nexxen Inc and records a historical opt-out tool hosted at yourdata.tremorinternational.com. Limitation: The registry uses legacy Tremor branding and a different route from the current Nexxen Privacy Center; preserve this as entity and route history, not current workflow proof.

Next review action: Reconcile Nexxen Inc, Nexxen International, Tremor, Amobee, and client-processor contexts, then verify the current Privacy Center before promotion.

Semcasting, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-04-01) The provider policy identifies Semcasting, Inc. and covers Semcasting, IDToolbox, Audience Designer, and PrivacyChoice services. It provides access, correction, deletion, sale opt-out, communications opt-out, privacychoice.com, phone, and email routes and states a 15-business-day outer target for sale opt-outs. Limitation: The page displays both a 2026 last-updated label and a July 16, 2025 effective-date statement; retain both dates rather than collapsing them.
  • Official source ↗ The current Privacy Choice page offers profile visibility, category-level opt-in or opt-out, global Do Not Sell, phone and email routes, and provider-stated permanent recording within Semcasting data. Limitation: The provider-stated 10-to-30-day timeline and permanent-recording language are not independent proof of request acceptance or completion.

Next review action: Confirm the current PrivacyChoice form and reconcile the policy date discrepancy, then preserve identity-resolution, advertising, analytics, category choice, U.S.-only, and provider-stated timing boundaries before promotion.

Blis Global Ltd

Reviewed 2026-09-25
  • Official source ↗ The provider policy identifies Blis Global Ltd as the parent controller and describes online advertising, cookies, mobile advertising IDs, IP address, browsing behavior, audience segments, location, and cross-device use. It describes access, deletion, correction, sale or sharing opt-out, identity verification, authorized agents, and the distinction between interest-based advertising opt-out and continued non-personalized ads.
  • Official source ↗ The current California rights page provides Blis’s privacy email and toll-free coded route, identity-verification requirements, authorized-agent handling, and 2025 request metrics. Limitation: The provider-stated metrics and route availability are not independent proof of acceptance, delivery, or completion for a specific request.
  • Official source ↗ (source date 2022-02-25) The California Department of Justice registration identifies Blis Global Ltd, records its privacy email, and names the historical CCPA route and privacy centre. Limitation: The registration is historical; preserve it as registry context and prefer the current provider rights page for route semantics.

Next review action: Confirm the current privacy-center route and preserve Blis Global versus local trading-company scope, advertising versus website context, device identifiers, consent, authorized-agent, and non-personalized-ad boundaries before promotion.

Realeflow, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-07-01) The provider’s July 2024 policy describes Realeflow, LLC processing across its website, real-estate-investing software, services, and other individuals whose information comes under its control. It documents marketing-call, text, email, direct-mail, sale opt-out, access, and deletion choices, including a provider form, phone, email, and a stated 30-business-day marketing-unsubscribe target. Limitation: The policy’s web links are dynamic or unresolved in the bounded review; do not infer that a marketing unsubscribe automatically removes service or sale data.
  • Official source ↗ (source date 2022-08-02) The provider privacy page is a first-party policy route and separates promotional communications from service, administrative, and transactional messages. Limitation: The page displays an older August 2022 version while a July 2024 provider PDF is also available; retain both versions and verify which is current before promotion.
  • Official source ↗ The current provider site footer exposes a Do Not Sell My Personal Information link. Limitation: The footer confirms a provider-linked route candidate but not the destination’s current semantics or request completion.

Next review action: Resolve the current Do Not Sell form and policy version, then preserve marketing-channel, service-account, sale, access, deletion, transactional-message, and 30-business-day scope before promotion.

Wiza, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-02-28) The policy identifies Wiza, Inc. as a B2B data provider and describes professional contact-information enrichment, account, website, and service processing. It documents access, correction, deletion, sale, targeted-advertising, profiling, GPC, authorized-agent, identity-verification, and appeal contexts.
  • Official source ↗ The provider opt-out form asks for first name, last name, multiple email addresses, and phone numbers, requires email confirmation, and states that it prevents contact information from being transmitted to Wiza end users. Limitation: The provider’s live request domain is wiza.co while the catalog domain is wiza.com; the form does not by itself establish removal from every Wiza product or public directory.
  • Official source ↗ (source date 2026-01-29) The provider help article distinguishes contact-data opt-out from a separate Wiza Directory opt-out and states that the contact form does not remove a public directory profile. Limitation: The help article is operational guidance, not proof that a submitted request was accepted or completed.

Next review action: Reconcile the catalog wiza.com label with Wiza, Inc. and the live wiza.co routes, then preserve contact-data, directory, account, client, GPC, identity, and request-confirmation scope before promotion.

LionShare Marketing, Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-09-17) The provider policy describes LionShare website collection, healthcare data analytics and marketing-automation context, cookies, promotional communications, and a separate opt-out page for database removal. It states that the online policy applies to website data and not offline collection and publishes 2025 CCPA request metrics. Limitation: The website-versus-offline limitation means the policy cannot alone establish the scope of the marketing database or every customer data service.
  • Official source ↗ The current provider opt-out form requires first name, last name, street address, city, state, ZIP, and optionally email, indicating an address-based matching workflow. Limitation: The bounded review confirms the provider-stated form fields but does not certify acceptance, delivery, matching, deletion, suppression, or completion.

Next review action: Confirm the current privacy policy and database scope, then preserve website versus offline, address matching, marketing, healthcare-data, CCPA, and request-outcome boundaries before promotion.

DealerX Partners LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-03-20) The provider page identifies DealerX Partners, LLC, separates Website and Platform processing, states that DealerX does not sell or license consumer data to third parties, and offers complete opt-out, data-inquiry, correction, and authorized-agent choices. It documents browser-and-device cookie scope and identity verification for requests.
  • Official source ↗ The provider contact page identifies DealerX Partners and states that, as of September 2024, it no longer tracks or collects data from California residents. Limitation: General contact details are not a privacy-request route; the privacy-options page remains the designated candidate.
  • Official source ↗ The provider agreement describes DealerX platform collection involving business-provided PII, addresses, cookies, email addresses, IP addresses, and mobile identifiers for automotive marketing, targeting, analytics, and optimization. Limitation: This is a business agreement and supporting service context, not consumer-request or completion evidence.

Next review action: Confirm the current privacy-options form and preserve Website versus Platform, browser/device, California cessation, automotive-client, authorized-agent, and no-sale/licensing scope before promotion.

Five Star Rated

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-04-01) The current policy identifies Five Star Rated LLC within the Ignite Visibility affiliate group and covers websites, social media, communications, and offline interactions. It describes targeted advertising and marketing communications and identifies the state-rights context for the provider’s consumer choices.
  • Official source ↗ The provider form offers Do Not Sell and Delete choices for California, Colorado, Connecticut, Utah, and Virginia residents and requires contact details for verification. Limitation: The form’s jurisdiction restriction and dynamic behavior were not independently tested for acceptance, delivery, or completion.

Next review action: Map Five Star Rated LLC to Ignite Visibility and its listed affiliates, then preserve state scope, marketing, targeted-advertising, deletion, identity, and affiliate-processing boundaries before promotion.

Lookify.io

Reviewed 2026-09-25
  • Official source ↗ The policy describes Lookify’s public-information phone lookup and aggregates consumer indexes, directories, property records, social networks, and business directories. It clearly states that the opt-out removes public listings on Lookify.io only and cannot remove information from third-party public sources, and it provides separate privacy-rights and Texas data-broker contexts.
  • Official source ↗ The provider’s opt-out destination is the stated route for removing public listings from Lookify.io. Limitation: The bounded review confirms the provider-stated route but does not certify request acceptance, matching, delivery, or completion.
  • Official source ↗ The California statement provides access, deletion, correction, portability, and opt-out rights and identifies the same opt-out page and verification context. Limitation: Public-listing removal, account deletion, and rights requests are separate actions and must not be merged.

Next review action: Keep Lookify listing removal, account deletion, third-party public sources, Texas data-broker rights, California rights, and identity verification as separate workflow facts before promotion.

General Motors LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-17) The current U.S. Consumer Privacy Statement identifies General Motors Holdings LLC and U.S. affiliates and covers online and offline products, services, websites, apps, connected-vehicle features, vehicle data, marketing, and privacy rights. It provides access, correction, deletion, sale, targeted-advertising, automated-processing, GPC, authorized-agent, appeal, and 45-day processing contexts.
  • Official source ↗ The provider’s U.S. Consumer Privacy Request Form is the designated request route, with 1-866-MYPRIVACY as the phone alternative and no email request acceptance. Limitation: The form’s live acceptance and completion behavior were not independently tested.
  • Official source ↗ The provider privacy center separates consumer choices and opt-out rights from other GM privacy resources. Limitation: The GM statement excludes GM Financial, General Motors Insurance, dealers, and third-party services; those entities require separate evidence.

Next review action: Preserve GM U.S., OnStar, vehicle, dealer, GM Financial, insurance, third-party-service, GPC, authorized-agent, and request-channel boundaries before treating this corporate profile as customer-ready.

Cision

Reviewed 2026-09-25
  • Official source ↗ The current Cision ID Opt-Out page provides a do-not-sell-or-share route through privacy@cision.com and a toll-free privacy number, and links to the journalist and influencer profile context. Limitation: The live submission and completion behavior were not independently tested.
  • Official source ↗ (source date 2024-04-11) The Cision US, Inc. policy covers information collected online and offline and describes media-intelligence, journalist, influencer, and communications use cases. It documents access, correction, erasure, objection, direct-marketing, and California sale-or-sharing rights and identifies Cision US, Inc. as the policy entity.
  • Official source ↗ The influencer notice states that individuals in Cision media or social-influencer databases may request profile amendment or removal from those databases by emailing privacy@cision.com. Limitation: The influencer database route is distinct from Cision customer, prospect, Brandwatch, and PR Newswire contexts.

Next review action: Reconcile Cision US, Cision Ltd, Brandwatch, PR Newswire, journalist, influencer, customer, and prospect contexts, then verify the current request route and preserve profile-removal versus marketing-subscription boundaries before promotion.

