# OfflistMe Content Authority Plan

Editorial content date: 2026-08-13
Evidence snapshot date: 2026-08-15

Source-first content authority plan for expanding OfflistMe knowledge without creating thin, duplicated, or unsupported pages.

## Current inventory

| Surface | Count | Meaning |
| --- | ---: | --- |
| Customer-ready broker profiles | 1,018 | Catalog records eligible for profile pages; not proof of removal outcomes |
| Profiles with direct catalog route | 553 | Records with an attached opt-out URL; source context is handled separately |
| Profiles with workflow records | 1,018 | Records with structured workflow fields |
| Registry context | 808 | Matched public-registry context, not ownership or suppression proof |
| Indexable blog posts | 116 | Editorial bodies after noindex duplicate controls |
| Broker guides | 94 | Detailed broker-specific guide records |
| Evidence facts | 155,319 | Source-linked facts and observations |

## Search-demand validation

Source: **Google Search Console**, property **sc-domain:offlist.me**, window **2025-04-20 → 2026-08-13**. This snapshot reports site performance, not competitor share or removal outcomes.

| Signal | Value |
| --- | ---: |
| Web pages with impressions | 916 |
| Web queries | 3,268 |
| Query × page rows | 4,431 |
| Web impressions | 49,775 |
| Question-query impressions | 5,832 |

### Near-term page opportunities

- **[/blog/remove-personal-data-from-chatgpt](/blog/remove-personal-data-from-chatgpt)** — 677 impressions, average position 9.22, CTR 0.30%. Refresh title, snippet, and source-backed answer block before expanding the topic.
- **[/blog/data-broker-list-2026-complete-guide](/blog/data-broker-list-2026-complete-guide)** — 132 impressions, average position 12.53, CTR 0.80%. Clarify editorial list intent and link prominently to the canonical live directory.
- **[/directory](/directory)** — 3,697 impressions, average position 30.96, CTR 0.70%. Treat as the canonical catalog hub; improve category and broker-profile discovery after the near-page-one pages.

### Intent and cannibalization signals

- **mugshot and arrest-record removal** — 174 impressions. Keep legal and jurisdictional limits explicit; do not promise removal.
- **remove a name from search engines** — 136 impressions. Keep the general search-engine guide and the Google-specific request guide as distinct intents; align links and wording to reduce overlap.
- **data-broker lists and opt-out sites** — 153 impressions. Consolidate broad list intent around the directory while retaining editorial explanation.
- **what is a data broker** — 83 impressions. Keep definition intent on the explainer and link the directory as the action route.

- This is a dated Search Console snapshot, not a live ranking guarantee.
- Search Console reports site performance; it does not prove removal outcomes, competitor share, AI citations, or conversion quality.
- The separate opportunities request returned fetch failed and is treated as unavailable, not as zero demand.

## High-impact freshness standard

272 of 272 High-impact profiles have a source check within 90 days of the 2026-08-15 evidence snapshot. This is a publication freshness gate, not proof that a route accepts a request or that a provider completed deletion.

## Provider business-context coverage

| Scope | Profiles |
| --- | ---: |
| Source-backed provider context | 197 |
| Missing provider context, review-only | 821 |

Profiles missing provider context remain a research queue. Do not infer products, data categories, purposes, customer segments, or control boundaries from a route, registry record, DNS result, or company name alone.

## First 20% authority tranche

The first tranche contains **204 profiles (20% of the catalog)**, including **204 explicitly High-impact records**. It is an evidence-work priority, not a live search-volume, ranking, removal-success, or competitor-share estimate.

**Selection rule:** Explicit High-impact catalog records are selected first. Ties are ordered by category priority, lower tracked-field completeness, and current route evidence. This is an evidence-work priority, not a live search-volume, ranking, removal-success, or competitor-share estimate.

**Demand validation:** A dated Google Search Console snapshot (2025-04-20 to 2026-08-13) is available for demand validation. It informs page and intent prioritization but does not estimate competitor share, removal success, or conversion quality.

### Tranche audit

| Readiness signal | Profiles |
| --- | ---: |
| Average tracked-field completeness | 44.63% |
| Registry context | 190 |
| Current route evidenced | 142 |
| Current email route recorded | 61 |
| Independent route observed | 141 |
| Route semantics pending | 59 |
| Route recheck required | 4 |
| In review-only enrichment queue | 18 |

The full machine-readable profile list is in [content-authority-plan.json](/content-authority-plan.json). The enrichment queue is review-only: it does not promote records, certify provider workflows, or assert user outcomes.

| Category | Tranche profiles |
| --- | ---: |
| Advertising & Adtech | 50 |
| B2B & Sales Intelligence | 35 |
| Credit, Risk & Identity | 39 |
| Marketing & Audience Data | 60 |
| People Search & Public Records | 20 |

### Representative first-pass profiles

| Broker | Category | Catalog impact | Evidence completeness | Route state |
| --- | --- | --- | ---: | --- |
| [Reality Media, Inc.](https://www.offlist.me/broker-knowledge/realitydebtsolutions-com) | Advertising & Adtech | High | 28.68% | current_route_evidenced |
| [Tandem Marketing, LLC](https://www.offlist.me/broker-knowledge/fhamortgagefinder-com) | Marketing & Audience Data | High | 29.07% | current_route_evidenced |
| [Appily](https://www.offlist.me/broker-knowledge/appily-com) | Marketing & Audience Data | High | 31.78% | current_route_evidenced |
| [RelSci (Altrata)](https://www.offlist.me/broker-knowledge/relsci-com) | B2B & Sales Intelligence | High | 31.78% | current_route_evidenced |
| [Nexsales Solutions Inc. (RightLeads)](https://www.offlist.me/broker-knowledge/nexsales-com) | B2B & Sales Intelligence | High | 32.17% | current_route_evidenced |
| [Zeotap GmbH](https://www.offlist.me/broker-knowledge/zeotap-com) | Advertising & Adtech | High | 32.17% | current_route_evidenced |
| [700Credit, LLC](https://www.offlist.me/broker-knowledge/700credit-com) | Credit, Risk & Identity | High | 42.25% | current_route_evidenced |
| [RayCDP, Inc.](https://www.offlist.me/broker-knowledge/raycdp-com) | Marketing & Audience Data | High | 32.56% | current_route_evidenced |
| [Findem, Inc.](https://www.offlist.me/broker-knowledge/findem-ai) | People Search & Public Records | High | 42.64% | current_route_evidenced |
| [Acquire Media U.S., LLC (Moody's Analytics NewsEdge)](https://www.offlist.me/broker-knowledge/newsedge-com) | B2B & Sales Intelligence | High | 32.95% | current_route_evidenced |
| [Leadership Connect](https://www.offlist.me/broker-knowledge/leadershipconnect-io) | B2B & Sales Intelligence | High | 32.95% | current_route_evidenced |
| [SBFE, LLC](https://www.offlist.me/broker-knowledge/sbfe-org) | Credit, Risk & Identity | High | 43.02% | current_route_evidenced |

## Next high-impact tranche

After the first 20%, the next tranche contains **68 explicitly High-impact profiles (6.68% of the catalog)**. It uses the same evidence-first ordering and remains a planning artifact, not a claim about search demand, competitor share, removal success, or provider outcomes.

**Selection rule:** Explicit High-impact catalog records outside the first 20% tranche, ordered by the same evidence-work score. This is a research and publication priority, not a live search-volume, ranking, removal-success, or competitor-share estimate.

### Tranche audit

| Readiness signal | Profiles |
| --- | ---: |
| Average tracked-field completeness | 46.98% |
| Registry context | 68 |
| Current route evidenced | 34 |
| Current email route recorded | 33 |
| Independent route observed | 35 |
| Route semantics pending | 32 |
| Route recheck required | 1 |
| In review-only enrichment queue | 10 |

| Category | Tranche profiles |
| --- | ---: |
| Advertising & Adtech | 13 |
| B2B & Sales Intelligence | 12 |
| Marketing & Audience Data | 27 |
| Social, Marketplaces & Platforms | 16 |

### Representative next-pass profiles

| Broker | Category | Catalog impact | Evidence completeness | Route state |
| --- | --- | --- | ---: | --- |
| [VideoAmp, Inc.](https://www.offlist.me/broker-knowledge/videoamp-com) | Advertising & Adtech | High | 45.35% | current_email_route_recorded |
| [Zeta Global](https://www.offlist.me/broker-knowledge/zetaglobal-com) | Advertising & Adtech | High | 45.35% | current_email_route_recorded |
| [Clickagy](https://www.offlist.me/broker-knowledge/clickagy-com) | Advertising & Adtech | High | 47.67% | current_route_evidenced |
| [Cuebiq Group, LLC](https://www.offlist.me/broker-knowledge/cuebiq-com) | Advertising & Adtech | High | 47.67% | current_route_evidenced |
| [i360, LLC](https://www.offlist.me/broker-knowledge/i-360-com) | Marketing & Audience Data | High | 47.67% | current_route_evidenced |
| [InfutorData / Lead Intelligence, Inc.](https://www.offlist.me/broker-knowledge/infutor-com) | Marketing & Audience Data | High | 47.67% | current_route_evidenced |
| [Path2Response, LLC](https://www.offlist.me/broker-knowledge/path2response-com) | Marketing & Audience Data | High | 47.67% | current_route_evidenced |
| [PlaceIQ; PIQ](https://www.offlist.me/broker-knowledge/precisely-com) | Advertising & Adtech | High | 47.67% | current_route_evidenced |
| [33 Mile Radius LLC](https://www.offlist.me/broker-knowledge/33mileradius-com) | Marketing & Audience Data | High | 45.74% | current_email_route_recorded |
| [33Across, Inc.](https://www.offlist.me/broker-knowledge/33across-com) | Advertising & Adtech | High | 45.74% | current_email_route_recorded |
| [Anchor Computer Inc.](https://www.offlist.me/broker-knowledge/anchorcomputer-com) | Marketing & Audience Data | High | 45.74% | current_email_route_recorded |
| [AtData, LLC](https://www.offlist.me/broker-knowledge/atdata-com) | B2B & Sales Intelligence | High | 45.74% | current_email_route_recorded |

The complete 68-profile list is in [content-authority-plan.json](/content-authority-plan.json). The enrichment queue remains review-only and does not promote a route or certify a provider workflow.

## Secondary tranche after High-impact coverage

After the 204-profile first tranche and the remaining 68 High-impact profiles, this next tranche contains **204 profiles (20.04% of the catalog)**. It is the next research and publication queue for records without an explicit High-impact label.

**Selection rule:** Profiles outside the explicit High-impact set, ordered by evidence gaps, category relevance, route state, and tracked-field completeness. This is a research and publication priority, not a ranking, market-share estimate, or removal-outcome claim.

### Tranche audit

| Readiness signal | Profiles |
| --- | ---: |
| Average tracked-field completeness | 32.73% |
| Registry context | 79 |
| Current route evidenced | 112 |
| Current email route recorded | 92 |
| Independent route observed | 112 |
| Route semantics pending | 90 |
| Route recheck required | 2 |
| In review-only enrichment queue | 42 |

| Catalog impact | Tranche profiles |
| --- | ---: |
| Medium | 71 |
| Not recorded | 133 |

| Category | Tranche profiles |
| --- | ---: |
| Advertising & Adtech | 29 |
| B2B & Sales Intelligence | 29 |
| Credit, Risk & Identity | 35 |
| Marketing & Audience Data | 69 |
| People Search & Public Records | 41 |
| Social, Marketplaces & Platforms | 1 |

The complete profile list is in [content-authority-plan.json](/content-authority-plan.json). This queue is review-only and does not promote a provider workflow or assert a user outcome.

## Authority model

### broker-profiles
- **Intent:** navigational, how-to
- **Canonical routes:** /broker-knowledge, /broker-knowledge/category/{category}, /broker-knowledge/freshness, /broker-knowledge/route-review, /directory, /broker-knowledge/{domain}
- **Rule:** Publish one profile per customer-ready record; expose current fields, source dates, gaps, and evidence boundaries.

### editorial-guides
- **Intent:** how-to, problem-solving
- **Canonical routes:** /blog/{slug}, /remove-from-{broker}
- **Rule:** Create a guide only when it adds first-party route detail, legal context, original comparison, or a distinct safety scenario.

### privacy-rights
- **Intent:** informational, legal-research
- **Canonical routes:** /us-privacy-laws, /ccpa-data-broker-opt-out-guide, /data-removal-by-state
- **Rule:** Cite the controlling regulator or statute and preserve jurisdiction, date, scope, and exception boundaries.

### evidence-and-methodology
- **Intent:** research, verification
- **Canonical routes:** /methodology, /broker-evidence-roadmap, /broker-evidence-scorecard
- **Rule:** Make the research method, freshness cadence, unresolved gaps, and non-outcome claims public.

### threat-models
- **Intent:** safety, scenario
- **Canonical routes:** /data-removal-by-profession, /blog/{scenario}
- **Rule:** Use specific risk context and practical steps; never imply that broker removal alone guarantees physical safety.

### comparisons
- **Intent:** commercial-investigation
- **Canonical routes:** /deleteme-vs-incogni-vs-offlistme, /blog/{comparison}
- **Rule:** Compare observable workflow, price, coverage scope, user control, and evidence; disclose methodology and ownership.