Socialgist; Boardreader

Reviewed 2026-09-25
  • Official source ↗ The policy identifies Effyis, Inc. d/b/a Socialgist and applies to consumers whose personal information appears in online social conversations that Socialgist monitors or receives from content partners, including forums, blogs, news, reviews, and social platforms. It expressly identifies the website operator as a data broker under Texas law and provides access, correction, deletion, sale opt-out, appeal, and authorized-agent contexts.
  • Official source ↗ The first-party domain is retained as the current provider context for Socialgist and the Boardreader registered-name alias. Limitation: A home page or brand alias does not by itself establish a separate Boardreader request route.

Next review action: Use privacy@socialgist.com for the current consumer route only after matching the relevant social handle or username, and preserve Socialgist, Boardreader, content-partner, source-platform, identity-verification, and 45-day-response boundaries before promotion.

The Org

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-11-17) The Org states that it processes professional data such as employer, job title, and professional contact information and offers an opt-out flow to prevent a person from appearing on The Org. It says the work email is used as the unique key for positions and retained to prevent re-addition, and provides privacy@theorg.com as an alternate route. Limitation: The provider states that personal or anonymous email addresses may not work for the individual opt-out flow.
  • Official source ↗ (source date 2025-06-09) The provider support article distinguishes individual profile removal from company-level requests, requires a work-email match for the individual route, and asks requesters to include the relevant profile link when using email. Limitation: Provider support guidance does not independently prove acceptance, deletion, suppression, or future non-republication.
  • Official source ↗ (source date 2024-11-13) The Org privacy policy identifies Orgio, Inc. and states that public org-chart data may come from public web pages, news, company team pages, and contributors; it provides access, correction, deletion, and restriction contexts. Limitation: The Org states it does not provide or collect consumer data in its do-not-sell notice; retain the professional-directory scope and do not generalize it to consumer data.

Next review action: Preserve The Org and Orgio, Inc. identity, professional-only data scope, individual position-page matching, company requests, work-email verification, suppression-retention, crowdsourced re-addition, and email-versus-web-route boundaries before promotion.

MH Sub I, LLC

Reviewed 2026-09-25
  • Official source ↗ The current policy identifies MH Sub I, LLC dba Internet Brands and affiliates, covers sites, services, applications, and software, and describes contact, profile, transaction, location, device, health, employment, and user-submitted information contexts. It provides access, update, deletion, marketing opt-out, identity-verification, retention, and third-party sharing contexts, including situations where an online request may be shared with a broker, aggregator, lender, dealer, or financial institution. Limitation: The policy applies only to sites and services that display or link to it; acquired companies and services may retain separate policies until integrated.
  • Official source ↗ The provider privacy-contact route is the current candidate for privacy-rights requests and is linked from the Internet Brands policy context. Limitation: The live form acceptance, entity selection, field requirements, and completion behavior were not independently tested.
  • Official source ↗ The corporate site identifies MH Sub I, LLC dba Internet Brands, its verticals, affiliates, corporate contact details, and the privacy-policy relationship. Limitation: Corporate ownership and a broad affiliate portfolio do not prove that one request removes information from every Internet Brands site, affiliate, acquired business, or third-party service.

Next review action: Map the specific Internet Brands site or service holding the record before sending a request, then preserve MH Sub I, affiliate, acquired-company, health, legal, finance, marketing, public-content, site-policy, and third-party-broker boundaries before promotion.

PossibleNOW, Inc.

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-03-11) The current PossibleNOW policy identifies PossibleNOW, Inc. and PossibleNOW Services, Inc. and applies to the listed PossibleNOW sites. In its data-broker context, PossibleNOW says it makes certain third-party-licensed data available to customers, including digital marketers, advertising partners, and ad-tech companies, for online and offline marketing. Limitation: The policy excludes data provided by customers under service agreements and vendors under data-sourcing agreements; those contractual data contexts require separate scope analysis.
  • Official source ↗ (source date 2025-01-29) The California supplement describes access, deletion, sale opt-out, authorized-agent, and targeted-advertising choices and points to an online privacy-rights or do-not-sell route and postal mail. Limitation: The page’s live form destination and current field requirements were not independently tested.
  • Official source ↗ The current provider site exposes Manage My Privacy Rights and Do Not Sell links and identifies PossibleNOW as a consent, preference, and data-analytics company. Limitation: Marketing unsubscribe and cookie preferences must not be treated as deletion or suppression from licensed customer data.

Next review action: Resolve the current privacy-rights destination and preserve PossibleNOW, PossibleNOW Services, DNC Solution, MyPreferences, licensed third-party data, customer or vendor contract data, website data, sale opt-out, targeted advertising, and marketing-unsubscribe boundaries before promotion.

FordDirect

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-25) The current FordDirect privacy statement identifies website, application, social-media, software, and service processing and lists categories sold or shared under California terminology, including identifiers, commercial information, online activity, geolocation, and inferences. It provides Your Privacy Choices, webform, phone, Global Privacy Control, identity-verification, authorized-agent, and 45-calendar-day response contexts. Limitation: The statement says dealer or dealer-association processing may be independent or controller-specific and may require a request to the relevant dealer.
  • Official source ↗ FordDirect says separate requests should be submitted for separate CCPA rights, receipt may be confirmed within 10 days, and requests involving dealer service-provider processing should identify the dealer. Limitation: A FordDirect request does not establish deletion from Ford Motor Company, a dealer, a dealer association, or an independent supplier.
  • Official source ↗ (source date 2020-02-07) The California Department of Justice registration identifies DealerDirect LLC doing business as FordDirect and preserves the historical registry privacy email, website, and request context. Limitation: The registry record is historical; the current FordDirect privacy statement and current form are the preferred route evidence.

Next review action: Reconcile FordDirect, DealerDirect LLC, Ford Motor Company, dealer, dealer-association, and supplier roles, then verify the current webform and preserve GPC, state, B2B, dealer, separate-right, identity, and 45-day boundaries before promotion.

Buyerlink Inc.

Reviewed 2026-09-25
  • Official source ↗ The current Buyerlink domain exposes a Do Not Sell or Share My Personal Information route whose page embeds a OneTrust privacy portal. Limitation: The embedded portal’s field requirements, entity selection, verification, acceptance, and completion behavior were not independently tested.
  • Official source ↗ The current Buyerlink privacy route is linked from the provider’s legal footer and is retained as the policy context for the current buyerlink.co domain. Limitation: The privacy page is dynamically rendered in the bounded review and did not expose its substantive policy text; do not infer policy scope or rights beyond the named first-party route.
  • Official source ↗ Buyerlink exposes a separate email-unsubscribe route that accepts an email address. Limitation: Email unsubscribe is a marketing-communication control and is not proof of sale opt-out, deletion, or suppression from lead-generation systems.
  • Official source ↗ The current catalog retains a California registry context for Buyerlink Inc and the provider’s legal or route history. Limitation: The bounded review did not resolve a current direct registry record URL; preserve registry identity and route evidence separately until reconciled.

Next review action: Reconcile Buyerlink Inc, Buyerlink.com, buyerlink.co, One Planet Group, lead-generation, publisher, marketplace, cookie, privacy-portal, and email-unsubscribe contexts before promotion; do not infer deletion from the unsubscribe route.

Remodeling.com, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-04-01) The current policy identifies Ignite Visibility and affiliates including Remodeling.com LLC, covers website, social, communications, and offline interactions, and describes identifiers, contact details, project information, device and online activity, marketing, and partner processing. It states that the policy does not govern information processed for enterprise customers as a service provider or processor.
  • Official source ↗ The current form allows California residents to request Do Not Sell and Delete choices, does not require an account, and asks for name, email, phone, address, California residence, and ZIP information; the provider may verify identity. Limitation: The form is explicitly limited to verifiable California consumer requests and its dynamic submission behavior was not independently tested.
  • Official source ↗ The provider terms identify Remodeling.com as a home-project lead and matching platform and state that homeowner submissions may result in email, telephone, mobile, SMS, mail, or fax contact by Remodeling.com and affiliates. Limitation: Contact consent, marketing unsubscribe, data-broker suppression, and deletion are separate workflow actions.

Next review action: Map Remodeling.com LLC to Ignite Visibility and its affiliates, then preserve California-only form scope, homeowner versus contractor data, enterprise-client processing, partner lead sharing, marketing consent, deletion, and current privacy-email boundaries before promotion.

SheerID

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-03-10) The Global Privacy Policy identifies SheerID, Inc. and affiliates and distinguishes SheerID-controlled Remember Me and Audience Services from verification processing performed for Clients, where the Client is the controller. It documents access, correction, deletion, portability, sale or sharing, targeted-advertising, authorized-agent, identity-verification, and 45-day-response contexts.
  • Official source ↗ (source date 2024-03-28) The Audience Development notice describes audience profiles and the sharing or sale of names, email addresses, birth dates, employer, educational institution, employment title, student status, medical-professional status, and military status to customer retailers. It provides a Privacy Center Do Not Sell route available regardless of residence and states that the entity maintaining the website is a data broker under Texas law. Limitation: This audience-data notice is distinct from client-controlled verification transactions and does not establish removal from a retailer or other SheerID client.
  • Official source ↗ The current policy gives privacy@sheerid.com, 1-833-317-3372, and Privacy Choices routes and says verification may use recent-interaction details such as account information, name, address, email, or phone. Limitation: The live Privacy Choices form was not independently tested for acceptance, delivery, or completion.

Next review action: Reconcile SheerID, Inc., Audience Development, Remember Me, verification-client, retailer, government-ID, and marketing-preference contexts, then preserve controller-versus-processor scope and current Privacy Center verification before promotion.

Disqus

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-07-10) The current policy describes Disqus as a public comment platform and marketing or data company collecting through Disqus and service-enabled third-party websites, and describes sale or sharing, targeted advertising, cookies, device and browser identifiers, hashed email, IP, professional or educational data, and data-broker or advertising-partner disclosures. It provides access, correction, deletion, sale or sharing opt-out, sensitive-data limitation, email opt-out, GPC, authorized-agent, and identity-verification contexts. Limitation: The policy does not control the independent privacy practices of publisher websites where Disqus is embedded.
  • Official source ↗ (source date 2026-06-05) The provider help article distinguishes commenter account-level data-sharing settings from publisher-level tracking controls and states that commenters can disable data sharing through the Disqus settings route or supported browser signals. Limitation: A data-sharing preference is not equivalent to deletion of account, comment, publisher-site, ad-partner, or downstream data copies.
  • Official source ↗ The provider help article separates account deletion or export from profiles managed by publisher websites and points users to a Disqus data-rights form. Limitation: Publisher-managed profiles and third-party reposts require separate review.

Next review action: Reconcile Disqus account, comment, publisher-embedded, cookie, ad-partner, Zeta, data-broker, GPC, and privacy-form contexts, and replace stale aggregate metrics with the current 2025 statistics before promotion.

Narvar, Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-07-08) The current Narvar policy identifies Narvar, Inc. as a software platform provider and separates corporate, Consumer Services, and Fraud Prevention Services processing. It provides access, correction, deletion, portability, objection, sale or sharing, targeted-advertising, profiling, sensitive-data, authorized-agent, and identity-verification contexts.
  • Official source ↗ The policy links the current Narvar Privacy Rights Tool for privacy requests and states that requests involving Merchant Services processed solely on behalf of a merchant must be directed to the relevant merchant. Limitation: The live form field requirements, acceptance, delivery, and completion behavior were not independently tested.
  • Official source ↗ The policy states that Narvar does not honor browser DNT signals, provides a corporate marketing unsubscribe distinction, and exposes separate privacy settings for California sale or sharing choices. Limitation: A marketing unsubscribe or Narvar corporate request does not establish removal from the relevant merchant, carrier, retailer, fraud customer, or third-party systems.

Next review action: Map Narvar corporate, Consumer Services, Fraud Prevention Services, Merchant Services, merchant controller, and downstream retailer contexts, then verify the Privacy Rights Tool and preserve processor-versus-controller, profiling, GPC, marketing, and request-channel boundaries before promotion.

AutoWeb, Inc.

Reviewed 2026-09-25
  • Official source ↗ The current AutoWeb site identifies AutoWeb, Inc., exposes a Privacy Policy, Do Not Sell or Share, and Unsubscribe footer route, and identifies Autodata, Inc. dba Chrome Data as a source of some content. Limitation: The substantive privacy policy is dynamically rendered in the bounded review; do not infer current request semantics beyond the linked first-party routes.
  • Official source ↗ The current AutoWeb Privacy Request Form is the provider-linked route for Do Not Sell, deletion, and other privacy requests. Limitation: The live form’s field requirements, acceptance, verification, and completion behavior were not independently tested.
  • Official source ↗ (source date 2023-02-02) The California Department of Justice registration identifies AutoWeb, Inc., records the privacy form, ConsumerCare@autoweb.com, and 800-267-2015, and describes sale opt-out and protected-person deletion routes. Limitation: The registration is historical; prefer the current AutoWeb footer and Privacy Request Form for route semantics.
  • Official source ↗ The current provider contact page identifies Consumer Support and Dealer Sales and Services at 844-205-9097 and distinguishes general business contact from consumer support. Limitation: General contact and dealer support are not substitutes for the privacy request form unless the provider directs the requester there.

Next review action: Reconcile AutoWeb, Autodata, Chrome Data, dealer, OEM, advertising, partner, consumer-support, unsubscribe, sale opt-out, and protected-person deletion contexts before promotion; retain the current OneTrust route as review-only until its live behavior is verified.

DataX Ltd. Consumer Opt-Out

Reviewed 2026-09-25
  • Official source ↗ The current DataX consumer route identifies DataX as an Equifax company and explains five-year and permanent opt-out choices for prescreen lists. Limitation: This route concerns prescreen-list use and does not establish deletion from all Equifax systems, credit files, downstream users, or other databases.
  • Official source ↗ The official permanent opt-out notice lists the information and signature fields for a permanent prescreen opt-out and states that the request becomes effective within five days after receipt. Limitation: The provider-stated timing is an effectiveness estimate for the prescreen route, not a guarantee of universal suppression or removal.
  • Official source ↗ The provider describes DataX as a credit-information services provider and separates consumer-report, prescreen, dispute, and identity-related contexts. Limitation: Credit-reporting, FCRA, dispute, freeze, and prescreen rights must not be merged into a generic data-broker deletion workflow.

Next review action: Preserve DataX, Equifax, prescreen-list, permanent-versus-five-year, FCRA, credit-report, dispute, freeze, identity, postal, and sensitive-information boundaries before promotion; never describe this route as erasing a credit file or downstream copies.

Harmon Research Group, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-06-06) The first-party policy describes Harmon Research survey participation as voluntary and consent-based and provides a route to request removal from its database or calls and email lists. Limitation: The published policy is older than the current review date; confirm the live policy and exact request semantics before promotion.
  • Official source ↗ (source date 2020-02-07) The California registry identifies Harmon Research Group, LLC as a registered data broker and lists its consumer request contact context. Limitation: The registry is historical and supporting evidence only; it does not prove current form acceptance, deletion, or non-republication.

Next review action: Recheck the current Harmon Research policy, then preserve survey-participant consent, study invitations, calls, email lists, database removal, sale or sharing scope, identity matching, and copies held by research clients before promotion.

Preferred Communications

Reviewed 2026-09-25
  • Official source ↗ The first-party domain exposes a consumer opt-out route for the cataloged Preferred Communications entity. Limitation: The bounded review did not independently test the live form’s fields, verification, acceptance, delivery, or completion behavior.
  • Official source ↗ (source date 2023-02-24) The California Department of Justice registry identifies Preferred Communications and lists the same consumer opt-out route, privacy email, sale opt-out, CCPA request, and protected-person deletion context. Limitation: The registry is historical; retain current first-party route evidence and registry identity separately until reconciled.

Next review action: Confirm the current consumer form and entity relationship, then preserve sale opt-out, access, deletion, protected-person, minimum-matching-data, verification, email, and registry-history boundaries before promotion.

Results Only Consulting and Advertising (ROC Advertising)

Reviewed 2026-09-25
  • Official source ↗ (source date 2019-12-27) The first-party policy describes direct-mail and marketing use cases and says ROC may receive consumer data from a data broker for one-time mailing lists. It directs a Data Removal Request to privacy@rocadvertising.com and describes access, correction, deletion, sale or rental opt-out, identity matching, and possible additional verification. Limitation: The policy is dated and contains an inconsistent privacy-email spelling in one section; use the consistently published address only after current route recheck.
  • Official source ↗ The current provider homepage identifies ROC Advertising as a direct-mail and marketing business. Limitation: A current homepage does not by itself update or supersede the dated privacy-policy terms.

Next review action: Recheck the current ROC policy and privacy mailbox, preserve one-time mailing, data-broker source, rental or sale, ten-day advertising, 45-day request, identity, authorized-agent, and email-typo boundaries before promotion.

BLACK KNIGHT DATA & ANALYTICS, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-01-01) The current ICE Privacy and Security Center states that Black Knight, Inc. is now part of Intercontinental Exchange and preserves the Black Knight privacy policy. It provides access, correction, deletion, sale or sharing, targeted-advertising, GPC, authorized-agent, identity-verification, and public-record-suppression contexts. Limitation: The successor page covers multiple ICE and Black Knight contexts; it does not prove that one request reaches every lender, servicer, mortgage broker, affiliate, or client-held record.
  • Official source ↗ The current ICE privacy web form is the provider-stated route for privacy-rights requests. Limitation: The live form’s entity selection, field requirements, acceptance, and completion behavior were not independently tested.
  • Official source ↗ The historical Black Knight domain is retained as the catalog entity context while the current privacy route is served through ICE. Limitation: A legacy domain and successor relationship do not establish a separate current Black Knight route or removal from client systems.

Next review action: Reconcile Black Knight Data & Analytics, Black Knight Inc, ICE, ICE Mortgage Technology, lender, servicer, mortgage-broker, public-record-suppression, employment, affiliate, and client-controller boundaries before promotion.

IQ Data Systems, Inc. dba Backgrounds Online

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-01-18) The first-party Backgrounds Online policy identifies I.Q. Data Systems dba Backgrounds Online, describes consumer-reporting and privacy-rights contexts, and says deletion requests may be limited by retention exceptions. It states that the provider generally does not accept deletion requests except in some account-closure contexts and may require identity information for non-account requests. Limitation: The policy does not establish a universal people-search opt-out route; a consumer-report disclosure or FCRA dispute route may be the appropriate path.
  • Official source ↗ The current first-party product page describes background screening, identity, criminal, employment, education, and consumer-report services. Limitation: Product descriptions are scope evidence, not proof of a consumer request route or deletion outcome.
  • Official source ↗ The cataloged provider privacy-policy destination remains a first-party route candidate for Backgrounds Online privacy context. Limitation: The bounded review did not independently confirm a current stable page at this exact URL or a current form accepting a generic removal request.

Next review action: Reconcile IQ Data Systems, Backgrounds Online, consumer-report, FCRA, employment-screening, report-access, dispute, account, identity-verification, retention, and client-employer contexts before promotion; do not present it as a generic public-record deletion route.

CoStar Realty Information, Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-04-01) The current CoStar Global Privacy Notice identifies CoStar Realty Information, Inc. and affiliates, covers commercial-real-estate products and services, and describes access, correction, deletion, portability, sale or sharing, targeted-advertising, and profiling rights in listed jurisdictions. Limitation: The notice covers multiple CoStar products, marketplaces, affiliates, and service contexts; it does not by itself prove that a request reaches every brand, customer, or public-record source.
  • Official source ↗ The current CoStar Data Privacy Portal identifies the request route, requires a separate request type per submission, asks the requester to select a CoStar brand or service, and lists name, email, address, state, ZIP, and phone fields. Limitation: The portal currently states that the form is temporarily unavailable; do not present it as an independently confirmed live submission route until rechecked.
  • Official source ↗ The provider cookie policy separates browser-based targeted-advertising controls from broader privacy-rights requests. Limitation: Cookie choices and marketing unsubscribe are not equivalent to deletion or suppression from CoStar product or directory records.