## Category briefs

### People Search & Public Records
- **Primary intent:** How do I remove a name, address, phone number, or public-record profile?
- **Fan-out questions:** What information does this people-search site display? · Does the provider use a profile URL, email, or form? · Does the route require phone or identity verification? · How should I verify the listing after the provider window? · What public-record source can cause the listing to return?
- **Source requirements:** provider suppression or privacy route · official state or federal record source when discussing public records · dated route observation when available
- **Direct sources:** [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/) · [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement) · [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa)
- **Answer blocks:**
  - **What information does a people-search site display?** Only describe the fields supported by the provider page, registry record, or other named source. A catalog label such as public records or contact data is a category signal, not proof that a particular person appears in the provider database. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa)
  - **Does the provider use a profile URL, email, or form?** Use the request channel recorded for that provider and show the source date. A provider-published privacy page, form, or email can document a channel; a reachable page or a read-only observation does not by itself prove that the channel accepts or completes a request. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement)
  - **Does the route require phone or identity verification?** Treat phone, profile, and identity fields as provider-specific workflow requirements. If the current source does not state a requirement, label it not recorded rather than guessing; do not send unnecessary identity documents. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement)
  - **How should I verify the listing after the provider window?** Keep the submitted request and any confirmation, then revisit the source listing after the provider-stated estimate or response. A later page observation can document what was visible at that time, but it is not proof of deletion or non-republication. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa)
  - **What public-record source can cause the listing to return?** A public-record source may be one input among several, but the specific source must be named and linked before it is presented as an explanation. Do not infer a causal source from a matching name or address alone. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement)
- **Avoid:** guaranteed deletion · permanent removal · universal reappearance timing

### Marketing & Audience Data
- **Primary intent:** What marketing or audience data may be associated with a broker, and how can a person exercise a request?
- **Fan-out questions:** Is the provider a data broker, an adtech vendor, or a service provider? · Which request types and jurisdictions are published? · Does the provider describe data categories or recipients? · Is the route first-party, processor-hosted, or context-only? · What is the difference between opt-out, deletion, and access?
- **Source requirements:** provider privacy or rights page · official registry or regulator record where matched · jurisdiction-specific statute or regulator guidance
- **Direct sources:** [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/) · [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement) · [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
- **Answer blocks:**
  - **Is the provider a data broker, an adtech vendor, or a service provider?** Use the provider description, official registry context, and the applicable legal definition separately. OfflistMe should preserve the source wording and avoid turning a marketing label or registry classification into a legal conclusion. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
  - **Which request types and jurisdictions are published?** List only request types and jurisdictions stated in the provider source or applicable official record. A general privacy inbox does not establish that every access, deletion, correction, or opt-out right is available in every jurisdiction. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement)
  - **Does the provider describe data categories or recipients?** Report categories and recipient groups as provider or registry declarations, with the source date and scope. These declarations describe business context; they do not prove a particular individual record or downstream disclosure. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
  - **Is the route first-party, processor-hosted, or context-only?** Review the page identity, host, request language, and relationship evidence before assigning a route role. A processor or cross-domain page remains a candidate until the provider relationship and request scope are confirmed. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/)
  - **What is the difference between opt-out, deletion, and access?** These request types can have different legal bases, scopes, and exceptions. The page should name the provider route and jurisdiction-specific source instead of treating one request as a universal substitute for the others. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
- **Avoid:** assuming an audience segment proves an individual profile · equating a DNS check with mailbox acceptance · treating a provider category as a finding of unlawful conduct

### B2B & Sales Intelligence
- **Primary intent:** How can a person or business contact suppress a sales-intelligence record without confusing business data with consumer rights?
- **Fan-out questions:** Is the record about a professional contact or a consumer profile? · What suppression or correction route does the provider publish? · Which fields are required to match the record? · Does the applicable privacy law cover this context? · What should a business save as evidence of its request?
- **Source requirements:** provider suppression route and terms · applicable law or regulator guidance · entity and brand relationship evidence
- **Direct sources:** [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement) · [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/) · [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
- **Answer blocks:**
  - **Is the record about a professional contact or a consumer profile?** Classify the context from the provider source and the recorded data domains. Professional identity, employment, and company-affiliation signals should not automatically be described as consumer records or treated as covered by every consumer privacy law. Sources: [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
  - **What suppression or correction route does the provider publish?** Use the provider-published suppression, correction, privacy, or rights route recorded for the entity. If the catalog only has a context page or an unreviewed cross-domain link, label that limitation and keep the route in review. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/)
  - **Which fields are required to match the record?** Show only fields supported by the provider workflow, such as a business email, profile URL, or other matching context. A field being useful for matching does not make it safe or necessary to disclose when the provider does not require it. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
  - **Does the applicable privacy law cover this context?** Coverage depends on jurisdiction, person or business context, data type, controller role, and statutory exceptions. Cite the applicable regulator or statute and present eligibility as a bounded question, not a universal conclusion. Sources: [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
  - **What should a business save as evidence of its request?** Keep the submitted text, date, route, confirmation, and any provider response while limiting unnecessary personal or confidential information. Saved correspondence documents the request process; it does not prove that a downstream recipient changed its record. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
- **Avoid:** assuming every B2B record is covered by every consumer privacy law · calling a processor portal the broker route without confirmation · promising removal from downstream customers

### Credit, Risk & Identity
- **Primary intent:** What is the correct privacy route when a broker, risk vendor, or consumer-reporting company holds identity data?
- **Fan-out questions:** Does the FCRA or another sector rule change the request path? · Is this a consumer report, identity signal, or marketing profile? · What identity verification is actually published? · Which regulator or official source explains the right? · What is the difference between a freeze, dispute, opt-out, and deletion request?
- **Source requirements:** provider rights or compliance page · CFPB, FTC, or statutory source where the legal boundary is discussed · separate treatment of consumer-reporting and marketing claims
- **Direct sources:** [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/) · [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement) · [Delete Act statutory text](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf)
- **Answer blocks:**
  - **Does the FCRA or another sector rule change the request path?** It can. First identify whether the record is a consumer report, an identity signal, a marketing profile, or another regulated context, then use the applicable provider and regulator source. A general privacy request should not be presented as a substitute for a dispute or freeze process. Sources: [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/), [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement)
  - **Is this a consumer report, identity signal, or marketing profile?** Use the provider description and official regulatory context rather than the company name alone. The catalog should preserve uncertainty when the available evidence does not establish the product or legal category. Sources: [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/), [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement)
  - **What identity verification is actually published?** Record only the identity checks stated in the current provider workflow. A request for verification can be request-specific; when a source is silent, label the expectation not recorded and recommend disclosing only what is necessary. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/)
  - **Which regulator or official source explains the right?** Link the controlling regulator, statute, or official rulemaking material beside the explanation and preserve the jurisdiction and date. Framework or enforcement material can provide context, but it is not automatically a finding about the individual provider. Sources: [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/), [Delete Act statutory text](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf)
  - **What is the difference between a freeze, dispute, opt-out, and deletion request?** These actions address different systems and purposes. A freeze, a consumer-report dispute, a marketing opt-out, and a deletion request should each be routed to the responsible provider using its applicable official instructions. Sources: [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/), [Delete Act statutory text](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf)
- **Avoid:** calling every identity vendor a credit bureau · using a privacy request as a substitute for a FCRA dispute · stating legal eligibility without jurisdiction and scope

### Advertising & Adtech
- **Primary intent:** How do people opt out of advertising, device, location, or audience data flows while distinguishing collection from broker publication?
- **Fan-out questions:** What data category or identifier does the provider describe? · Is there a consumer rights route or only an industry opt-out? · Does Global Privacy Control apply to this provider context? · Is the page a first-party request route or an explanatory policy? · What downstream or device-level control remains separate?
- **Source requirements:** provider privacy choices or request route · official regulator or recognized framework source · explicit distinction between provider statements and OfflistMe observations
- **Direct sources:** [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement) · [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework) · [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/)
- **Answer blocks:**
  - **What data category or identifier does the provider describe?** Name the category or identifier only when the provider or official source states it, such as device, location, audience, or contact data. A general privacy policy should not be narrowed into a more specific individual finding without supporting text. Sources: [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework), [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/)
  - **Is there a consumer-rights route or only an industry opt-out?** Identify whether the page provides a provider-specific rights route, an industry choice tool, a device control, or explanatory context. These mechanisms can coexist and should not be presented as interchangeable deletion channels. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
  - **Does Global Privacy Control apply to this provider context?** The answer depends on the provider, browser signal, jurisdiction, and the source describing how the signal is honored. Treat a GPC statement as provider-specific evidence and do not generalize one implementation to all advertising or data-broker flows. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework)
  - **Is the page a first-party request route or an explanatory policy?** Check the page language, form or submission controls, host relationship, and request type. A policy or choices page can explain rights without being the page where a request is submitted. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/)
  - **What downstream or device-level control remains separate?** A browser, operating-system, platform, or advertising-choice control can address a different collection or delivery point than a broker request. Document the separate control and its scope instead of claiming that one opt-out stops every downstream flow. Sources: [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework), [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement)
- **Avoid:** claiming an opt-out stops all tracking · inferring data sharing from a reachable endpoint · presenting industry-choice tools as universal deletion

### Social, Marketplaces & Platforms
- **Primary intent:** How do I remove a platform account or a broker copy of information connected to that platform?
- **Fan-out questions:** Is the data held by the platform or a separate broker? · What account-deletion and privacy-request paths differ? · What public profile or marketplace listing remains after account closure? · What evidence should be saved before submitting? · Which legal or platform-specific exception applies?
- **Source requirements:** platform help or privacy source · broker route source for copied records · clear separation of account closure from third-party removal
- **Direct sources:** [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement) · [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/) · [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa)
- **Answer blocks:**
  - **Is the data held by the platform or a separate broker?** Identify the controller or provider named in the source and keep platform-account data separate from a broker copy. A platform profile and a third-party listing can require different routes and produce different evidence. Sources: [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/), [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa)
  - **What account-deletion and privacy-request paths differ?** Account closure changes access to a platform account, while a privacy request addresses data processing by the named provider. Follow the current instructions for the specific system and do not treat account closure as downstream broker removal. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/)
  - **What public profile or marketplace listing remains after account closure?** Only state what the platform or broker source documents and re-check the relevant listing separately. The disappearance of an account does not establish that copied, indexed, or marketplace data was removed. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa)
  - **What evidence should be saved before submitting?** Save the route, request text, date, confirmation, and relevant listing reference while avoiding unnecessary sensitive data. This creates a follow-up record without claiming that the provider accepted or completed the request. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa)
  - **Which legal or platform-specific exception applies?** Use the platform terms, privacy source, registry record, or controlling statute that states the exception. Do not turn a general account rule or a broker category into a universal legal answer. Sources: [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement), [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/)
- **Avoid:** equating account deletion with downstream deletion · claiming platform-wide removal from a single request · using a generic form as proof of route ownership

### Top German Data brokers
- **Primary intent:** Which German or EU privacy route applies to a broker record, and what should a person verify before sending?
- **Fan-out questions:** Is the controller identified and in the EEA? · Does GDPR erasure, objection, or another right fit the request? · What response window and complaint authority apply? · Is the record sourced from a public register or commercial data? · What identity information is proportionate to provide?
- **Source requirements:** provider controller or rights page · GDPR/BDSG or relevant supervisory-authority source · country-specific registry or official record where applicable
- **Direct sources:** [EDPB Annual Report 2025](https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en) · [EDPB Data Subject Rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en) · [EUR-Lex General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)
- **Answer blocks:**
  - **Is the controller identified and in the EEA?** Start with the provider controller, legal name, contact, and jurisdiction stated in the provider source. A German-language domain or a European customer does not by itself prove the controller location or applicable scope. Sources: [EDPB Data Subject Rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en), [EUR-Lex General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)
  - **Does GDPR erasure, objection, or another right fit the request?** The relevant right depends on the processing purpose, legal basis, data, controller, and applicable exceptions. Explain the distinction using the official rights source and regulation text rather than treating every request as automatic erasure. Sources: [EDPB Data Subject Rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en), [EUR-Lex General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)
  - **What response window and complaint authority apply?** Use the current controller instructions and the applicable supervisory-authority guidance for the request. The knowledge base should preserve the source and jurisdiction instead of inventing a deadline from a generic privacy page. Sources: [EDPB Data Subject Rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en), [EDPB Annual Report 2025](https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en)
  - **Is the record sourced from a public register or commercial data?** Name the source type and link the relevant official record or provider statement. Public availability does not by itself remove data-protection obligations or prove that a particular broker record is lawful or unlawful. Sources: [EUR-Lex General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679), [EDPB Data Subject Rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en)
  - **What identity information is proportionate to provide?** Provide only what the controller reasonably needs to identify the requester or record, following its current instructions. The GDPR principles and rights context support minimisation, but the exact verification step remains provider- and request-specific. Sources: [EUR-Lex General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679), [EDPB Data Subject Rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en)
- **Avoid:** turning GDPR into an automatic deletion guarantee · assuming one EU route covers every affiliated controller · requesting unnecessary identity documents

## Evidence priorities

- **P0 — Failed route rechecks (33):** Recheck independently, preserve the failure or blocker, and do not convert it into a removal or unavailability claim.
- **P0 — Route semantics and route-channel review (925):** Confirm whether the source is a current first-party request route, a context page, a processor, or an ambiguous page before promoting it; keep email-only routes explicit.
- **P1 — Registry and entity context (210):** Resolve legal operator, aliases, parent relationships, and jurisdiction only from official or provider-supported evidence.
- **P1 — Provider business-context supplements (821):** Add current provider-described products, data categories, purposes, customer context, and control boundaries only from first-party or official sources; do not infer business context from a route or registry record.
- **P1 — Freshness review (15):** Refresh stale source records on a documented cadence; a changed date alone is not a content update.
- **P2 — Workflow detail enrichment (525):** Add request types, fields, identity boundaries, channels, and completion evidence only when the source supports them.