Next review action: Recheck the CoStar portal availability and preserve CoStar product, marketplace, Professional Directory, commercial-real-estate, affiliate, cookie, GPC, brand-selection, one-request-per-submission, and identity-matching boundaries before promotion.

PublicRecordCom, LLC

Reviewed 2026-09-25
  • Official source ↗ The current PublicRecord.com Data Privacy Rights page offers separate access, user-data deletion, and people-search-result opt-out choices. It states that the result opt-out applies whether or not the requester is a member and may take 5–7 days to take effect, with search-engine removal potentially taking longer. Limitation: The page distinguishes account/user-data deletion from people-search-result removal; neither proves deletion from public records, upstream sources, search engines, or third-party copies.
  • Official source ↗ The current contact page identifies PublicRecord.com LLC and states that it is not a consumer reporting agency under the FCRA. Limitation: The FCRA disclaimer is scope context and does not establish a privacy-request completion outcome.
  • Official source ↗ The current provider site presents people, phone, address, and public-record search services. Limitation: Search functionality and public-record aggregation do not by themselves prove the exact sources or persistence of an individual listing.

Next review action: Preserve PublicRecordCom identity, people-search-result opt-out, account deletion, public-record source, search-engine reindexing, FCRA disclaimer, identity matching, and downstream-copy boundaries before promotion.

Compact Information Systems (d/b/a Deep Sync)

Reviewed 2026-09-25
  • Official source ↗ The first-party policy describes Deep Sync marketing-data services, licensed information, customer and partner sharing, consumer attributes, and access, deletion, and sale opt-out rights. It states that a deletion request may need to be distinguished from an opt-out because suppression records can be retained to prevent future sale. Limitation: The policy is older than the current review date; use the current privacy portal for route fields and recheck policy freshness before promotion.
  • Official source ↗ The current Compact Information Systems privacy route redirects to the Deep Sync privacy center and exposes a Do Not Sell form with requester role, name, email, additional emails, phone numbers, and current or prior addresses. Limitation: The form’s acceptance, identity-verification, and completion behavior were not independently tested.
  • Official source ↗ The current provider route is the Deep Sync opt-out destination for suppression and privacy choices, while the provider distinguishes corporate or client-data requests from consumer opt-out requests. Limitation: A consumer opt-out does not establish deletion from client databases, partner systems, or downstream copies.

Next review action: Reconcile Compact Information Systems, Deep Sync, HomeData, listed legacy brands, consumer suppression, deletion, corporate/client data, partner licensing, prior addresses, and identity-verification boundaries before promotion.

Quorum Analytics

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-22) The current Quorum privacy policy identifies Quorum Analytics Inc. and affiliates, covers websites, apps, and services, and provides access, correction, erasure, objection, restriction, and applicable sale or sharing request contexts. It directs U.S. privacy requests to privacy@quorum.us and says requests should identify the request type in the subject line. Limitation: Quorum’s policy distinguishes its own controller processing from client or service-provider contexts; one request may not reach client-controlled data.
  • Official source ↗ (source date 2026-06-22) The policy says it aims to acknowledge applicable U.S. requests within 10 days and substantively respond within 45 days, with a possible additional 45 days when reasonably needed; it requests name and email for verification. Limitation: These are published response aims, not a guarantee of deletion, suppression, or removal from backups, aggregate data, de-identified data, deletion records, or client copies.
  • Official source ↗ The provider’s current product context describes policy-influencer and public-affairs data services, which helps distinguish professional or public-individual profile scope from ordinary consumer people-search records. Limitation: Product marketing material is scope evidence, not proof that a particular profile is present or that an email request was accepted.

Next review action: Preserve Quorum Analytics, public-affairs, policy-influencer, professional-profile, client-controller, public-information, retention, email-request, verification, and response-window boundaries before promotion.

FREEPEOPLESEARCH.COM, LLC

Reviewed 2026-09-25
  • Official source ↗ The current FreePeopleSearch Data Privacy Rights page separates user-data deletion from people-search-result opt-out, states that opt-out removes the requester from its search results whether or not they are a member, and publishes a 5–7 day effectiveness estimate. Limitation: The stated timing is provider guidance for its own results; it does not establish removal from search engines, public records, upstream sources, or other people-search sites.
  • Official source ↗ (source date 2022-08-01) The provider policy identifies FreePeopleSearch.com, states that it sells information and reports obtained from public records, and describes access, correction, deletion, sale opt-out, identity verification, and third-party-platform boundaries. Limitation: The general policy is dated; use the current privacy-rights page for route semantics and recheck the policy before promotion.
  • Official source ↗ The current FAQ confirms that the provider’s opt-out is intended to remove records shown on its own site. Limitation: A provider-site result removal is not universal deletion or non-republication.

Next review action: Reconcile FreePeopleSearch, public-record report, people-search result, account data, sale opt-out, identity verification, search-engine indexing, third-party platform, FCRA disclaimer, and 5–7-day scope before promotion.

USPeopleSearch.com, LLC

Reviewed 2026-09-25
  • Official source ↗ The cataloged privacy-rights URL currently redirects to the US People Search homepage, whose first-party content describes people-search, public-record, phone, address, and background-search services. Limitation: The redirect did not expose a current privacy-request form or stable opt-out workflow in the bounded review; do not treat the legacy route as confirmed.
  • Official source ↗ The current provider policy describes personal-information collection, cookies, advertising technology, and privacy choices, including third-party advertising controls. Limitation: The current policy route did not provide a confirmed people-search-result removal workflow in the bounded review.
  • Official source ↗ The current terms identify USPeopleSearch.com and distinguish electronic-communication unsubscribe controls from broader privacy rights. Limitation: Email or text unsubscribe is not equivalent to removal from people-search results or public-record data.

Next review action: Resolve a current first-party USPeopleSearch privacy or result-removal route and confirm the legal operator before promotion; retain the redirect, people-search, public-record, advertising, email-unsubscribe, and FCRA-scope limitations.

Peoplewhiz, Inc

Reviewed 2026-09-25
  • Official source ↗ The cataloged first-party PeopleWhiz domain is retained as the provider context for the registered entity. Limitation: The bounded review could not retrieve the current provider page or confirm a current privacy-rights form, fields, verification, or completion behavior.
  • Official source ↗ The California historical Data Broker Registry is the official source context for the cataloged Peoplewhiz registration, public contact, and consumer-request history. Limitation: The bounded review did not resolve a stable individual Peoplewhiz registration URL; historical registry content is not proof of a current route.

Next review action: Resolve the current PeopleWhiz privacy or result-removal route and exact legal entity before promotion; preserve historical registry, people-search, profile-removal, identity, and route-availability uncertainty.

Riv Data Corp. dba Carpe Data

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-04-14) The current policy identifies RIV Data Corp. d/b/a Carpe Data, describes a business-to-business insurance-data and analytics company, and states that it collects personal information from third-party data sources and clients for insurance underwriting and claims contexts. It describes access, correction, erasure, restriction, objection, portability, sale, California opt-out, and identity-verification rights. Limitation: Carpe’s client-provided claimant and insured data may be governed by client agreements or legal exceptions; a direct Carpe request may not reach client-controlled records.
  • Official source ↗ (source date 2025-04-14) The policy directs rights requests to RightToKnow@carpe.io and provides 877-342-2773 for California requests; it requires identity verification and says responses will be provided within the applicable legal period. Limitation: The policy does not promise deletion of all client, legal, retained, or third-party source copies.
  • Official source ↗ The current provider site describes Carpe as an insurance decision and intelligence platform, confirming the professional and insurance-data scope. Limitation: Corporate product context does not by itself establish that a particular individual profile is present.

Next review action: Reconcile RIV Data Corp, Carpe Data, Carpe, insurance carrier, claimant, insured, third-party-source, client-controller, public-web, score or inference, identity, sale, and retention boundaries before promotion.

InCheck Inc

Reviewed 2026-09-25
  • Official source ↗ The current InCheck privacy page identifies InCheck, Inc. as a consumer reporting agency governed by the FCRA and describes background-screening information, authorized screening purposes, employer or landlord recipients, and legal retention or disclosure boundaries. Limitation: The policy does not establish a generic people-search opt-out or universal deletion route; consumer-report access, correction, and dispute processes require separate treatment.
  • Official source ↗ The provider’s current contact and candidate-help context identifies InCheck as a background-screening service and exposes the public support route. Limitation: The general support route does not by itself confirm the consumer-request fields, identity verification, or FCRA dispute workflow.
  • Official source ↗ The current first-party site provides the company and screening-service context for InCheck. Limitation: A company homepage is not proof of a privacy-request submission or report correction outcome.

Next review action: Preserve InCheck, consumer-reporting, FCRA, employer or landlord authorization, report access, dispute, correction, legal retention, identity verification, and support-route boundaries before promotion; do not present it as a generic marketing broker.

AGR Marketing Solutions LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2020-05-04) The California Department of Justice historical registration identifies AGR Marketing Solutions LLC, its public email, website, and the registered consumer-request URL. Limitation: The registry-listed route uses HTTP and a generic sample-page path; the registration itself is historical and does not prove a current functioning request route.
  • Official source ↗ The cataloged first-party domain is retained as the provider context for AGR Marketing Solutions. Limitation: The bounded review could not safely retrieve the current provider page or confirm current privacy policy, fields, identity verification, or completion behavior.

Next review action: Recheck the current AGR domain and privacy route over HTTPS, reconcile the historical sample-page registration, and preserve email, lead or marketing, identity, route-availability, and registry-history boundaries before promotion.

ReallyGreatRate, Inc

Reviewed 2026-09-25
  • Official source ↗ The current RGR Marketing site identifies lead-generation services for mortgage, solar, and home-improvement businesses and provides a business contact route. Limitation: The public site’s lead-generation content does not by itself expose a current consumer privacy request form.
  • Official source ↗ The California historical registry identifies ReallyGreatRate, Inc. dba RGR Marketing and states that its consumer-facing sites include Do Not Sell My Info links. Limitation: The bounded review did not resolve a stable individual registration URL or independently confirm a current consumer-facing link, form fields, verification, or completion behavior.

Next review action: Resolve the current RGR consumer-facing Do Not Sell route and reconcile ReallyGreatRate, RGR Marketing, mortgage, solar, home-improvement lead, consent, telephone, email, registry, and identity boundaries before promotion.

Knowledge Works, Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2020-02-27) The California Department of Justice historical registration identifies Knowledge Works, Inc. d/b/a PayNet, lists Equifax’s privacy route and public email, and records that PayNet does not post personal information online in the protected-person context. Limitation: The registration is historical and does not by itself establish current PayNet or Equifax workflow semantics.
  • Official source ↗ The official registry points to the Equifax privacy request route for the cataloged PayNet entity. Limitation: The live Equifax form’s current fields, entity selection, verification, acceptance, and completion behavior were not independently tested.
  • Official source ↗ The Equifax privacy statement distinguishes consumer-reporting activity, financial and employment information, third-party data providers, public records, and applicable FCRA or GLBA contexts. Limitation: Equifax’s broad corporate policy does not prove that a request removes PayNet commercial-credit records, consumer reports, client-held data, or legally retained information.
  • Official source ↗ The historical registry identifies PayNet as the registered website context, while current Equifax materials identify PayNet as an Equifax business. Limitation: The domain, entity, acquisition, and current privacy-route relationships require separate reconciliation before promotion.

Next review action: Reconcile Knowledge Works, PayNet, Equifax, commercial-credit, consumer-reporting, FCRA, GLBA, client, identity, government-ID, registry, and current-domain boundaries before promotion; never frame this as a generic people-search deletion route.

Trestle Solutions, Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-10-07) The Trestle notice identifies Trestle Solutions, Inc. and covers Trestle APIs, identity-verification products, the website, business interactions, and individual end users. It provides access, correction, deletion, portability, sale or sharing opt-out, marketing, and identity-verification contexts. Limitation: The accessible notice is older than the current review date; confirm the current policy and route before promotion.
  • Official source ↗ The notice identifies this first-party page as the CCPA request route and provides data@trestleiq.com as an alternative, with name, phone, address, and email used for verification when needed. Limitation: The bounded review did not independently test the live form’s acceptance, delivery, or completion behavior.
  • Official source ↗ The provider DPA distinguishes customer personal information, customer responsibility for consumer requests, and Trestle assistance or deletion on customer direction. Limitation: Customer-controller data may require a request to the relevant customer rather than a direct Trestle request.

Next review action: Reconcile Trestle Solutions, Trestle IQ, identity verification, API, customer-controller, customer data, data-subject, sale opt-out, deletion, suppression, and policy-freshness boundaries before promotion.

AnalyticsIQ Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-05-13) The current AnalyticsIQ policy is posted for Alliant Cooperative Data Solutions and affiliates, including AnalyticsIQ, and distinguishes website information from personal information processed in its Data Products. It provides access, deletion, correction, sale or sharing, targeted-advertising, GPC, authorized-agent, and verification contexts. Limitation: The policy covers Alliant and AnalyticsIQ together; entity and route selection must remain explicit.
  • Official source ↗ The current consumer privacy page says consumers may access, opt out of the marketing database, or request deletion through the OneTrust portal or by calling 833-533-1388. Limitation: The live OneTrust form’s field requirements, identity matching, acceptance, and completion behavior were not independently tested.
  • Official source ↗ The current provider site describes people-based marketing data and directs consumers to its privacy page for marketing-database controls. Limitation: Marketing-data suppression is separate from website cookie choices, company-email unsubscribe, customer-held copies, and other Alliant services.

Next review action: Reconcile AnalyticsIQ, Alliant Cooperative Data Solutions, affiliates, marketing database, Data Products, website data, OneTrust, phone, GPC, deletion, opt-out, and customer-copy boundaries before promotion.

Share Local Media, Inc

Reviewed 2026-09-25
  • Official source ↗ The California historical registration identifies Share Local Media, Inc. and lists a California Residents Rights Request Form and privacy email context for opt-out, CCPA requests, and protected-person deletion. Limitation: The registry is historical and does not establish current form fields, identity verification, acceptance, delivery, or completion.
  • Official source ↗ The cataloged first-party privacy subdomain is retained as the provider’s current route candidate. Limitation: The bounded review could not safely retrieve the page; do not treat the route as confirmed until independently rechecked.
  • Official source ↗ The cataloged first-party policy URL is retained as the current policy candidate for the provider domain. Limitation: The bounded review could not safely retrieve the page or confirm current request semantics.

Next review action: Recheck Share Local Media’s HTTPS privacy center and policy, then reconcile current entity, California form, protected-person, email, identity, sale opt-out, deletion, and registry-history boundaries before promotion.

Advertise4Sales LLC

Reviewed 2026-09-25
  • Official source ↗ The cataloged first-party 4LegalLeads removal URL is the provider-stated route candidate for CCPA opt-out or deletion requests. Limitation: The bounded review encountered a cache miss; live form fields, entity selection, acceptance, verification, and completion were not independently confirmed.
  • Official source ↗ The cataloged first-party lawyer FAQ is retained as context for the 4LegalLeads and Advertise4Sales relationship and legal-lead service scope. Limitation: The bounded review timed out; do not infer current privacy or lead-disclosure semantics from the unavailable page.
  • Official source ↗ The first-party domain is retained as the provider context for the cataloged Advertise4Sales entity. Limitation: A reachable domain alone does not establish a current privacy request route or removal from leads already delivered to customers.

Next review action: Recheck 4LegalLeads over HTTPS, verify Advertise4Sales legal-name and brand mapping, and preserve lead-delivery, customer-copy, CCPA, removal-form, email, identity, and route-availability boundaries before promotion.

Catalina Marketing Corporation

Reviewed 2026-09-25
  • Official source ↗ The current Catalina site describes shopper-data, audience, CPG marketing, media activation, and consumer-relationship services and identifies a current Your Privacy Choices link in the footer. Limitation: The public site’s corporate and marketing context does not itself prove the current privacy form’s fields or completion behavior.
  • Official source ↗ The provider-linked OneTrust Privacy Web Form is the current route candidate for Catalina privacy choices. Limitation: The live form exposed no bounded text fields in review; acceptance, verification, and completion behavior were not independently tested.
  • Official source ↗ The current legal page preserves Catalina’s policy and privacy-choice navigation and confirms the active provider domain. Limitation: Catalina’s current ownership or affiliate relationship, including the site’s Infillion acquisition reference, requires separate entity reconciliation before promotion.

Next review action: Reconcile Catalina Marketing Corporation, Catalina, Infillion, shopper, purchase, audience, CPG, privacy-choice, OneTrust, sale, deletion, marketing, and affiliate boundaries before promotion.

People Data Labs

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-07-01) The current People Data Labs policy identifies People Data Labs, Inc., describes professional, hiring, marketing, fraud, and business-to-business data services, and provides opt-out, access, correction, deletion, marketing, authorized-agent, and identity-verification contexts. It states that an opt-out prevents the provided information and associated data from being shared or made available through its products. Limitation: The policy permits certain operational, legal, aggregate, de-identified, customer, or otherwise legally allowed processing to continue.
  • Official source ↗ The current first-party Do Not Sell form asks for full name and email and states that submission stops future sale of personal information. Limitation: The live form’s identity matching, confirmation, acceptance, and downstream customer propagation were not independently tested.
  • Official source ↗ The provider explains its proprietary and public data sources, privacy-rights handling, and that API opt-outs or deletions are applied immediately while licensed-data customers receive changes in future builds. Limitation: Customer-held copies and delivery schedules are separate from the provider’s own suppression state.
  • Official source ↗ The Subject Request API documentation explains how customer systems receive opted-out IDs, making downstream customer propagation a distinct operational context. Limitation: API documentation does not prove that every customer has applied a request or that all downstream copies were deleted.

Next review action: Reconcile People Data Labs, professional data, marketing, hiring, fraud, public sources, Privacy Center, API versus licensed-data delivery, subject-request propagation, customer copies, identity, and deletion boundaries before promotion.

Media.net Advertising FZ-LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-22) The current policy identifies Media.Net Advertising FZ-LLC and describes advertising technology, online identifiers, device identifiers, general location, third-party data, and consumer privacy rights. It links to a privacy-rights request route, a sale-or-sharing opt-out, GPC handling, and privacy@media.net. Limitation: The policy says much of the stored information may identify a browser or device rather than a directly named individual, and a request may be treated as a sale opt-out when identity cannot be verified.
  • Official source ↗ The first-party preferences page presents privacy-rights requests and sale-or-sharing or targeted-advertising preference controls by jurisdiction. Limitation: The bounded review did not independently test form acceptance, verification, or completion.
  • Official source ↗ The first-party opt-out page describes a browser-cookie choice for interest-based advertising and explains that the choice is browser-specific and does not stop data collection. Limitation: This is an advertising-cookie preference, not proof of deletion from all Media.net records or partner-held copies.

Next review action: Reconcile Media.net Advertising FZ-LLC, advertising technology, browser/device identifiers, privacy-rights request, sale-or-sharing, GPC, cookie opt-out, partner processing, email, identity, and deletion boundaries before promotion.

Coast Technology, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2024-10-01) The first-party policy identifies Coast Technology I, LLC and describes data products, website design, marketing-data services, third-party data providers, public sources, and consumer data categories. It describes NAI and DAA interest-based advertising choices, GPC, state privacy rights, and info@dealershiptoolkit.com. Limitation: The policy is dated October 2024 and the provider-stated privacy route was not independently confirmed in the bounded review.
  • Official source ↗ The first-party California policy describes access, deletion, correction, sale opt-out, and a stated target of responding to opt-out-of-sale requests within 15 business days. Limitation: The page does not by itself confirm current form fields, identity checks, acceptance, or completion.
  • Official source ↗ The first-party dashboard domain provides context for the cataloged Dealership Toolkit relationship. Limitation: A login dashboard is not a public consumer privacy request route.