## Publication gates

- Use a canonical page for each intent; consolidate or noindex duplicate broker-specific blog pages.
- Lead with a self-contained answer, then show steps, comparison tables, FAQs, and direct source links.
- Show author, source-check date, date modified, methodology, and uncertainty on the page itself.
- Mirror visible content in JSON-LD; never mark up hidden, misleading, or unverified claims.
- Keep research-universe candidates out of customer-ready claims until route, entity, uniqueness, and source gates pass.
- Do not publish automated removal, guaranteed deletion, monitoring, mailbox acceptance, or outcome-rate claims.

## Vercel and crawl controls

- Keep broker profiles on-demand with ISR; do not pre-render the full catalog during Vercel builds.
- Keep heavy evidence artifacts server-side and expose compact generated indexes to machine readers.
- Use one catalog source to drive profile pages, directory links, schema, sitemaps, and LLM indexes.
- Prefer HTML and semantic headings over AI-only fragments; machine-readable files supplement, not replace, people-first pages.

## Measurement boundary

Google Search Console snapshot available for 2025-04-20 to 2026-08-13; use it for page and intent prioritization, then refresh it before making current-performance claims.

Run `GSC_DAYS=480 npm run gsc:comprehensive && npm run gsc:questions` only when live credentials are available. Google reports AI-feature traffic in standard Search Console web performance data; there is no separate local artifact here that can truthfully report AI Overview or competitor citation share.

## Tier-1 source library

- [California Data Broker Registry](https://cppa.ca.gov/data_broker_registry/) — California Privacy Protection Agency
- [Information for Data Brokers / DROP](https://cppa.ca.gov/data_brokers/) — California Privacy Protection Agency
- [Delete Act statutory text](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf) — California Privacy Protection Agency
- [HIPAA Breach Portal](https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf) — U.S. Department of Health and Human Services, Office for Civil Rights
- [Privacy and Security Enforcement](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement) — Federal Trade Commission
- [Consumer Sentinel Network Data Book](https://www.ftc.gov/reports/consumer-sentinel-network-data-book-2024) — Federal Trade Commission
- [FTC PADFAA data-broker guidance](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa) — Federal Trade Commission
- [Consumer reporting rulemaking materials](https://www.consumerfinance.gov/rules-policy/rules-under-development/protecting-americans-from-harmful-data-broker-practices-regulation-v/) — Consumer Financial Protection Bureau
- [NIST Privacy Framework](https://www.nist.gov/privacy-framework/privacy-framework) — National Institute of Standards and Technology
- [Cross-Sector Cybersecurity Performance Goals](https://www.cisa.gov/cybersecurity-performance-goals) — Cybersecurity and Infrastructure Security Agency
- [EDPB Annual Report 2025](https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en) — European Data Protection Board
- [EDPB Data Subject Rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en) — European Data Protection Board
- [EUR-Lex General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679) — European Union
- [2025 Internet Crime Report](https://www.fbi.gov/file-repository/2025_ic3report.pdf/view) — FBI Internet Crime Complaint Center

## Recent official-source reviews

These notes are bounded research candidates for the next High-impact tranche. They are not customer-ready route certifications, request-delivery evidence, deletion outcomes, or automatic catalog updates.

### Dataline, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Review the current portal and entity relationship, then promote only after the route and workflow are independently confirmed.
- **Official evidence:**
  - [https://datalinedata.com/privacy-policy/](https://datalinedata.com/privacy-policy/) — source date 2026-01-08: Dataline identifies itself as a provider of consumer marketing information. The policy directs consumers to its Privacy Portal for opt-out requests and describes California access, deletion, and sale/sharing rights.
  - [https://datalinedata.com/do-not-sell-my-information/](https://datalinedata.com/do-not-sell-my-information/): The policy links to this page as the Do Not Sell / Privacy Portal route. Limitation: The route returned a 404/cache miss in the bounded research environment; retain it as an unpromoted candidate until independently rechecked.

### Reveal Mobile, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current form route and record the device-identifier requirement as workflow context without implying a completed removal.
- **Official evidence:**
  - [https://revealmobile.com/privacy](https://revealmobile.com/privacy) — source date 2024-11-08: The policy describes an opt-in mobile location-data product and identifies IDFA/AdID as device identifiers used for matching. It directs consumers to a privacy request form and privacy@revealmobile.com for access, deletion, and sale opt-out requests.
  - [https://revealmobile.com/privacy-form](https://revealmobile.com/privacy-form): The official form states that it accepts access, deletion, and sale opt-out requests and responds within the timeframe required by applicable law.

### Tunnl, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm route semantics and jurisdiction scope before updating the customer-ready workflow record.
- **Official evidence:**
  - [https://www.tunnldata.com/privacy-policy](https://www.tunnldata.com/privacy-policy) — source date 2026-07-21: The policy identifies Tunnl, LLC and states that it processes information for clients, including people with whom it has no direct relationship. It describes GPC recognition and directs rights requests to an interactive webform or 1-866-498-2784.
  - [https://privacy.tunnldata.com/](https://privacy.tunnldata.com/): The linked official privacy-request portal is the provider-stated request channel.

### Unacast
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the provider privacy statement through an accessible first-party source before promoting any route or workflow detail.
- **Official evidence:**
  - [https://docs.unacast.com/legal/](https://docs.unacast.com/legal/): Unacast states that its products use aggregated data and that it honors mobile users’ requests not to accept location data, sharing those requests with partners. Limitation: The linked privacy statement was blocked by robots.txt in the research environment, so the underlying policy was not independently reviewed.

### Xcelerated Data LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current opt-out form URL and entity/client boundary before updating workflow fields.
- **Official evidence:**
  - [https://xcelerated.com/privacy/](https://xcelerated.com/privacy/) — source date 2026-01-01: The policy identifies Xcelerated LLC and distinguishes its own database from data processed for dealer or client entities. It describes a database opt-out process and says that opting out of Xcelerated’s database does not opt out of client databases.

### Veraset, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the live form and record device-level scope without implying universal or completed removal.
- **Official evidence:**
  - [https://www.veraset.com/legal/privacy-policy](https://www.veraset.com/legal/privacy-policy): The policy describes GPS location and device-level data products and identifies hashed email and mobile advertising identifiers among the data-solution opt-out context. It links to a provider opt-out form and states that a device-specific opt-out may need to be repeated for other devices or after an advertising-ID reset.
  - [https://www.veraset.com/do-not-sell-my-personal-information/](https://www.veraset.com/do-not-sell-my-personal-information/): The provider-stated opt-out and Do Not Sell form linked from the privacy policy.

### Webbula, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm current form behavior and exact identity fields before promoting the route or suppression wording.
- **Official evidence:**
  - [https://webbula.com/privacy-policy/](https://webbula.com/privacy-policy/) — source date 2026-03-26: The privacy notice identifies Webbula’s data services and says its direct database opt-out suppresses associated information rather than selling it. It identifies a direct opt-out page and privacy contact.
  - [https://webbula.com/privacy-center/](https://webbula.com/privacy-center/): The official privacy center presents opt-out, data-access, appeal, GDPR, and CCPA paths and identifies Webbula as a data broker under Texas law.
  - [https://webbula.com/opt-out-request/](https://webbula.com/opt-out-request/): The privacy notice names this page as the direct opt-out route and also provides a phone alternative.

### Azerion US Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Identify the relevant Azerion service/entity and its specific privacy notice before considering any route promotion.
- **Official evidence:**
  - [https://www.azerion.com/azerion-global-corporate-privacy-notice/](https://www.azerion.com/azerion-global-corporate-privacy-notice/): The global notice identifies Azerion Group N.V. and affiliates/subsidiaries as responsible parties and says specific services may have supplemental privacy notices. It directs service-specific information requests to dpo@azerion.com. Limitation: The global notice is not by itself a specific consumer data-broker opt-out route; service and entity scope require further review.

### Belardi Ostroy, ALC, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the legal-entity and brand relationship, then review the linked request routes before promoting any workflow detail.
- **Official evidence:**
  - [https://belardiwong.com/privacy-policy/](https://belardiwong.com/privacy-policy/) — source date 2026-01-27: The Belardi Wong policy describes state privacy rights, direct-marketing opt-out choices, and privacy-officer contact details. It describes marketing-data categories and says requests may require identity verification. Limitation: The current provider policy uses the Belardi Wong brand; the legal-entity relationship to the catalog name still requires explicit entity review.

### Convex Labs LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm whether the request route covers Convex’s own records or customer-user data before updating the catalog workflow.
- **Official evidence:**
  - [https://www.convex.com/privacy-policy](https://www.convex.com/privacy-policy) — source date 2026-01-30: The policy identifies Convex Labs LLC and states that Convex is a division of ServiceTitan, Inc.; it distinguishes Convex processing from Customer User Data processed for customers.
  - [https://www.convex.com/request-removal](https://www.convex.com/request-removal): The official privacy-choices page offers opt-out, access, correction, and deletion request types and lists support@convexlabs.io as an alternative contact.

### Cybba Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile the older general policy with the current California notice and identify the current consumer request route before promotion.
- **Official evidence:**
  - [https://cybba.com/privacy-policy/](https://cybba.com/privacy-policy/) — source date 2022-06-14: The policy describes Cybba digital-marketing services and distinguishes cookie/device opt-outs from marketing-email unsubscribe controls.
  - [https://cybba.com/ccpa-notice/](https://cybba.com/ccpa-notice/) — source date 2026-06-29: The current California notice supplements the older general policy and provides jurisdiction-specific disclosure context.

### Datonics LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the live request controls and preserve browser/device/email scope separately before updating the workflow record.
- **Official evidence:**
  - [https://www.datonics.com/privacy/technology-privacy-policy](https://www.datonics.com/privacy/technology-privacy-policy) — source date 2026-05-05: The technology policy describes cookies, hashed email addresses, and mobile advertising IDs and explains that opt-out choices can be browser- or device-specific. It states how Datonics treats Global Privacy Control and other opt-out preference signals where applicable.
  - [https://www.datonics.com/privacy/privacy-choices](https://www.datonics.com/privacy/privacy-choices): The privacy-choices page presents browser, mobile-device, and email privacy-rights paths and explains identifier-specific limitations.

### MediaWallah Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current portal URL and keep browser, mobile, CTV, and personal-information routes separate before promotion.
- **Official evidence:**
  - [https://mediawallah.com/privacy-policy/](https://mediawallah.com/privacy-policy/) — source date 2024-09-17: The policy describes MediaWallah services, opt-out paths for cookies and mobile advertising identifiers, and an opt-out portal for other identifiers or personal information. It provides privacy@mediawallah.com and a verifiable-request phone channel.

### MULTIMEDIA LISTS, INC.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Locate and independently review the current Do Not Sell / consumer request route before adding workflow details.
- **Official evidence:**
  - [https://multimedialists.com/privacy-policy/](https://multimedialists.com/privacy-policy/): The policy identifies Multimedia Lists as a provider of data marketing and consumer analytics products used across direct mail, email, online, and connected-TV channels. Limitation: The page was not sufficient in the bounded review to confirm the current consumer request form or exact route semantics.
  - [https://multimedialists.com/about/](https://multimedialists.com/about/): The provider describes data licensing, appends, list brokerage, and list-management services and links to its privacy and Do Not Sell paths.

### Nexxen Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current privacy-center behavior and controller-versus-client scope before promoting the route.
- **Official evidence:**
  - [https://nexxen.com/services-privacy-policy/](https://nexxen.com/services-privacy-policy/) — source date 2026-07-01: The services policy distinguishes Nexxen controller/business processing from client processor/service-provider processing. It describes industry tools, browser/device controls, Global Privacy Control, and a privacy-rights request page for opt-out, access, and deletion requests.
  - [https://nexxen.com/privacy-data-subject-rights-request/](https://nexxen.com/privacy-data-subject-rights-request/): The provider-stated privacy data-subject request route linked from the current services policy.

### Semcasting, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current PrivacyChoice route, jurisdiction scope, and source date discrepancy before workflow promotion.
- **Official evidence:**
  - [https://www.semcasting.com/privacy_policy_v1?hsLang=en](https://www.semcasting.com/privacy_policy_v1?hsLang=en) — source date 2026-04-01: The policy covers Semcasting and related services and describes consumer rights, Do Not Sell, and industry opt-out controls.
  - [https://www.semcasting.com/privacy_choice](https://www.semcasting.com/privacy_choice): The provider offers online, phone, and email privacy-choice channels and states a 10-to-30-day processing timeline for recorded selections.