Next review action: Confirm Coast Technology I, LLC versus Dealership Toolkit and dashboard identity, locate the current public request route, and preserve advertising-cookie, sale, deletion, email, identity, and client-held-data boundaries before promotion.

Exact Match Marketing Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-02-04) The current policy identifies Exact Match Marketing Inc and describes a data-driven marketing platform, third-party data providers, data brokers, audience cohorts, targeted advertising, profiling, and state privacy rights. It provides a Do Not Sell or Share link and an email route for opt-out, deletion, access, correction, and profiling requests, with a stated 45-day response period for applicable requests. The policy states that Exact Match is registered as a data broker in California, Vermont, Texas, and Oregon. Limitation: The policy distinguishes client-uploaded data processed for clients from Exact Match-controlled data; requests about client-uploaded records may need to go to the client.
  • Official source ↗ The first-party terms connect the software platform to marketing, advertising, data, analytics, data-cleansing, and lead-generation functions and reference the privacy policy. Limitation: Terms do not prove that a public privacy form accepts or completes a consumer request.

Next review action: Reconcile Exact Match Marketing Inc, platform, third-party data, client-uploaded data, data-broker registrations, Do Not Sell, email, identity, request timing, profiling, and client-versus-controller boundaries before promotion.

InMarket Media, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-02-12) The current policy identifies InMarket Media, LLC and describes mobile applications, SDKs, advertising, measurement, audience segments, purchase or receipt data, hashed identifiers, and precise geolocation contexts. It provides opt-out, access, deletion, correction, sensitive-information, GPC, phone, and first-party form routes and states that browser/device advertising choices are scoped to the device or browser. The policy publishes 2024 California request statistics, including 17,450 opt-outs and 55,981 deletions, with no denials reported and a seven-day median for each. Limitation: Advertising opt-out does not stop advertising, and device or browser choices do not by themselves prove deletion from all InMarket or partner-held records.
  • Official source ↗ The first-party AdChoices page is an advertising-choice route and links back to the current privacy policy. Limitation: AdChoices is not equivalent to a general deletion request.
  • Official source ↗ The first-party site separately exposes business-contact opt-out context. Limitation: Business-contact handling is a distinct route and should not be conflated with consumer advertising, location, or deletion requests.

Next review action: Reconcile InMarket Media, LLC, applications, SDKs, advertising, measurement, location, purchase data, device/browser controls, consumer forms, business contacts, and partner-copy boundaries before promotion.

COMPACT INFORMATION SYSTEMS

Reviewed 2026-09-25
  • Official source ↗ The current first-party Deep Sync privacy-choice page identifies a public Do Not Sell route, supports opt-out and deletion selections, accepts multiple emails, phones, and addresses, describes identity verification, and provides privacy.compliance@deepsync.com and a phone channel. The page states that deletion may take up to 45 days and creates a suppression record intended to prevent re-addition to active business files. Limitation: The page also says suppression does not remove data from compilers or other sources and that corporate or client data may require a separate email request.
  • Official source ↗ The first-party request route presents access, source, category, third-party, correction, and related privacy-request options and repeats the phone and mail alternatives. Limitation: The bounded review did not submit a request or independently test identity questions, acceptance, delivery, or completion.
  • Official source ↗ (source date 2023-08-15) The provider-hosted mail form names Compact Information Systems and describes the Deep Sync consumer opt-out process and mailing address. Limitation: The catalog profile uses cisdirect.com while the current route uses Deep Sync branding; the legal-entity, domain, and duplicate-profile relationship must be explicitly reconciled.

Next review action: Reconcile COMPACT INFORMATION SYSTEMS, cisdirect.com, Deep Sync, Compact Information Systems, the separate compactlists.com profile, suppression, compiler data, corporate/client data, public form, mail route, phone, identity, and deletion boundaries before promotion.

DATAX LTD

Reviewed 2026-09-25
  • Official source ↗ (source date 2019-12-01) The first-party DataX Online Privacy Policy identifies DataX, Ltd. and directs readers to the Equifax Privacy Statement for additional privacy information. Limitation: The policy is materially older than the current evidence snapshot and does not by itself establish current request fields, route behavior, or ownership scope.
  • Official source ↗ The first-party DataX consumer page identifies DataX as an Equifax company and provides a five-year phone opt-out and a permanent mail-based opt-out for prescreen lists, with stated five-day effectiveness after receipt of the permanent notice. Limitation: This route is for prescreen-list opt-out under the described credit-reporting context; it is not proof of deletion from all DataX or Equifax systems.
  • Official source ↗ The cataloged Equifax privacy statement is retained as the provider-linked corporate privacy context. Limitation: The DataX consumer route and the general Equifax statement may cover different products, legal bases, and records.

Next review action: Reconcile DATAX LTD, dataxltd.com, the separate consumers.dataxltd.com profile, DataX and Equifax ownership, prescreen versus general privacy requests, phone, mail, identity, FCRA, and deletion boundaries before promotion.

FourthWall Media, Inc

Reviewed 2026-09-25
  • Official source ↗ The current privacy notice identifies FourthWall Media, Inc. and describes television, broadcast, cable, satellite, device-viewership, aggregation, reporting, and advertising-measurement services. It provides privacypolicy@fourthwall.tv and identifies consumers whose data is processed for customers as a covered audience. Limitation: The notice states that it does not respond to Do Not Track signals; it does not by itself establish deletion from customer-held reports or downstream advertising systems.
  • Official source ↗ The first-party Do Not Sell or Share form exposes fields for name, email, phone, street address, locality, region, postal code, and country, and presents a submit request action. Limitation: The bounded review did not submit the form or independently confirm identity verification, email confirmation, response timing, deletion behavior, or propagation to customers.
  • Official source ↗ The first-party site describes FourthWall as an addressable advertising and media-data provider, supporting the cataloged entity context. Limitation: Marketing context alone is not proof of a privacy request route or completed removal.

Next review action: Reconcile FourthWall Media, Inc., television and device-viewership data, consumer versus customer processing, Do Not Sell form fields, privacy email, identity, deletion, downstream customer reports, and response evidence before promotion.

Subgraph, Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-29) The current policy identifies Subgraph Inc and describes recruiting, candidate information, professional data providers, advertising and social-media sharing, and Google Workspace integrations. It provides privacy-rights, opt-out, deletion, access, correction, profiling, and marketing-choice context through the first-party privacy-rights page and team@subgraph.tech. The policy states that a future sale or sharing opt-out should be acted on as soon as feasible and no later than 15 days, while certain state requests have different response periods. Limitation: The policy distinguishes account data, candidate information, customer-provided data, and third-party professional data; a request may not cover every data context.
  • Official source ↗ The first-party privacy-rights route is the provider-stated path for consumer requests and is linked from the current policy. Limitation: The bounded review did not submit the route or independently test form fields, verification, acceptance, or completion.
  • Official source ↗ The first-party privacy-choices route is separately named in the policy for certain sale-or-sharing requests. Limitation: The relationship between privacy-rights and privacy-choices routes should be confirmed before presenting a single workflow.

Next review action: Reconcile Subgraph Inc, candidate and account data, customer-provided records, recruiting sources, Google Workspace data, privacy-rights versus privacy-choices routes, email, identity, profiling, deletion, and downstream customer copies before promotion.

Fifty Technology Ltd

Reviewed 2026-09-25
  • Official source ↗ The current policy identifies Fifty Technology Limited trading as Fifty and Fifty Media and describes analytics, advertising technology, publicly available social-media data, audience insights, and media services. It describes access, opt-out, erasure, correction, restriction, portability, and objection rights and names a data-protection contact. Limitation: The policy says Fifty may not generally know names, full email addresses, physical addresses, or other identifiers for some web and social-media users, which can limit record matching and erasure.
  • Official source ↗ The first-party opt-out page describes publicly available social-media data, says the service does not collect cookie data or clear-text email addresses for the stated audience-insight activity, and provides a consumer email and California hotline for rights requests. Limitation: The page directs users to manage visibility on source social platforms as well as contact Fifty; those platform controls are not deletion from Fifty’s records or client-held aggregates.
  • Official source ↗ The first-party terms connect Fifty Technology Ltd and Fifty Media as the provider identity. Limitation: Terms do not establish current request-form behavior or downstream deletion.

Next review action: Reconcile Fifty Technology Ltd, Fifty Media, public social-media sources, aggregated audience insights, source-platform controls, email, hotline, identity matching, erasure feasibility, and client-held aggregate boundaries before promotion.

Integrated Direct Marketing, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2021-10-13) The California registration identifies IDM, Inc., describes it as a data brokerage company, and states that consumers may use the website’s Do Not Sell link or ccpa@idm.us.com for opt-out requests. The registration states that IDM acquires data from other providers and does not explicitly capture consumer data through its website or platforms. Limitation: The registry record is historical and does not establish current route fields, identity verification, confirmation, or completion behavior.
  • Official source ↗ The provider-hosted privacy policy describes sources including government sources, third-party vendors, data providers, data subjects, and public websites, and describes licensing business and professional contact information for marketing and data-management purposes. Limitation: This is an older provider-hosted policy; the current public privacy page and current legal-name relationship to the catalog record require recheck.
  • Official source ↗ The cataloged first-party Do Not Sell route remains the provider-stated URL referenced by the registration and catalog evidence. Limitation: The bounded web review could not safely fetch this URL, so current form fields, acceptance, identity checks, and completion remain unconfirmed.

Next review action: Reconcile Integrated Direct Marketing, LLC versus IDM, Inc., current privacy route availability, historical registry and policy evidence, data-provider sources, ccpa@idm.us.com, identity, deletion, and customer-copy boundaries before promotion.