### Taboola, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current access-request portal and preserve browser/device scope before updating the workflow record.
- **Official evidence:**
  - [https://policies.taboola.com/privacy-policy/](https://policies.taboola.com/privacy-policy/) — source date 2026-04-10: The policy describes user access, correction, deletion, and targeted-advertising or sale opt-out rights. It states that opt-out choices operate at the browser and device level and distinguishes contextual recommendations from interest-based recommendations.

### Viant US LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the platform privacy policy and live request controls, keeping business-contact and consumer platform scope separate.
- **Official evidence:**
  - [https://www.viantinc.com/privacy-center/](https://www.viantinc.com/privacy-center/): The privacy center is marked last updated July 2026, distinguishes platform privacy from website privacy, and presents separate opt-out and access/deletion/correction request paths. It describes targeted-advertising and sale/sharing choices and provides privacy@viantinc.com for certain business-contact requests.

### VideoAmp, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the form’s current request types and distinguish GPC handling from direct request submission before promotion.
- **Official evidence:**
  - [https://videoamp.com/privacy-policy](https://videoamp.com/privacy-policy) — source date 2026-06-08: The offerings policy describes VideoAmp media measurement and optimization services and links to a specific personal-information opt-out path. It distinguishes browser, mobile-device, and connected-device advertising choices.
  - [https://videoamp.com/opt-out/](https://videoamp.com/opt-out/): The official privacy-rights request page records requests and responses under applicable privacy laws and provides privacy@videoamp.com for questions.
  - [https://videoamp.com/us-privacy-notice](https://videoamp.com/us-privacy-notice): The U.S. notice states that VideoAmp currently responds to browser-based Global Privacy Control signals.

### Zeta Global
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Preserve the separate email and cookie/device route semantics and verify current request behavior before workflow promotion.
- **Official evidence:**
  - [https://zetaglobal.com/privacy-policy/](https://zetaglobal.com/privacy-policy/) — source date 2025-08-29: The policy separates website privacy from services privacy and describes access, deletion, sale/sharing, sensitive-data, email, and online-behavioral-advertising choices. It states that GPC and other universal opt-out signals are processed for sale/sharing requests.
  - [https://zetaglobal.com/privacy-choices/](https://zetaglobal.com/privacy-choices/): The privacy choices page distinguishes email-address and cookie-ID databases and instructs users to use the relevant mechanisms for each.
  - [https://zetaglobal.com/rights-request/](https://zetaglobal.com/rights-request/): The rights-request page allows a user to view, download, or request deletion of data associated with the current browser or mobile advertising identifier.

### Clickagy
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current request controls and preserve browser/device identity scope before workflow promotion.
- **Official evidence:**
  - [https://www.clickagy.com/privacy-center](https://www.clickagy.com/privacy-center): The privacy center separates access, deletion, do-not-sell/share, and correction choices and explains that requests are tied to the browser or device used. It identifies Clickagy as a data broker under Texas law and points to privacy@clickagy.com for correction questions.
  - [https://www.clickagy.com/privacy](https://www.clickagy.com/privacy): The privacy policy identifies Clickagy’s B2B buyer-intent and advertising technology context and links directly to the privacy center.

### i360, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the portal’s current request types and jurisdiction scope before updating the catalog workflow.
- **Official evidence:**
  - [https://www.i-360.com/privacy-policy/](https://www.i-360.com/privacy-policy/) — source date 2026-06-30: The current policy identifies i360, LLC and describes a consumer request portal for opting out of potential sale of covered information.

### Path2Response, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current portal URL and preserve U.S.-only scope, identity verification, and request-type distinctions before promotion.
- **Official evidence:**
  - [https://path2response.com/privacy-policy/](https://path2response.com/privacy-policy/) — source date 2026-07-01: The policy describes Path2Response data marketing services and provides access, correction, deletion, and sale/sharing opt-out choices. It gives a Consumer Rights Portal and phone route and states that Data Services requests are limited to U.S. consumers.
  - [https://path2response.com/privacy-approach/](https://path2response.com/privacy-approach/): The provider describes its consumer privacy approach and points to the Consumer Rights Portal and phone PIN route.

### 33 Mile Radius LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the affiliate/entity scope and preserve California-only route semantics before workflow promotion.
- **Official evidence:**
  - [https://www.33mileradius.com/privacy-policy/](https://www.33mileradius.com/privacy-policy/) — source date 2026-04-01: The policy identifies 33 Mile Radius among the Ignite Visibility affiliates covered by the notice and describes personal-information practices across websites, communications, and offline interactions.
  - [https://www.33mileradius.com/do-not-sell/](https://www.33mileradius.com/do-not-sell/): The official page offers a do-not-sell/delete form and states that it responds to verifiable consumer requests from California residents.

### 33Across, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current portal controls and preserve browser, device, and submitted-email scope separately before workflow promotion.
- **Official evidence:**
  - [https://www.33across.com/privacy-policy](https://www.33across.com/privacy-policy) — source date 2023-10-04: The policy describes 33Across advertising and publisher technology and explains cookie-based and cookie-less data collection. It says the provider opt-out applies to 33Across collection and uses persistent browser/device signals, while separate email and mobile-advertising-ID choices are limited to the submitted identifier.
  - [https://udp.33across.com/udp_opt_out](https://udp.33across.com/udp_opt_out): The official User Data Portal presents browser, email, access, erase, and do-not-sell choices and warns that browser/device changes can require a new opt-out.
  - [https://www.33across.com/privacy-policy/ccpa-notice](https://www.33across.com/privacy-policy/ccpa-notice) — source date 2025-07-08: The California notice links to the consumer request form and states that identity verification is required for certain requests.

### Anchor Computer Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the live opt-out form and preserve the provider-stated limitation that opting out of Anchor does not opt out of client or other-source databases.
- **Official evidence:**
  - [https://www.anchorcomputer.com/privacy-policy/](https://www.anchorcomputer.com/privacy-policy/) — source date 2026-06-01: The policy identifies ANCHOR Computer and its affiliates as providers of consumer and business marketing data products sourced from data partners. It offers an ANCHOR database opt-out through a first-party link, email, or toll-free phone route and describes identity-verification fields.
  - [https://ecom2.anchorcomputer.com/](https://ecom2.anchorcomputer.com/): The policy links to this provider-controlled opt-out destination for ANCHOR database requests. Limitation: The bounded source review did not independently confirm the form’s current fields or completion behavior.

### AtData, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the live privacy-rights form and preserve the distinction between general rights requests and sale/sharing or marketing opt-outs before promotion.
- **Official evidence:**
  - [https://atdata.com/privacy-policy/](https://atdata.com/privacy-policy/) — source date 2026-07-16: The policy identifies AtData, LLC and describes collection from public sources, customers, data compilers, data brokers, resellers, advertising networks, and other partners. It describes marketing, identity-resolution, data-hygiene, anti-fraud, and analytics services and identifies AtData as a data broker under Texas law.
  - [https://instantdata.atdata.com/optout](https://instantdata.atdata.com/optout): The official opt-out form accepts requests concerning targeted advertising or cross-context behavioral advertising, sale, certain profiling, and direct marketing.
  - [https://atdata.com/privacy-policy/](https://atdata.com/privacy-policy/) — source date 2026-07-16: The policy separately provides a privacy-rights form, an opt-out page, mail, and phone channels and reports 2025 consumer-request metrics. Limitation: The source supports request channels and scope, not mailbox acceptance, delivery, completion, or deletion outcomes.

### Audience Acuity
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the separate sale opt-out and rights-request form behavior, preserve client-database and retention exceptions, and only then assess workflow promotion.
- **Official evidence:**
  - [https://audienceacuity.com/privacy-policy/](https://audienceacuity.com/privacy-policy/) — source date 2025-12-29: The policy describes Audience Acuity audience-data services for analytics, enrichment, direct mail, online display, and email marketing. It states that an opt-out of Audience Acuity’s proprietary database does not opt a person out of client databases and may retain information for risk, compliance, or anti-fraud purposes.
  - [https://privacy.audienceacuity.com/](https://privacy.audienceacuity.com/): The official consumer-rights form presents delete and access choices and requires identity-matching information such as name plus address, email, or phone.
  - [https://optout.audienceacuity.com/](https://optout.audienceacuity.com/): The privacy policy links to a separate opt-out-of-sale form for sale or targeted-advertising choices.

### Bookyourdata
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the live form and preserve the distinction between provider-stated response targets, request processing, and any independently verified outcome before workflow promotion.
- **Official evidence:**
  - [https://www.bookyourdata.com/privacy-policy](https://www.bookyourdata.com/privacy-policy) — source date 2026-06-25: The policy identifies Bookyourdata and describes business-to-business marketing data processing and privacy requests for access, deletion, and opt-out. It states that verified requests have separate response expectations and publishes 2025 California request metrics.
  - [https://optout.bookyourdata.com/](https://optout.bookyourdata.com/): The provider-controlled form offers do-not-sell/share and deletion choices, requires email confirmation before action, identifies the operator as A Direct Marketing Inc., and states a 15-business-day target for verified sale/sharing opt-outs.

### Choreograph LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the portal’s current request types and preserve browser/device scope, offline-versus-online distinctions, and regional entity rules before promotion.
- **Official evidence:**
  - [https://www.choreograph.com/global-privacy-policy/global-privacy-policy-english](https://www.choreograph.com/global-privacy-policy/global-privacy-policy-english) — source date 2024-10-02: The global policy identifies Choreograph as a WPP data and technology business and describes both online and offline data handling. It links to a Consumer Preference Portal for privacy rights, future-processing opt-out, and deletion requests and states that portal choices apply to the specific browser or device used.
  - [https://cpp.choreograph.com/](https://cpp.choreograph.com/): The provider-linked Consumer Preference Portal is the stated route for exercising rights through the preference center. Limitation: The bounded review confirms the provider-stated portal relationship but does not certify acceptance, delivery, or completion of a request.

### Exact Customer
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the provider domain and locate the current first-party privacy notice or request form before adding any customer-ready route or timing detail.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/558915](https://oag.ca.gov/data-broker/registration/558915) — source date 2022-11-16: The California Department of Justice data-broker registration identifies Exact Customer, lists privacy@exactcustomer.com, and describes a California Privacy Notice and Do Not Sell path in the provider’s landing-page footers. The registration lists Exact Customer’s Connecticut address and records a phone opt-out route.
  - [http://exactcustomer.com](http://exactcustomer.com): The official California registration identifies this as the provider website. Limitation: The live provider site and the exact current privacy-request URL were not independently confirmed in the bounded review; retain the record as a registry-supported research candidate.

### Keyword Connects LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Identify and independently review any broker-database or Do Not Sell route, keeping site-marketing unsubscribe separate from suppression of data held for third parties.
- **Official evidence:**
  - [https://keywordconnects.com/privacy-policy/](https://keywordconnects.com/privacy-policy/) — source date 2025-07-25: The policy identifies Keyword Connects LLC and describes contact, device, cookie, marketing, affiliate, and third-party partner processing. It provides access, correction, erasure, export, California rights, identity-verification, and marketing-unsubscribe choices and reports California request metrics.
  - [https://keywordconnects.com/marketing-privacy-policy/](https://keywordconnects.com/marketing-privacy-policy/): The marketing policy provides unsubscribe instructions and privacy@keywordconnects.com for marketing-communication opt-out requests. Limitation: These pages describe site, marketing, and privacy-rights controls but do not by themselves confirm a current standalone data-broker suppression route for records held outside the Sites.

### Minerva
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current preferences form and preserve the designated-channel, identity-verification, and statutory timing details before workflow promotion.
- **Official evidence:**
  - [https://www.minerva.io/privacy-policy](https://www.minerva.io/privacy-policy) — source date 2025-03-31: The policy identifies Minerva BI Inc. and describes personal-information processing across online and offline Services, including data from customers, public records, data brokers, and other providers. It designates a webform at preferences.minerva.io and a toll-free number for access, correction, deletion, and sale/sharing opt-out requests and states that requests sent through other channels are redirected to the webform.
  - [https://preferences.minerva.io/](https://preferences.minerva.io/): The provider-stated preferences domain is the designated consumer-rights submission route. Limitation: The bounded review confirms the provider-stated destination but does not certify acceptance, delivery, or completion of a request.

### DataPartners
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current preference-form behavior and preserve the provider-only database scope, suppression-versus-deletion distinction, and designated-channel rule before promotion.
- **Official evidence:**
  - [https://www.datapartners.com/privacy-policy/](https://www.datapartners.com/privacy-policy/) — source date 2026-02-10: The policy identifies Data Partners Inc. and describes direct-marketing information sourced from public records, subscriptions, warranties, surveys, point-of-sale information, website activity, mobile applications, affiliates, and partners. It provides a Manage Your Privacy Preferences route and a toll-free phone route for database opt-out requests.
  - [https://www.datapartners.com/manage-your-privacy-preferences/](https://www.datapartners.com/manage-your-privacy-preferences/): The official privacy-preferences page distinguishes sale, targeted-advertising, profiling, and deletion choices and provides 866-423-1818 for assistance.
  - [https://www.datapartners.com/california-residents/](https://www.datapartners.com/california-residents/): The California privacy page supplements the general policy with jurisdiction-specific rights context. Limitation: DataPartners explicitly says email and general contact forms are not valid privacy-request channels; retain the designated web and phone routes separately.

### NFocus
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the live request pages and preserve address verification, state scope, statutory exceptions, and provider-versus-client boundaries before promotion.
- **Official evidence:**
  - [https://www.n-focus.com/privacy-policy/](https://www.n-focus.com/privacy-policy/) — source date 2025-12-16: The policy identifies NFocus Consulting Inc., describes business and consumer data services, and identifies NFocus as a data broker under Texas law. It provides deletion and Do Not Sell request pages, a phone route, identity verification context, and 2024 California request metrics.
  - [https://www.n-focus.com/do-not-sell-my-personal-information/](https://www.n-focus.com/do-not-sell-my-personal-information/): The provider-linked page is the stated Do Not Sell or Share request route. Limitation: The bounded review confirms the policy-linked route but does not independently certify form acceptance, delivery, or completion.

### Venntel
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current form’s required mobile-advertising identifier and preserve device-specific scope, partner/customer boundary, retention exceptions, and request metrics as separate facts before promotion.
- **Official evidence:**
  - [https://www.venntel.com/privacy-policy](https://www.venntel.com/privacy-policy) — source date 2026-01: The policy identifies Venntel, Inc. and describes location data received from partners, including latitude/longitude, mobile advertising IDs, IP address, application data, and device information. It describes data-services use, customer sharing, sale opt-out rights, a four-year retention period for data-services personal information, and a device-specific opt-out limitation.
  - [https://www.venntel.com/opt-out](https://www.venntel.com/opt-out): The official Opt Out & Delete Request page is the provider-stated route for location-data choices.
  - [https://www.venntel.com/privacy-request-statistics](https://www.venntel.com/privacy-request-statistics) — source date 2026-01: The provider publishes 2025 privacy-request metrics and states that the reported figures cover all individuals regardless of jurisdiction.

### Wiland Direct
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current form destinations and preserve request-type, identity-verification, authorized-agent, and Wiland-only scope before workflow promotion.
- **Official evidence:**
  - [https://wiland.com/privacy-policies/](https://wiland.com/privacy-policies/): The policy identifies Wiland, Inc. and describes consumer-data use in marketing products and services, including information obtained from sources other than the Wiland website.
  - [https://wiland.com/privacy-choices/](https://wiland.com/privacy-choices/) — source date 2026-07-01: The current privacy-choice page offers opt-out, deletion, and access paths for U.S. consumers, provides a toll-free telephone route, and states that choices apply specifically to Wiland and the personal information it collects. The page documents identity and authorized-agent requirements and says requests should use the designated forms or phone channel.

### Consumerbase, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve the Consumerbase, Exact Data, and Data Axle entity relationship and recheck the live Do Not Sell route before adding customer-ready workflow details.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/555117](https://oag.ca.gov/data-broker/registration/555117) — source date 2022-07-13: The California Department of Justice registration identifies Consumerbase LLC doing business as Exact Data, lists privacy@exactdata.com, and describes an email or website Do Not Sell route.
  - [https://www.exactdata.com/privacy-policy.html](https://www.exactdata.com/privacy-policy.html): The current Exact Data privacy page identifies Data Axle Inc. and affiliates as providers of consumer and B2B marketing data services and directs consumers to a Do Not Sell route or privacy email for rights requests. Limitation: The current policy is branded around Data Axle while the California registry names Consumerbase LLC d/b/a Exact Data; the legal-entity and route relationship requires explicit reconciliation.
  - [https://www.exactdata.com/faq/](https://www.exactdata.com/faq/): The provider describes Exact Data as a consumer and business data service and links to its privacy policy.

### Lead Me Media LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the policy portal’s current form behavior and keep database, email, SMS, browser-signal, and third-party/client controls separate before promotion.
- **Official evidence:**
  - [https://policy.leadmemedia.com/PoliciesTermsConditions/privacypolicy.html](https://policy.leadmemedia.com/PoliciesTermsConditions/privacypolicy.html) — source date 2025-01-16: The policy identifies Lead Me Media, LLC and describes consumer-information collection through surveys, order forms, registrations, third-party sources, email, and SMS. It provides a dedicated policy portal, phone, and mailing route for privacy-rights requests and describes opt-out-of-sale/sharing, targeted-advertising, profiling, and marketing choices.
  - [https://leadmemedia.com/privacy.html](https://leadmemedia.com/privacy.html): The provider’s website privacy page separately describes email-list and SMS unsubscribe controls and notes that third-party websites and clients may have separate practices. Limitation: The older website policy and newer policy portal should not be merged into one route without confirming the current request destination and scope.

### Cengage Learning, Inc. (Gale Directories)
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current Gale Directory opt-out form and map the Gale/Cengage entity relationship, keeping product-specific sale/sharing choices separate from general Cengage account deletion.
- **Official evidence:**
  - [https://www.cengagegroup.com/privacy/notice/](https://www.cengagegroup.com/privacy/notice/) — source date 2026-02-17: The current Cengage Privacy Notice identifies Cengage Learning, Inc. and subsidiaries including Gale and provides general privacy-rights, sale/sharing, targeted-advertising, and deletion routes. It specifically directs consumers to a separate sale/sharing form for Gale Directory products and lists a privacy-rights form and phone route.
  - [https://oag.ca.gov/data-broker/registration/562707](https://oag.ca.gov/data-broker/registration/562707) — source date 2023-02-08: The California Department of Justice registration identifies Gale, lists privacy@cengage.com, and directs consumers to gale.com/privacy for CCPA requests and deletion requests. Limitation: The catalog record uses the Cengage domain and Gale Directories label; the exact current Gale product route and entity mapping require reconciliation before promotion.

### Alliant Cooperative Data Solutions LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the live portal fields and preserve Alliant-versus-AnalyticsIQ, website-versus-Data-Products, and FCRA-specific route boundaries before promotion.
- **Official evidence:**
  - [https://alliantinsight.com/data-services-and-website-privacy-policy/](https://alliantinsight.com/data-services-and-website-privacy-policy/) — source date 2026-07-29: The data-products policy identifies Alliant Cooperative Data Solutions, LLC and its subsidiaries and affiliates, including Analytics IQ, and expressly separates licensed Data Products from website visitor data. It describes identifiers, contact information, purchase behavior, interests, and other consumer information used in Data Products and links to Do Not Sell and sensitive-information controls.
  - [https://privacyportal-cdn.onetrust.com/dsarwebform/591ac1c1-3a1e-496f-9e43-ff4afb5fef85/2b52262e-8ada-4725-b86e-e4b960336f96.html](https://privacyportal-cdn.onetrust.com/dsarwebform/591ac1c1-3a1e-496f-9e43-ff4afb5fef85/2b52262e-8ada-4725-b86e-e4b960336f96.html): The current Alliant policy footer links to this provider-controlled privacy web form for Do Not Sell or Share and sensitive-information choices. Limitation: The form is hosted on a privacy-portal domain and its dynamic fields were not independently validated in the bounded review.
  - [https://alliantinsight.com/opt-out-statistics/](https://alliantinsight.com/opt-out-statistics/): Alliant publishes consumer-request statistics and identifies the website entity as a data broker under Texas law.

### Data Axle Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Data Axle’s parent/affiliate routing with Exact Data and other catalog aliases, then preserve GPC, verification, and authorized-agent scope before promotion.
- **Official evidence:**
  - [https://www.data-axle.com/privacy-policy/](https://www.data-axle.com/privacy-policy/): The policy identifies Data Axle as a data broker under Texas law, describes consumer and B2B data from public and third-party sources, and lists Exact Data among Data Axle affiliates. It recognizes Global Privacy Control and provides consumer and authorized-agent rights-request routes.
  - [https://www.data-axle.com/privacy-rights-request/](https://www.data-axle.com/privacy-rights-request/): The official consumer form presents access, sale/sharing opt-out, deletion, and correction choices and requires identifying contact information for verification.
  - [https://www.data-axle.com/privacy-rights-request-authorized-agent/](https://www.data-axle.com/privacy-rights-request-authorized-agent/): The provider offers a separate authorized-agent form and requires authority documentation for delegated requests.

### Altrata, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current product-rights contact and map Altrata, Delinian, and named product entities before adding a customer-ready route.
- **Official evidence:**
  - [https://altrata.com/product-privacy-notice](https://altrata.com/product-privacy-notice) — source date 2026-06: The Product Privacy Notice identifies Altrata people-intelligence products including BoardEx, RelSci, Wealth-X, and WealthEngine and states that information is processed for client-facing products. It provides access, correction, deletion, portability, objection, and sale/sharing choices, with identity verification and a California phone route.
  - [https://altrata.com/online-privacy-notice](https://altrata.com/online-privacy-notice) — source date 2026-06: The separate Online Privacy Notice covers website and online-platform data and identifies Altrata as part of Delinian. Limitation: The online notice and product notice cover different processing contexts; the product-data request route must not be inferred from website-cookie or marketing controls.

### Claritas LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current portal controls and keep offline database, digital identifier, email, GPC, and U.S.-only scope distinct before workflow promotion.
- **Official evidence:**
  - [https://claritas.com/privacy-legal/](https://claritas.com/privacy-legal/) — source date 2026-05-08: The current notice identifies Claritas, LLC as a data-driven marketing company and a registered data broker under California, Oregon, Texas, and Vermont law. It separates offline marketing-database opt-out, digital/browser opt-out, marketing-email unsubscribe, access, correction, deletion, and appeal routes and states that U.S. scope applies to Claritas services.
  - [https://privacyportal.onetrust.com/webform/68582716-6ce4-4f6e-bf08-78371b5f3292/6c7dc52d-0e2b-481f-9256-0755179e3783](https://privacyportal.onetrust.com/webform/68582716-6ce4-4f6e-bf08-78371b5f3292/6c7dc52d-0e2b-481f-9256-0755179e3783): The policy links to a provider-controlled portal for offline and digital privacy choices. Limitation: The portal is dynamic and the bounded review did not independently validate its current field set or completion behavior.

### First Direct, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the current Alerts.com relationship and preserve the historical registry date, provider identity, and request-route uncertainty before promotion.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/186251](https://oag.ca.gov/data-broker/registration/186251) — source date 2020-01-30: The California Department of Justice registration identifies First Direct, Inc., lists support@firstdirectmarketing.com, and states that consumers may search and submit CCPA requests or protected-person deletion requests through alerts.com. Limitation: This is a historical registration record; the registry states that legacy California registrations cover 2020-2023, so the current operating entity and live route require a fresh check.
  - [https://firstdirectmarketing.com/privacy-policy/](https://firstdirectmarketing.com/privacy-policy/): The provider hosts a first-party privacy policy and links it from the current First Direct site. Limitation: The bounded review did not independently validate the current request workflow or reconcile the provider policy with the registry-listed Alerts.com route.
  - [https://alerts.com/](https://alerts.com/): The California registration names Alerts.com as the search and request destination for First Direct consumers. Limitation: The route is hosted on a separate domain; its current relationship to First Direct and request completion behavior were not independently validated.

### Speedeon Data LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the live form and preserve the distinction between suppression, deletion, sale/sharing, sensitive-data, identity, and U.S.-address scope before promotion.
- **Official evidence:**
  - [https://speedeondata.com/privacy-policy/](https://speedeondata.com/privacy-policy/) — source date 2026-01-21: The Data Products Privacy Policy identifies Speedeon Data LLC and describes consumer information assembled and provided to customers primarily for marketing purposes. It documents privacy rights and opt-out choices for sale, sharing, targeted advertising, profiling, and sensitive personal information, plus authorized-agent and contact routes.
  - [https://optout.speedeondata.com/](https://optout.speedeondata.com/): The provider-controlled opt-out form offers deletion, opt-out, and sensitive-data choices and states that an approved request adds the submitted name and address to a suppression file; the form limits each request to one name and address. Limitation: The bounded review confirms provider-stated form behavior only and does not certify acceptance, delivery, deletion, or suppression completion.

### WINR Data
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Locate and date the current first-party privacy notice, confirm the portal’s live controls, and keep identity verification, fraud prevention, digital advertising, and jurisdiction scope separate before promotion.
- **Official evidence:**
  - [https://www.winrdata.com/](https://www.winrdata.com/): The provider describes WINR as an identity-resolution, identity-verification, address-intelligence, KYC, and fraud-prevention data business with coverage across multiple geographies.
  - [https://www.winrdata.com/contact-us/](https://www.winrdata.com/contact-us/): The provider’s contact page directs data-subject access or suppression requests to privacy@winrdata.com or a secure web form.
  - [https://privacyportal-au.onetrust.com/webform/ad3cafad-4bf2-4d22-951f-57cc1fd05690/5fa8f2da-0508-42a6-bbc7-9b031898d10c](https://privacyportal-au.onetrust.com/webform/ad3cafad-4bf2-4d22-951f-57cc1fd05690/5fa8f2da-0508-42a6-bbc7-9b031898d10c): The provider-linked OneTrust form presents consumer, household, parent or guardian, and authorized-agent request roles and asks for jurisdiction and identity details. Limitation: The dynamic portal and its current legal-entity, geography, and request-completion behavior were not independently validated in the bounded review.