Rainbarrel USA LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-10-21) The current RainBarrel policy identifies RainBarrel Inc. and describes mobile advertising IDs, IP addresses, location-based audience construction, hashed emails, aggregated demographics, and advertising-platform activation. It states that RainBarrel does not collect names, clear-text email addresses, clear-text phone numbers, or physical addresses for its audience products, and that requests may take up to one week to take effect. It provides CCPA access, deletion, and opt-out context and identifies info@rbarrel.com as a contact. Limitation: The catalog legal name is Rainbarrel USA LLC while the current first-party policy identifies RainBarrel Inc.; the corporate relationship to KnowerTech and the catalog record requires explicit entity review.
  • Official source ↗ The first-party opt-out form accepts an advertising ID and email for MAID and hashed-email audience opt-out and separately links Unified ID 2.0 controls. Limitation: This is an identifier- and audience-specific opt-out, not proof of removal from every RainBarrel system, source provider, advertising platform, or customer-held copy.
  • Official source ↗ The first-party company page identifies RainBarrel’s President as President of Knower Tech and describes the RainBarrel audience graph and consented advertising-data context. Limitation: A leadership reference is not sufficient evidence that KnowerTech, RainBarrel Inc., and the cataloged Rainbarrel USA LLC are the same legal entity.

Next review action: Reconcile Rainbarrel USA LLC, RainBarrel Inc., KnowerTech, rbarrel.com, advertising IDs, hashed email, source-platform controls, one-week effect statement, email, identity, deletion, and advertising/customer propagation before promotion.

ASL MARKETING INC

Reviewed 2026-09-25
  • Official source ↗ The current Deep Sync policy identifies Compact Information Systems, LLC d/b/a Deep Sync and expressly lists ASL Marketing, Inc. among its branded lines of business and affiliates. It describes marketing, hygiene, analytics, consumer information, direct-mail, email, online channels, identity verification, deletion, opt-out, and suppression handling. Limitation: The policy covers a family of brands and distinguishes controller processing from other contexts; it does not by itself establish that every ASL-branded record is held in the same system.
  • Official source ↗ The current Deep Sync privacy route provides opt-out, targeted-advertising, profiling, deletion, address, phone, and email fields; it states that identity questions may be dynamically generated and that deletion can take up to 45 days with a suppression record. The first-party ASL site redirects into Deep Sync-branded content and the Deep Sync footer links to the same privacy route. Limitation: The route was not submitted; acceptance, identity outcome, confirmation, and brand-level propagation were not independently tested.
  • Official source ↗ The provider’s help content identifies ASL Marketing as a Deep Sync brand and describes student, young-adult, parent, college, and self-reported data products and source categories. Limitation: Marketing coverage and sourcing context do not prove deletion from customer-held datasets or every affiliated brand.

Next review action: Reconcile ASL Marketing Inc, aslmarketing.com, Deep Sync, Compact Information Systems, student and young-adult data, the family-wide privacy route, suppression, identity, deletion, and customer-copy propagation before promotion.

Deep Root Analytics, LLC

Reviewed 2026-09-25
  • Official source ↗ The current policy identifies Deep Root Analytics, LLC and describes processing for services, clients, website visitors, and individuals whose information is processed without a direct relationship. It describes access, deletion, correction, sale-or-sharing opt-out, profiling, GPC, and a first-party interactive webform plus a toll-free channel. The policy publishes 2025 request metrics and states that requests are verified against data points in the provider’s records. Limitation: The page states an effective date of March 2023 and a last-updated month of June 2026 without an exact day; the webform’s live fields and completion behavior were not independently tested.
  • Official source ↗ The first-party California page states that opt-out requests may be submitted with full name, physical address, and telephone number by webform, email, or phone, and describes authorized-agent verification. Limitation: The page provides request instructions but does not prove acceptance, response, deletion, or propagation to Deep Root customers.
  • Official source ↗ The first-party site describes Deep Root audience, polling, focus-group, and media-measurement services, supporting the cataloged entity context. Limitation: Business context alone is not proof of a current consumer request route.

Next review action: Reconcile Deep Root Analytics, direct versus client-linked processing, audience and polling data, CCPA form, email, phone, identity matching, GPC, protected-person requests, deletion, and client-held copies before promotion.

DataDelivers, LLC

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-06-12) The current policy identifies DataDelivers, LLC and describes data strategy, analytic insights, customer-management technology, direct mail, email, website, and social-media marketing services. It provides access, deletion, correction, opt-out, portability, profiling, GPC, identity-matching, and authorized-agent context, with stated targets of 15 business days for opt-outs and 45 calendar days for deletion or access requests. The policy states that client data practices may differ and are not controlled by DataDelivers. Limitation: The policy’s route links and the separate form were not submitted; client-held copies and downstream campaign systems remain outside the provider’s own stated control.
  • Official source ↗ The first-party individual opt-out form exposes identity, name, address, email, phone, signature, date, and CAPTCHA fields and states that the information is used for database matching and suppression. The form identifies DataDelivers contact email and phone details. Limitation: The bounded review did not submit the form or independently confirm acceptance, verification, confirmation, or actual suppression.
  • Official source ↗ The first-party site describes DataDelivers customer-data-platform and marketing analytics services, supporting the provider context. Limitation: A reachable homepage does not prove a completed privacy request.

Next review action: Reconcile DataDelivers, client-controlled processing, opt-out form fields, privacy email, identity matching, GPC, response targets, suppression, campaign copies, and deletion boundaries before promotion.

Hivestack Technologies Inc

Reviewed 2026-09-25
  • Official source ↗ The Perion CCPA notice identifies Hivestack Technologies Inc. as a Perion affiliate and data broker, describes sale or sharing for advertising, and provides privacy, DSR, and opt-out context. It states that Hivestack’s offerings may rely on device identifiers such as MAIDs rather than direct identifiers such as email addresses, which can limit identity matching. The notice provides Hivestack contact information and reports a prior request-statistics table. Limitation: The page states a July 2025 last-modified month without an exact day and covers Perion and Hivestack contexts together; it does not prove current form acceptance or deletion from partner systems.
  • Official source ↗ The current Perion opt-out page provides a browser-cookie choice for interest-based advertising and explains that the choice is browser- and cookie-dependent. Limitation: The Perion cookie route is not equivalent to deletion of Hivestack device identifiers or customer-held advertising data.
  • Official source ↗ (source date 2025-02-24) The provider-hosted Hivestack policy identifies Hivestack Technologies Inc. as part of Perion Network Ltd, provides privacy@hivestack.com, describes DOOH advertising and device data, and links to DSR and industry opt-out mechanisms. Limitation: This policy is hosted on a regional Hivestack domain and has an older exact date; reconcile it with the current Perion route before promotion.

Next review action: Reconcile Hivestack Technologies Inc, Hivestack, Perion Network, perion.com, device identifiers, MAIDs, DOOH data, cookie opt-out, DSR route, privacy email, identity, deletion, and partner propagation before promotion.

Revenue Roll Inc

Reviewed 2026-09-25
  • Official source ↗ The current policy identifies Revenue Roll Inc DBA Tie and describes public databases, marketing partners, social-media platforms, data providers, mailing addresses, email, phone, intent data, and targeted advertising contexts. It provides access, correction, deletion, sale-or-sharing, profiling, GPC, authorized-agent, identity-verification, and data-subject-request context through info@meettie.com. The policy describes prior request metrics and states that deletion or account termination may retain limited information for security, fraud, legal, or operational reasons. Limitation: The policy states a last-updated month of June 2025 without an exact day; the linked data-subject request form was not independently tested.
  • Official source ↗ The provider’s first-party transition page states that Revenue Roll is now Tie and describes its identity-network and opt-in framework. Limitation: Brand-transition context does not itself establish the current privacy form’s acceptance or record scope.
  • Official source ↗ (source date 2026-06-18) The current terms identify Revenue Roll Inc d/b/a Tie and connect the meettie.com platform to the provider identity. Limitation: Terms do not establish a consumer deletion outcome or downstream customer propagation.

Next review action: Reconcile Revenue Roll Inc, Tie, meettie.com, public and partner sources, opt-in versus opt-out data, data-subject request route, identity, GPC, deletion, retention, and customer-held copies before promotion.

DataMentors LLC dba V12

Reviewed 2026-09-25
  • Official source ↗ The current PGM Solutions opt-out form identifies a first-party Porch Group Media route, states that submitted data is used to remove name, address, phone, and email information from PGM databases, and states a processing target of no longer than 10 business days. The form exposes name, address, email, phone, date, identity-role, and submission fields and provides privacy@porchgroupmedia.com. Limitation: The route uses PGM Solutions branding while the catalog profile uses DataMentors/V12; legal-entity, brand, and cross-database coverage require explicit reconciliation.
  • Official source ↗ The V12 Group policy describes direct-mail, online, email, and cookie-based services and browser/device-specific online advertising opt-outs. Limitation: The policy identifies V12 Group and Datagence rather than the cataloged DataMentors/Porch Group Media record; it is retained as historical or related-brand context, not proof of current PGM coverage.
  • Official source ↗ The Porch privacy policy provides parent-company access, deletion, and sale-opt-out context and identifies separate request timing for opt-out versus access/deletion requests. Limitation: Porch parent-company requests may cover different records from PGM Solutions or V12 datasets.

Next review action: Reconcile DataMentors LLC, V12 Data, V12 Group, Porch Group Media, PGM Solutions, optout.porchgroupmedia.com, dataset scope, identity fields, response target, deletion, and affiliate/customer copies before promotion.

MV Digital Group, LLC

Reviewed 2026-09-25
  • Official source ↗ The current first-party CinqDI site describes contextual and behavioral data, attitudinal and demographic insights, proprietary first-party publisher data, polling research, voter-file data, and audience-persona modeling. Limitation: The public page confirms audience-data activity but does not itself confirm a current consumer privacy request route or deletion workflow.
  • Official source ↗ The first-party company page describes CinqDI’s use of publication first-party data, voter-file data, audience segments, and psychographic models, supporting the provider and brand context. Limitation: Audience and modeling descriptions do not prove current request-form fields, identity verification, or deletion from models and customer activations.
  • Official source ↗ The cataloged first-party privacy-rights URL remains the route candidate associated with MV Digital Group/CinqDI. Limitation: The bounded review did not independently confirm this route’s current availability, form fields, acceptance, identity process, or completion behavior; do not promote the cataloged Equifax-route assumption without current entity evidence.

Next review action: Reconcile MV Digital Group, LLC, CinqDI, voter-file and publisher data, psychographic modeling, privacy-rights route availability, identity, deletion, model retraining, and customer activation copies before promotion.