### Yes
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve the catalog alias and entity mapping, then preserve browser, device, mobile-advertising-ID, CTV, platform, and website-policy scope before promotion.
- **Official evidence:**
  - [https://pubmatic.com/legal/privacy-policy/](https://pubmatic.com/legal/privacy-policy/) — source date 2026-07: The current Platform Privacy Policy identifies PubMatic, Inc. and global subsidiaries and describes SSP and advertising-platform processing involving online identifiers, device and browser information, audience segments, geolocation, behavioral information, and ad interactions. It separates platform privacy from PubMatic website privacy and PubMatic US, Inc. policy contexts and documents state-law opt-out and data-rights choices.
  - [https://pubmatic.com/legal/opt-out/](https://pubmatic.com/legal/opt-out/) — source date 2026-05: The provider’s opt-out page describes browser- or device-specific choices for interest-based advertising, mobile advertising IDs, and cross-device targeting and states that opting out does not stop all advertising.
  - [https://apps.pubmatic.com/optout.jsp?action=optout](https://apps.pubmatic.com/optout.jsp?action=optout): The current PubMatic legal pages link to this provider-controlled opt-out tool for platform advertising choices. Limitation: The dynamic tool was not independently tested for acceptance or completion, and the catalog name “Yes” must be reconciled to PubMatic and the correct legal entity before promotion.

### Dataline, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current portal fields and preserve sale, sharing, limited-use, browser-advertising, California-verification, and deletion semantics as separate facts before promotion.
- **Official evidence:**
  - [https://datalinedata.com/privacy-policy/](https://datalinedata.com/privacy-policy/): The policy identifies Dataline as a data broker under Texas law and describes opt-out choices for sale, sharing, limited use, and online targeted advertising. It states that Dataline treats opt-out of sale, sharing, and limited use as deletion requests and distinguishes browser or device advertising opt-outs from its direct privacy route.
  - [https://datalinedata.com/privacy-portal/](https://datalinedata.com/privacy-portal/): The provider privacy portal presents access, delete or Do Not Sell, cross-contextual behavioral advertising, and correction choices and provides a verification step for the request. Limitation: The bounded review confirms the provider-stated portal and request types but does not certify submission acceptance, delivery, deletion, or suppression completion.
  - [https://oag.ca.gov/data-broker/registration/187481](https://oag.ca.gov/data-broker/registration/187481) — source date 2020-02-27: The California Department of Justice registration identifies Dataline, Inc., lists privacy.officer@datalinedata.com, and records the provider website and California request-verification process. Limitation: This is a historical registration record; the current operating details and request behavior must be rechecked against the live provider policy.

### Reveal Mobile, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile the historical /ccpa/ route with the current privacy form and preserve opt-in, mobile-advertising-ID, location, device, customer, and website scope before promotion.
- **Official evidence:**
  - [https://revealmobile.com/privacy](https://revealmobile.com/privacy) — source date 2024-11-08: The policy identifies Reveal Mobile, Inc. and describes its location-measurement business, mobile-product data, device identifiers, and website processing. It states that the Mobile Product is opt-in, describes device and app-level controls, and offers a U.S. privacy form for access, deletion, and sale opt-out requests.
  - [https://revealmobile.com/privacy-form/](https://revealmobile.com/privacy-form/): The provider’s consumer privacy form states that consumers may request that location data not be used or sold and offers optout@revealmobile.com as an alternate contact route. Limitation: The bounded review confirms the provider-stated form and email route but does not certify acceptance, delivery, device matching, deletion, or sale-opt-out completion.
  - [https://oag.ca.gov/data-broker/registration/548416](https://oag.ca.gov/data-broker/registration/548416) — source date 2021-12-10: The California Department of Justice registration identifies Reveal Mobile, lists privacy@revealmobile.com, and records the historical CCPA route and privacy policy. Limitation: The registry points to a legacy /ccpa/ path; the current privacy form should be treated as the live candidate only after route reconciliation.

### Tunnl, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current designated request channel and preserve direct-relationship, client-service, targeted-advertising, sale, profiling, jurisdiction, and legacy-contact boundaries before promotion.
- **Official evidence:**
  - [https://www.tunnldata.com/privacy-policy](https://www.tunnldata.com/privacy-policy) — source date 2026-07-21: The current policy identifies Tunnl, LLC, is effective as of June 2026, and expressly covers individuals without a direct relationship whose information is processed through client services. It describes rights to opt out of targeted advertising, sale, and certain profiling and provides notice@tunnldata.com for a privacy request context.
  - [https://oag.ca.gov/data-broker/registration/550371](https://oag.ca.gov/data-broker/registration/550371) — source date 2022-01-28: The California Department of Justice registration identifies Tunnl, LLC and records historical CCPA opt-out, information, and deletion routes using dedicated email addresses and a toll-free number. Limitation: The registry routes are historical; the current policy and live request-channel relationship require explicit reconciliation before using the older email or phone details in customer-facing workflow.
  - [https://www.tunnldata.com/ccpa](https://www.tunnldata.com/ccpa): The current privacy policy identifies the provider CCPA page as a source for data-collection and privacy-rights information. Limitation: The bounded review did not independently validate the current CCPA page fields or request-completion behavior.

### Unacast
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current form and preserve Data Services versus website scope, device-specific location choices, mobile-advertising-ID reset behavior, supplier/customer boundaries, and request outcome limits before promotion.
- **Official evidence:**
  - [https://www.unacast.com/privacy-policy](https://www.unacast.com/privacy-policy) — source date 2026-01: The current policy identifies Unacast, Inc. and separates Data Services from website processing, including information received from third-party data suppliers. It provides sale opt-out, access, deletion, and privacy-request choices and states that Data Services opt-out is specific to the submitted device and may need to be repeated after a mobile-advertising-ID reset.
  - [https://www.unacast.com/opt-out](https://www.unacast.com/opt-out): The provider’s Opt Out & Delete Request page offers a form for sale opt-out and related privacy questions and identifies privacy@unacast.com as an alternate route. Limitation: The bounded review confirms the provider-stated form but does not certify acceptance, delivery, device matching, deletion, or opt-out completion.
  - [https://oag.ca.gov/data-broker/registration/550828](https://oag.ca.gov/data-broker/registration/550828) — source date 2022-02-10: The California Department of Justice registration identifies Unacast, Inc., lists privacy@unacast.com, and records the provider webform for know, delete, and sale opt-out requests. Limitation: The registration is historical; retain it as registry context rather than proof that a current request was accepted or completed.

### Xcelerated Data LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile the two provider privacy URLs and current form destination, then preserve proprietary-database, client-database, risk/compliance, marketing-channel, verification, and forward-looking scope before promotion.
- **Official evidence:**
  - [https://xcelerated.com/privacy/](https://xcelerated.com/privacy/) — source date 2026-01-01: The policy identifies Xcelerated LLC and its subsidiaries and affiliates and describes data products used for direct mail, email, display, social, television, and radio marketing. It provides access, correction, deletion, sale/sharing, targeted-advertising, and profiling rights and says the database opt-out applies to Xcelerated’s proprietary database rather than clients’ databases.
  - [https://www.xcelerated.com/privacy](https://www.xcelerated.com/privacy) — source date 2026-01-01: The provider’s alternate privacy page describes the Xcelerated database opt-out and states that an opt-out is forward-looking and may not remove data from client databases or risk, compliance, and anti-fraud products. Limitation: The provider exposes both xcelerated.com and www.xcelerated.com privacy URLs; the exact live form destination and request-completion behavior were not independently validated.

### Veraset, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current form destination and preserve hashed-email, mobile-advertising-ID, location, device-specific, reset, client, and legacy-registry route boundaries before promotion.
- **Official evidence:**
  - [https://www.veraset.com/legal/privacy-policy](https://www.veraset.com/legal/privacy-policy): The policy identifies Veraset, LLC and describes GPS location and device-level point-of-interest data products supplied to clients for advertising, research, urban planning, customer insights, and analytics. It provides device settings and a provider form for hashed email, mobile advertising identifiers, location data, and related data, and states that the choice is device-specific and must be repeated after a mobile-advertising-ID reset.
  - [https://www.veraset.com/legal/do-not-sell-request](https://www.veraset.com/legal/do-not-sell-request): The provider’s request page presents consumer sale, sharing, and targeted-advertising choices and identifies a mobile-advertising-ID workflow for the data-solution opt-out. Limitation: The dynamic request flow was not independently tested for acceptance, device matching, deletion, or completion.
  - [https://oag.ca.gov/data-broker/registration/186412](https://oag.ca.gov/data-broker/registration/186412) — source date 2020-03-23: The California Department of Justice registration identifies Veraset, lists privacy@veraset.com, and records a historical opt-out path requiring email and mobile advertising ID. Limitation: The registry references a legacy /do-not-sell-my-info path; reconcile it with the current legal request page before using either URL as a customer-ready route.

### Webbula, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current privacy-center form and preserve direct-database, active-marketing, forever-suppression, cookie-based advertising, data-hygiene, and historical-registry scope before promotion.
- **Official evidence:**
  - [https://webbula.com/privacy-policy/](https://webbula.com/privacy-policy/) — source date 2026-03-26: The current notice identifies Webbula, LLC, describes online and offline data services, and distinguishes its direct database opt-out from cookie-based industry opt-outs. It states that a direct opt-out suppresses personal information from Webbula’s active marketing databases and identifies a provider form and phone route.
  - [https://webbula.com/privacy-center/](https://webbula.com/privacy-center/): The provider privacy center offers opt-out, data access, appeal, and privacy-notice paths and states that an opt-out removes information from data services and adds the person to a forever suppression. Limitation: The bounded review confirms provider-stated suppression language but does not certify acceptance, delivery, or suppression completion.
  - [https://oag.ca.gov/data-broker/registration/186746](https://oag.ca.gov/data-broker/registration/186746) — source date 2020-02-07: The California Department of Justice registration identifies Webbula, LLC, records its privacy center, email, phone, and mailing routes, and describes its data hygiene and customer-insight services. Limitation: The registration is historical and contains older address and phone details; prefer the current provider privacy center after reconciliation.

### Azerion US Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Map Azerion Group, Azerion Services B.V., Azerion Technology B.V., Inskin, and the catalog’s Azerion US label, then confirm the current service-specific request route before promotion.
- **Official evidence:**
  - [https://www.azerion.com/azerion-global-corporate-privacy-notice/](https://www.azerion.com/azerion-global-corporate-privacy-notice/) — source date 2025-07-01: The current global notice identifies Azerion Group N.V. and its affiliates and subsidiaries and covers services, advertisements, mobile applications, products, and data received from business partners. It provides access, correction, deletion, objection, portability, and data-protection-officer contact through dpo@azerion.com.
  - [https://www.azerion.com/inskin-privacy-notice/](https://www.azerion.com/inskin-privacy-notice/): The provider’s Inskin-specific notice describes a service-specific privacy context, direct-marketing controls, and data-subject rights through dpo@azerion.com. Limitation: The Inskin notice is product-specific and must not be generalized to every Azerion or Azerion US processing context.
  - [https://www.azerion.com/website-privacy-notice/](https://www.azerion.com/website-privacy-notice/) — source date 2022-09-01: The website notice provides separate website-processing, deletion, and data-subject-rights context and identifies Azerion Services B.V. as the website operator. Limitation: The notice is older and website-specific; it is supporting context only, not proof of a current advertising-data or Azerion US request route.

### Belardi Ostroy, ALC, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve the Belardi Ostroy, Belardi Wong, and Acxiom relationship and locate the current service or offline-database request route, keeping website, direct-marketing, and client-service controls separate before promotion.
- **Official evidence:**
  - [https://belardiwong.com/privacy-policy/](https://belardiwong.com/privacy-policy/) — source date 2026-01-27: The current policy identifies Belardi Wong and states that it is limited mainly to website collection except for the State Privacy Rights section. It describes direct-marketing opt-out choices for U.S. residents, site advertising and analytics controls, and a Privacy Officer contact at privacy.officer@belardiwong.com and 800-252-5478. Limitation: The policy expressly excludes most offline and service processing; it cannot by itself establish the route for data held in Belardi Wong’s marketing services.
  - [https://www.belardiwong.com/privacy](https://www.belardiwong.com/privacy): The provider’s alternate privacy URL is retained as a first-party route candidate for the Belardi Wong privacy context. Limitation: The bounded review did not independently confirm whether this alternate URL is current or whether its direct-marketing form differs from the canonical policy page.

### Convex Labs LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Convex Labs, Convex, ServiceTitan, and the Atlas product entities, then verify the current data-broker registration and request route before promotion.
- **Official evidence:**
  - [https://www.convex.com/privacy-policy](https://www.convex.com/privacy-policy) — source date 2026-01-30: The policy identifies Convex Labs LLC, states that Convex is a division of ServiceTitan, Inc., and covers the Convex and Atlas websites, applications, products, services, tools, and features. It describes consumer privacy choices and directs users to the provider request-removal route for applicable rights.
  - [https://www.convex.com/request-removal](https://www.convex.com/request-removal): The provider request form offers access, deletion, correction, and sale opt-out request types, asks for user type and state, and provides support@convexlabs.io as an alternate route with possible identity verification. Limitation: The bounded review confirms the provider-stated request form but does not certify acceptance, delivery, entity matching, or completion.
  - [https://www.convex.com/data-sourcing-and-privacy-compliance](https://www.convex.com/data-sourcing-and-privacy-compliance): Convex’s privacy-compliance page states that it maintains a California data-broker registration and offers a Do Not Sell form. Limitation: This page is provider context rather than an independently verified registry record; preserve the California registration claim separately until the current registry entry is matched.

### Cybba Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current OneTrust destination and preserve California verification, client versus Cybba processing, cookie/mobile scope, marketing unsubscribe, and historical phone-route boundaries before promotion.
- **Official evidence:**
  - [https://cybba.com/ccpa-notice/](https://cybba.com/ccpa-notice/) — source date 2025-12-04: The current California notice identifies Cybba Inc., describes identifiers, commercial and online activity, geolocation, client and advertising-network disclosures, and lists access, deletion, and opt-out rights. It provides a current Do Not Sell route and a phone route with verification requirements and response-timing information.
  - [https://cybba.com/privacy-policy/](https://cybba.com/privacy-policy/) — source date 2022-06-14: The general policy describes Cybba’s digital-marketing services and distinguishes website, mobile, cookie, client, and interest-based-advertising choices. Limitation: The general policy is older than the California notice; use the newer jurisdiction-specific notice for current California request semantics and keep general marketing unsubscribe separate.
  - [https://oag.ca.gov/data-broker/registration/540582](https://oag.ca.gov/data-broker/registration/540582) — source date 2021-05-06: The California Department of Justice registration identifies Cybba Inc. and records a historical OneTrust request flow, email verification, and phone fallback for CCPA opt-out requests. Limitation: The registry route and phone details are historical; reconcile them with the current CCPA notice before using the flow as a customer-ready route.

### Datonics LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current privacy-choice form and preserve browser, mobile-advertising-ID, hashed-email, cookie, cross-device, GPC, website, and technology-policy boundaries before promotion.
- **Official evidence:**
  - [https://www.datonics.com/privacy/technology-privacy-policy](https://www.datonics.com/privacy/technology-privacy-policy) — source date 2026-05-05: The current Technology Privacy Policy identifies Datonics as a New York-based advertising-technology company and states that it is considered a data broker under certain state laws. It describes cookies, hashed emails, mobile advertising IDs, browsing and search data, partner sources, targeted advertising, cross-device association, and Global Privacy Control treatment.
  - [https://www.datonics.com/privacy/privacy-choices](https://www.datonics.com/privacy/privacy-choices): The privacy-choices page offers browser, mobile-device, hashed-email, access, deletion, correction, sale/sharing, targeted-advertising, and sensitive-information choices. It documents browser-cookie, mobile-advertising-ID, and particular-email scope and explains that choices may need to be repeated after cookie, browser, device, or advertising-ID changes. Limitation: The dynamic form behavior was not independently tested for acceptance, delivery, or completion.
  - [https://www.datonics.com/privacy](https://www.datonics.com/privacy): The provider privacy center separates website, technology, Data Privacy Framework, Shopify app, and privacy-choice contexts. Limitation: Do not merge the website and technology policies into one request route; the catalog record requires technology-data scope.

### MediaWallah
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve and verify the current service-data privacy portal, then preserve cookie, mobile, CTV, hashed-email, device-linkage, client, partner, website, and marketing-email boundaries before promotion.
- **Official evidence:**
  - [https://mediawallah.com/privacy-policy/](https://mediawallah.com/privacy-policy/): The provider policy describes MediaWallah services involving cookies, mobile and CTV identifiers, hashed email, device linkage, advertising measurement, audience targeting, and data shared with clients and partners. It distinguishes promotional-email unsubscribe from service-level tracking and identifies a cookie opt-out, industry opt-outs, and a separate portal for other identifiers or personal information. Limitation: The bounded review did not resolve the linked portal destination or independently validate the current form behavior.
  - [https://mediawallah.com/](https://mediawallah.com/): The first-party domain is retained as the provider context for MediaWallah’s privacy policy and service materials. Limitation: A website or marketing unsubscribe must not be presented as proof of removal from MediaWallah’s service data or client databases.

### Multimedia Lists, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the current Do Not Sell destination and preserve marketing-database suppression, direct-collection deletion, client-service, connected-TV, and historical Alerts.com scope before promotion.
- **Official evidence:**
  - [https://multimedialists.com/privacy-policy/](https://multimedialists.com/privacy-policy/) — source date 2021-12-14: The policy identifies Multimedia Lists, Inc. and describes consumer and analytics data used for direct mail, email, online, connected-TV, and other marketing channels. It distinguishes opt-out of sale or marketing-database suppression from deletion of information collected directly from a consumer and notes that service-provider requests may need to go through the named client. Limitation: The policy is dated and the live Do Not Sell form destination was not independently resolved in the bounded review.
  - [https://oag.ca.gov/data-broker/registration/548525](https://oag.ca.gov/data-broker/registration/548525): The California Department of Justice registration identifies Multimedia Lists, Inc. and records an Alerts.com route for opt-out and deletion requests. Limitation: The registry route is historical and must be reconciled with the current provider privacy page before promotion.
  - [https://multimedialists.com/contact/](https://multimedialists.com/contact/): The provider contact page supplies current first-party business contact context for Multimedia Lists. Limitation: General sales contact is not a verified privacy-request route.

### Nexxen Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Nexxen Inc, Nexxen International, Tremor, Amobee, and client-processor contexts, then verify the current Privacy Center before promotion.
- **Official evidence:**
  - [https://nexxen.com/services-privacy-policy/](https://nexxen.com/services-privacy-policy/) — source date 2026-07-01: The current Services Privacy Policy describes Nexxen’s global advertising technology services across web, mobile, CTV, linear television, and digital channels and identifies device, browsing, location, ad-interaction, inferred-segment, and transaction data. It separates controller or business processing from client processor or service-provider processing and documents access, deletion, correction, sale/sharing opt-out, authorized-agent, and appeal contexts.
  - [https://nexxen.com/privacy-data-subject-rights-request/](https://nexxen.com/privacy-data-subject-rights-request/): The provider-linked Privacy Center is the stated route for consumer privacy rights and targeted-advertising opt-out requests. Limitation: The dynamic privacy center was not independently tested for acceptance, delivery, entity matching, or completion.
  - [https://oag.ca.gov/data-broker/registration/573332](https://oag.ca.gov/data-broker/registration/573332) — source date 2023-09-15: The California Department of Justice registration identifies Nexxen Inc and records a historical opt-out tool hosted at yourdata.tremorinternational.com. Limitation: The registry uses legacy Tremor branding and a different route from the current Nexxen Privacy Center; preserve this as entity and route history, not current workflow proof.

### Semcasting, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current PrivacyChoice form and reconcile the policy date discrepancy, then preserve identity-resolution, advertising, analytics, category choice, U.S.-only, and provider-stated timing boundaries before promotion.
- **Official evidence:**
  - [https://www.semcasting.com/privacy_policy_v1](https://www.semcasting.com/privacy_policy_v1) — source date 2026-04-01: The provider policy identifies Semcasting, Inc. and covers Semcasting, IDToolbox, Audience Designer, and PrivacyChoice services. It provides access, correction, deletion, sale opt-out, communications opt-out, privacychoice.com, phone, and email routes and states a 15-business-day outer target for sale opt-outs. Limitation: The page displays both a 2026 last-updated label and a July 16, 2025 effective-date statement; retain both dates rather than collapsing them.
  - [https://www.semcasting.com/privacy_choice](https://www.semcasting.com/privacy_choice): The current Privacy Choice page offers profile visibility, category-level opt-in or opt-out, global Do Not Sell, phone and email routes, and provider-stated permanent recording within Semcasting data. Limitation: The provider-stated 10-to-30-day timeline and permanent-recording language are not independent proof of request acceptance or completion.

### Blis Global Ltd
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current privacy-center route and preserve Blis Global versus local trading-company scope, advertising versus website context, device identifiers, consent, authorized-agent, and non-personalized-ad boundaries before promotion.
- **Official evidence:**
  - [https://blis.com/blis-privacy-policy-for-online-advertising-and-related-uses/](https://blis.com/blis-privacy-policy-for-online-advertising-and-related-uses/): The provider policy identifies Blis Global Ltd as the parent controller and describes online advertising, cookies, mobile advertising IDs, IP address, browsing behavior, audience segments, location, and cross-device use. It describes access, deletion, correction, sale or sharing opt-out, identity verification, authorized agents, and the distinction between interest-based advertising opt-out and continued non-personalized ads.
  - [https://blis.com/ccpa-opt-out/](https://blis.com/ccpa-opt-out/): The current California rights page provides Blis’s privacy email and toll-free coded route, identity-verification requirements, authorized-agent handling, and 2025 request metrics. Limitation: The provider-stated metrics and route availability are not independent proof of acceptance, delivery, or completion for a specific request.
  - [https://oag.ca.gov/data-broker/registration/551185](https://oag.ca.gov/data-broker/registration/551185) — source date 2022-02-25: The California Department of Justice registration identifies Blis Global Ltd, records its privacy email, and names the historical CCPA route and privacy centre. Limitation: The registration is historical; preserve it as registry context and prefer the current provider rights page for route semantics.

### Realeflow, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve the current Do Not Sell form and policy version, then preserve marketing-channel, service-account, sale, access, deletion, transactional-message, and 30-business-day scope before promotion.
- **Official evidence:**
  - [https://cdn.realeflow.com/privacy-policy.pdf](https://cdn.realeflow.com/privacy-policy.pdf) — source date 2024-07-01: The provider’s July 2024 policy describes Realeflow, LLC processing across its website, real-estate-investing software, services, and other individuals whose information comes under its control. It documents marketing-call, text, email, direct-mail, sale opt-out, access, and deletion choices, including a provider form, phone, email, and a stated 30-business-day marketing-unsubscribe target. Limitation: The policy’s web links are dynamic or unresolved in the bounded review; do not infer that a marketing unsubscribe automatically removes service or sale data.
  - [https://realeflow.com/privacy-policy/](https://realeflow.com/privacy-policy/) — source date 2022-08-02: The provider privacy page is a first-party policy route and separates promotional communications from service, administrative, and transactional messages. Limitation: The page displays an older August 2022 version while a July 2024 provider PDF is also available; retain both versions and verify which is current before promotion.
  - [https://realeflow.com/log-in/](https://realeflow.com/log-in/): The current provider site footer exposes a Do Not Sell My Personal Information link. Limitation: The footer confirms a provider-linked route candidate but not the destination’s current semantics or request completion.

### Wiza, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile the catalog wiza.com label with Wiza, Inc. and the live wiza.co routes, then preserve contact-data, directory, account, client, GPC, identity, and request-confirmation scope before promotion.
- **Official evidence:**
  - [https://wiza.co/privacy](https://wiza.co/privacy) — source date 2025-02-28: The policy identifies Wiza, Inc. as a B2B data provider and describes professional contact-information enrichment, account, website, and service processing. It documents access, correction, deletion, sale, targeted-advertising, profiling, GPC, authorized-agent, identity-verification, and appeal contexts.
  - [https://wiza.co/optout-contact-info](https://wiza.co/optout-contact-info): The provider opt-out form asks for first name, last name, multiple email addresses, and phone numbers, requires email confirmation, and states that it prevents contact information from being transmitted to Wiza end users. Limitation: The provider’s live request domain is wiza.co while the catalog domain is wiza.com; the form does not by itself establish removal from every Wiza product or public directory.
  - [https://help.wiza.co/en/articles/12063172-how-to-remove-your-contact-info](https://help.wiza.co/en/articles/12063172-how-to-remove-your-contact-info) — source date 2026-01-29: The provider help article distinguishes contact-data opt-out from a separate Wiza Directory opt-out and states that the contact form does not remove a public directory profile. Limitation: The help article is operational guidance, not proof that a submitted request was accepted or completed.

### LionShare Marketing, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current privacy policy and database scope, then preserve website versus offline, address matching, marketing, healthcare-data, CCPA, and request-outcome boundaries before promotion.
- **Official evidence:**
  - [https://www.lionsharemarketing.com/privacy-policy/](https://www.lionsharemarketing.com/privacy-policy/) — source date 2024-09-17: The provider policy describes LionShare website collection, healthcare data analytics and marketing-automation context, cookies, promotional communications, and a separate opt-out page for database removal. It states that the online policy applies to website data and not offline collection and publishes 2025 CCPA request metrics. Limitation: The website-versus-offline limitation means the policy cannot alone establish the scope of the marketing database or every customer data service.
  - [https://www.lionsharemarketing.com/opt-out/](https://www.lionsharemarketing.com/opt-out/): The current provider opt-out form requires first name, last name, street address, city, state, ZIP, and optionally email, indicating an address-based matching workflow. Limitation: The bounded review confirms the provider-stated form fields but does not certify acceptance, delivery, matching, deletion, suppression, or completion.