Carry Technologies Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-03-20) The current Platform Privacy Notice identifies Carry Technologies, Inc. dba Hightouch and describes Match Booster, audience enrichment, and third-party data-provider inputs. It distinguishes Hightouch’s processor or service-provider role for customer data from its own controlled processing and provides access, correction, deletion, opt-out, identity-confirmation, and authorized-agent context. It provides datadeletion@hightouch.com and a first-party privacy-choices route. Limitation: The notice distinguishes Hightouch-controlled data from customer data processed on behalf of customers; a request to Hightouch may not remove data held by the customer or original provider.
  • Official source ↗ (source date 2026-06-29) The current general policy identifies Carry Technologies, Inc. dba Hightouch and provides preferences.hightouch.com, datadeletion@hightouch.com, access, deletion, targeted-advertising, and identity-verification context. It states that it does not apply to personal information processed on behalf of customers as a processor or service provider. Limitation: The policy’s consumer route and form behavior were not submitted or independently tested.
  • Official source ↗ The first-party preferences subdomain is the provider-stated privacy-choice route linked from current Hightouch policies. Limitation: The bounded review did not confirm live fields, acceptance, verification, or completion.

Next review action: Reconcile Carry Technologies, Hightouch, Match Booster, customer processor data, third-party enrichment, privacy preferences, email, identity, deletion, and original-provider or customer copies before promotion.

Decide Technologies Inc

Reviewed 2026-09-25
  • Official source ↗ The current first-party site identifies Decide as an AI-powered performance advertising and unified advertising platform connecting advertisers, publishers, supply, and platform partners. Limitation: The current homepage confirms advertising-platform context but does not by itself establish a consumer privacy request route or the exact data-controller entity for every platform partner.
  • Official source ↗ The cataloged first-party privacy URL is retained as the route candidate associated with Decide Technologies Inc. Limitation: The bounded fetch returned no usable policy text; current request fields, entity identity, acceptance, verification, and completion remain unconfirmed.
  • Official source ↗ The catalog evidence links Decide’s California data-broker registration context to the official registry. Limitation: Registry discovery does not prove the current live route or downstream suppression.

Next review action: Reconcile Decide Technologies Inc, Decide’s advertising platform, publisher and platform partners, current privacy-page availability, registry email and phone, identity, deletion, cookie/device data, and partner-held copies before promotion.

Digital Viking Media Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2023-08-01) The California registration identifies Digital Viking Media Inc and states that consumers may submit opt-out or other CCPA requests by email or postal mail, including protected-person requests. Limitation: The registry record is historical and does not provide the current privacy email, current form fields, identity verification, response timing, or completion behavior.
  • Official source ↗ The cataloged first-party privacy-policy URL is retained as the provider-stated route candidate. Limitation: The bounded review could not safely fetch the current page, so its route semantics and freshness are unconfirmed.
  • Official source ↗ The cataloged first-party domain is retained as the provider context for Digital Viking Media Inc. Limitation: A domain or contact page does not prove a current consumer privacy workflow.

Next review action: Reconcile Digital Viking Media Inc, current first-party domain and privacy route, historical registry email/mail channels, identity, deletion, protected-person handling, and downstream customer copies before promotion.

FreeWheel Media Inc

Reviewed 2026-09-25
  • Official source ↗ (source date 2025-07-15) The current policy identifies FreeWheel Media, Inc. and affiliates and describes site visitors, publisher and media-buyer services, device identifiers, IP addresses, audience segments, advertising delivery, and connected-TV or streaming contexts. It provides access, portability, correction, deletion, Do Not Sell or Share, sensitive-information, phone, email, and identity-verification routes. It distinguishes FreeWheel’s role from publishers, media buyers, DMPs, and other advertising-ecosystem entities. Limitation: The policy says a FreeWheel cookie opt-out does not remove data controlled by publishers, demand partners, DMPs, or other ecosystem participants.
  • Official source ↗ The first-party opt-out page provides a FreeWheel cookie choice and explains that the preference is stored in a cookie. Limitation: Cookie opt-out is browser-specific and is not equivalent to deletion of all FreeWheel or partner-held information.
  • Official source ↗ The first-party legal center confirms the current FreeWheel provider domain and legal navigation. Limitation: Legal navigation alone does not prove a completed consumer request.

Next review action: Reconcile FreeWheel Media, Inc., publisher and media-buyer roles, device identifiers, CTV, cookie opt-out, CCPA email and phone route, identity, deletion, DMPs, publishers, and downstream advertising partners before promotion.

Matchbook Data, LLC

Reviewed 2026-09-25
  • Official source ↗ The provider policy describes Matchbook as a platform for collecting, aggregating, licensing, and managing location and device data for audience building, advertising measurement, and research. It describes browser, mobile-device, email, access, deletion, opt-out, appeal, privacy-email, and phone routes. Limitation: The policy does not by itself prove that an advertising-ID opt-out removes previously collected data from every recipient or licensed database.
  • Official source ↗ The current first-party privacy-choice page distinguishes opt-out from deletion and explains that requests require a device or advertising ID plus an email address. It exposes device ID and email fields, provides privacy@matchbookdata.com and a toll-free number, and describes device-setting limitations, including Android zeroing behavior. Limitation: The live form was not submitted; identity matching, confirmation, acceptance, and downstream recipient deletion were not independently tested.
  • Official source ↗ The first-party site navigation and footer identify Matchbook as the provider context for the privacy-choice route. Limitation: Business context alone is not proof of request completion.

Next review action: Reconcile Matchbook Data, location and device identifiers, advertising ID or installation ID, privacy-choice versus deletion routes, email, phone, identity, recipient databases, and device-specific limitations before promotion.

Milestone Marketing Solutions

Reviewed 2026-09-25
  • Official source ↗ (source date 2026-03-26) The current policy identifies Milestone Marketing Solutions, LLC and describes information collected through services, communications, and third-party sources including data brokers. It provides rights to opt out of targeted advertising, profiling, and sales, along with access, deletion, correction, identity, and request context. Limitation: The policy’s current form fields and completion behavior were not independently tested.
  • Official source ↗ The first-party Do Not Sell page states that consumers may request removal by toll-free phone, written request, email, or a form and that all form fields must be complete and accurate. Limitation: The page was not submitted; confirmation, verification, response timing, and deletion from downstream customer copies remain unconfirmed.
  • Official source ↗ The first-party California policy provides CCPA access, deletion, correction, and sale opt-out context and states that information will not be shared after an opt-out unless the consumer later consents. Limitation: The page does not establish that every affiliated customer or historical recipient has deleted earlier copies.

Next review action: Reconcile Milestone Marketing Solutions, LLC, third-party sources, Do Not Sell form, email, phone, mail, identity, response evidence, CCPA deletion, and customer-held copies before promotion.

The complete review notes and source URLs are available in the JSON authority plan.

Demand validation · 2025-04-20 → 2026-08-13

Use observed demand to choose the next pages

This Search Console snapshot is a prioritization signal, not proof of competitor share, AI citation share, removal success, or conversion quality. It highlights pages where a focused source-backed revision can improve an already-visible intent.

49,775

Web impressions

sitewide snapshot

5,832

Question impressions

276 question queries

677

Near-page-one target

ChatGPT guide impressions

3,697

Broad catalog hub

directory impressions

PageImpressionsAvg. positionNext action
/blog/remove-personal-data-from-chatgpt6779.22Implemented 2026-08-20: consolidated the OpenAI source-backed answer flow, refreshed title/snippet metadata, and aligned visible FAQs with the answer schema; remeasure after recrawl.
/blog/data-broker-list-2026-complete-guide13212.53Implemented 2026-08-20: clarified dated catalog methodology, current DROP scope, and the canonical live directory path; remeasure after recrawl.
/directory3,69730.96Implemented 2026-08-20: made web/email/manual evidence types explicit and strengthened category and broker-profile discovery; remeasure after recrawl.

Prioritized evidence work

The backlog is prioritized by the evidence needed to make a profile useful and safe to cite. It is not a promise to fill every field proactively, especially fields that require a user's own request outcome.

PriorityWorkstreamScopeProof requiredBoundary
P0Failed route rechecks34Independently observe the recorded provider URL and preserve status, redirects, errors, and access blockers.A failed observation is not proof of provider-wide unavailability.
P0Route-semantics review468Review the first-party page to distinguish an opt-out route from a privacy policy, processor portal, or unrelated source page.A reachable URL is not automatically a canonical submission route.
P1Workflow detail enrichment1Record source-backed field purpose, format, jurisdiction, sensitivity, match impact, channels, and prerequisites.Do not infer exact form requirements from a URL or title alone.
P1Entity and suppression mapping528Use official corporate, registry, legal, or provider evidence for legal operator, parent, aliases, brands, and suppression relationships.Shared domains or email routes do not prove shared ownership or suppression.
P1Verified contact evidence0Keep first-party contact provenance and bounded DNS evidence separate from mailbox acceptance.DNS/MX checks do not prove an inbox exists or accepts a request.
P2Freshness and provenance1,043Maintain source-check dates, next verification dates, source URLs, capture methods, and retracted observations for each profile.A date without a source is not evidence.

Nine dimensions on every broker profile

A profile is more than an opt-out link. Its evidence matrix tracks whether each dimension is documented, partially documented, unknown, or not recorded.

Entity identity

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Business context

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Regulatory context

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Request workflow

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Contact routes

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Privacy boundary

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Verification

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Catalog metadata

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

Source provenance

Dimension-level field coverage is shown on each profile, with source dates and remaining gaps.

What is intentionally not a proactive backlog

User-authorized outcome fields—such as a user-confirmed submission, broker response, case ID, deletion confirmation, or relisting observation—are recorded only when the user explicitly supplies or authorizes the evidence. OfflistMe prepares drafts and routes; users review, send or submit, verify, and follow up.

Verification rules

  1. Prefer provider-published or official registry sources.
  2. Keep route reachability, route semantics, mailbox acceptance, delivery, response, deletion, and relisting as separate states.
  3. Preserve source dates, next verification dates, conflicts, access blockers, and retracted observations.
  4. Publish only claims supported by the stated source and observation method.