### DealerX Partners LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current privacy-options form and preserve Website versus Platform, browser/device, California cessation, automotive-client, authorized-agent, and no-sale/licensing scope before promotion.
- **Official evidence:**
  - [https://dealerx.com/privacy-options/](https://dealerx.com/privacy-options/) — source date 2025-03-20: The provider page identifies DealerX Partners, LLC, separates Website and Platform processing, states that DealerX does not sell or license consumer data to third parties, and offers complete opt-out, data-inquiry, correction, and authorized-agent choices. It documents browser-and-device cookie scope and identity verification for requests.
  - [https://dealerx.com/contact-us/](https://dealerx.com/contact-us/): The provider contact page identifies DealerX Partners and states that, as of September 2024, it no longer tracks or collects data from California residents. Limitation: General contact details are not a privacy-request route; the privacy-options page remains the designated candidate.
  - [https://dealerx.com/wp-content/uploads/sites/64/2022/06/DealerX-Pixel-Data-Collection-Agreement.pdf](https://dealerx.com/wp-content/uploads/sites/64/2022/06/DealerX-Pixel-Data-Collection-Agreement.pdf): The provider agreement describes DealerX platform collection involving business-provided PII, addresses, cookies, email addresses, IP addresses, and mobile identifiers for automotive marketing, targeting, analytics, and optimization. Limitation: This is a business agreement and supporting service context, not consumer-request or completion evidence.

### Five Star Rated
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Map Five Star Rated LLC to Ignite Visibility and its listed affiliates, then preserve state scope, marketing, targeted-advertising, deletion, identity, and affiliate-processing boundaries before promotion.
- **Official evidence:**
  - [https://www.fivestarrated.com/privacy-policy](https://www.fivestarrated.com/privacy-policy) — source date 2026-04-01: The current policy identifies Five Star Rated LLC within the Ignite Visibility affiliate group and covers websites, social media, communications, and offline interactions. It describes targeted advertising and marketing communications and identifies the state-rights context for the provider’s consumer choices.
  - [https://www.fivestarrated.com/do-not-sell](https://www.fivestarrated.com/do-not-sell): The provider form offers Do Not Sell and Delete choices for California, Colorado, Connecticut, Utah, and Virginia residents and requires contact details for verification. Limitation: The form’s jurisdiction restriction and dynamic behavior were not independently tested for acceptance, delivery, or completion.

### Lookify.io
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Keep Lookify listing removal, account deletion, third-party public sources, Texas data-broker rights, California rights, and identity verification as separate workflow facts before promotion.
- **Official evidence:**
  - [https://lookify.io/privacy-policy](https://lookify.io/privacy-policy): The policy describes Lookify’s public-information phone lookup and aggregates consumer indexes, directories, property records, social networks, and business directories. It clearly states that the opt-out removes public listings on Lookify.io only and cannot remove information from third-party public sources, and it provides separate privacy-rights and Texas data-broker contexts.
  - [https://lookify.io/opt-out](https://lookify.io/opt-out): The provider’s opt-out destination is the stated route for removing public listings from Lookify.io. Limitation: The bounded review confirms the provider-stated route but does not certify request acceptance, matching, delivery, or completion.
  - [https://lookify.io/ccpa-privacy-statement](https://lookify.io/ccpa-privacy-statement): The California statement provides access, deletion, correction, portability, and opt-out rights and identifies the same opt-out page and verification context. Limitation: Public-listing removal, account deletion, and rights requests are separate actions and must not be merged.

### General Motors LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Preserve GM U.S., OnStar, vehicle, dealer, GM Financial, insurance, third-party-service, GPC, authorized-agent, and request-channel boundaries before treating this corporate profile as customer-ready.
- **Official evidence:**
  - [https://www.gm.com/privacy-statement](https://www.gm.com/privacy-statement) — source date 2026-06-17: The current U.S. Consumer Privacy Statement identifies General Motors Holdings LLC and U.S. affiliates and covers online and offline products, services, websites, apps, connected-vehicle features, vehicle data, marketing, and privacy rights. It provides access, correction, deletion, sale, targeted-advertising, automated-processing, GPC, authorized-agent, appeal, and 45-day processing contexts.
  - [https://www.gm.com/consumer-privacy](https://www.gm.com/consumer-privacy): The provider’s U.S. Consumer Privacy Request Form is the designated request route, with 1-866-MYPRIVACY as the phone alternative and no email request acceptance. Limitation: The form’s live acceptance and completion behavior were not independently tested.
  - [https://www.gm.com/privacy-center](https://www.gm.com/privacy-center): The provider privacy center separates consumer choices and opt-out rights from other GM privacy resources. Limitation: The GM statement excludes GM Financial, General Motors Insurance, dealers, and third-party services; those entities require separate evidence.

### Cision
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Cision US, Cision Ltd, Brandwatch, PR Newswire, journalist, influencer, customer, and prospect contexts, then verify the current request route and preserve profile-removal versus marketing-subscription boundaries before promotion.
- **Official evidence:**
  - [https://www.cision.com/contact-us/opt-out/](https://www.cision.com/contact-us/opt-out/): The current Cision ID Opt-Out page provides a do-not-sell-or-share route through privacy@cision.com and a toll-free privacy number, and links to the journalist and influencer profile context. Limitation: The live submission and completion behavior were not independently tested.
  - [https://www.cision.com/legal/privacy-policy/](https://www.cision.com/legal/privacy-policy/) — source date 2024-04-11: The Cision US, Inc. policy covers information collected online and offline and describes media-intelligence, journalist, influencer, and communications use cases. It documents access, correction, erasure, objection, direct-marketing, and California sale-or-sharing rights and identifies Cision US, Inc. as the policy entity.
  - [https://privacy.cision.com/dataprivacynotice_influencers](https://privacy.cision.com/dataprivacynotice_influencers): The influencer notice states that individuals in Cision media or social-influencer databases may request profile amendment or removal from those databases by emailing privacy@cision.com. Limitation: The influencer database route is distinct from Cision customer, prospect, Brandwatch, and PR Newswire contexts.

### Socialgist; Boardreader
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Use privacy@socialgist.com for the current consumer route only after matching the relevant social handle or username, and preserve Socialgist, Boardreader, content-partner, source-platform, identity-verification, and 45-day-response boundaries before promotion.
- **Official evidence:**
  - [https://www.socialgist.ai/privacy-and-terms](https://www.socialgist.ai/privacy-and-terms): The policy identifies Effyis, Inc. d/b/a Socialgist and applies to consumers whose personal information appears in online social conversations that Socialgist monitors or receives from content partners, including forums, blogs, news, reviews, and social platforms. It expressly identifies the website operator as a data broker under Texas law and provides access, correction, deletion, sale opt-out, appeal, and authorized-agent contexts.
  - [https://www.socialgist.ai](https://www.socialgist.ai): The first-party domain is retained as the current provider context for Socialgist and the Boardreader registered-name alias. Limitation: A home page or brand alias does not by itself establish a separate Boardreader request route.

### The Org
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Preserve The Org and Orgio, Inc. identity, professional-only data scope, individual position-page matching, company requests, work-email verification, suppression-retention, crowdsourced re-addition, and email-versus-web-route boundaries before promotion.
- **Official evidence:**
  - [https://theorg.com/do-not-sell](https://theorg.com/do-not-sell) — source date 2024-11-17: The Org states that it processes professional data such as employer, job title, and professional contact information and offers an opt-out flow to prevent a person from appearing on The Org. It says the work email is used as the unique key for positions and retained to prevent re-addition, and provides privacy@theorg.com as an alternate route. Limitation: The provider states that personal or anonymous email addresses may not work for the individual opt-out flow.
  - [https://support.theorg.com/en/articles/6797342-delete-your-data-on-the-org](https://support.theorg.com/en/articles/6797342-delete-your-data-on-the-org) — source date 2025-06-09: The provider support article distinguishes individual profile removal from company-level requests, requires a work-email match for the individual route, and asks requesters to include the relevant profile link when using email. Limitation: Provider support guidance does not independently prove acceptance, deletion, suppression, or future non-republication.
  - [https://theorg.com/privacy](https://theorg.com/privacy) — source date 2024-11-13: The Org privacy policy identifies Orgio, Inc. and states that public org-chart data may come from public web pages, news, company team pages, and contributors; it provides access, correction, deletion, and restriction contexts. Limitation: The Org states it does not provide or collect consumer data in its do-not-sell notice; retain the professional-directory scope and do not generalize it to consumer data.

### MH Sub I, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Map the specific Internet Brands site or service holding the record before sending a request, then preserve MH Sub I, affiliate, acquired-company, health, legal, finance, marketing, public-content, site-policy, and third-party-broker boundaries before promotion.
- **Official evidence:**
  - [https://www.internetbrands.com/privacy](https://www.internetbrands.com/privacy): The current policy identifies MH Sub I, LLC dba Internet Brands and affiliates, covers sites, services, applications, and software, and describes contact, profile, transaction, location, device, health, employment, and user-submitted information contexts. It provides access, update, deletion, marketing opt-out, identity-verification, retention, and third-party sharing contexts, including situations where an online request may be shared with a broker, aggregator, lender, dealer, or financial institution. Limitation: The policy applies only to sites and services that display or link to it; acquired companies and services may retain separate policies until integrated.
  - [https://www.internetbrands.com/privacy/privacy-contact-form](https://www.internetbrands.com/privacy/privacy-contact-form): The provider privacy-contact route is the current candidate for privacy-rights requests and is linked from the Internet Brands policy context. Limitation: The live form acceptance, entity selection, field requirements, and completion behavior were not independently tested.
  - [https://www.internetbrands.com](https://www.internetbrands.com): The corporate site identifies MH Sub I, LLC dba Internet Brands, its verticals, affiliates, corporate contact details, and the privacy-policy relationship. Limitation: Corporate ownership and a broad affiliate portfolio do not prove that one request removes information from every Internet Brands site, affiliate, acquired business, or third-party service.

### PossibleNOW, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve the current privacy-rights destination and preserve PossibleNOW, PossibleNOW Services, DNC Solution, MyPreferences, licensed third-party data, customer or vendor contract data, website data, sale opt-out, targeted advertising, and marketing-unsubscribe boundaries before promotion.
- **Official evidence:**
  - [https://www.possiblenow.com/privacy-statement](https://www.possiblenow.com/privacy-statement) — source date 2026-03-11: The current PossibleNOW policy identifies PossibleNOW, Inc. and PossibleNOW Services, Inc. and applies to the listed PossibleNOW sites. In its data-broker context, PossibleNOW says it makes certain third-party-licensed data available to customers, including digital marketers, advertising partners, and ad-tech companies, for online and offline marketing. Limitation: The policy excludes data provided by customers under service agreements and vendors under data-sourcing agreements; those contractual data contexts require separate scope analysis.
  - [https://www.possiblenow.com/privacy-statement-california](https://www.possiblenow.com/privacy-statement-california) — source date 2025-01-29: The California supplement describes access, deletion, sale opt-out, authorized-agent, and targeted-advertising choices and points to an online privacy-rights or do-not-sell route and postal mail. Limitation: The page’s live form destination and current field requirements were not independently tested.
  - [https://www.possiblenow.com](https://www.possiblenow.com): The current provider site exposes Manage My Privacy Rights and Do Not Sell links and identifies PossibleNOW as a consent, preference, and data-analytics company. Limitation: Marketing unsubscribe and cookie preferences must not be treated as deletion or suppression from licensed customer data.

### FordDirect
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile FordDirect, DealerDirect LLC, Ford Motor Company, dealer, dealer-association, and supplier roles, then verify the current webform and preserve GPC, state, B2B, dealer, separate-right, identity, and 45-day boundaries before promotion.
- **Official evidence:**
  - [https://www.forddirect.com/privacy](https://www.forddirect.com/privacy) — source date 2026-06-25: The current FordDirect privacy statement identifies website, application, social-media, software, and service processing and lists categories sold or shared under California terminology, including identifiers, commercial information, online activity, geolocation, and inferences. It provides Your Privacy Choices, webform, phone, Global Privacy Control, identity-verification, authorized-agent, and 45-calendar-day response contexts. Limitation: The statement says dealer or dealer-association processing may be independent or controller-specific and may require a request to the relevant dealer.
  - [https://www.forddirect.com/privacy](https://www.forddirect.com/privacy): FordDirect says separate requests should be submitted for separate CCPA rights, receipt may be confirmed within 10 days, and requests involving dealer service-provider processing should identify the dealer. Limitation: A FordDirect request does not establish deletion from Ford Motor Company, a dealer, a dealer association, or an independent supplier.
  - [https://oag.ca.gov/data-broker/registration/186810](https://oag.ca.gov/data-broker/registration/186810) — source date 2020-02-07: The California Department of Justice registration identifies DealerDirect LLC doing business as FordDirect and preserves the historical registry privacy email, website, and request context. Limitation: The registry record is historical; the current FordDirect privacy statement and current form are the preferred route evidence.

### Buyerlink Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Buyerlink Inc, Buyerlink.com, buyerlink.co, One Planet Group, lead-generation, publisher, marketplace, cookie, privacy-portal, and email-unsubscribe contexts before promotion; do not infer deletion from the unsubscribe route.
- **Official evidence:**
  - [https://www.buyerlink.co/do-not-sell-or-share-my-personal-information](https://www.buyerlink.co/do-not-sell-or-share-my-personal-information): The current Buyerlink domain exposes a Do Not Sell or Share My Personal Information route whose page embeds a OneTrust privacy portal. Limitation: The embedded portal’s field requirements, entity selection, verification, acceptance, and completion behavior were not independently tested.
  - [https://www.buyerlink.co/privacy](https://www.buyerlink.co/privacy): The current Buyerlink privacy route is linked from the provider’s legal footer and is retained as the policy context for the current buyerlink.co domain. Limitation: The privacy page is dynamically rendered in the bounded review and did not expose its substantive policy text; do not infer policy scope or rights beyond the named first-party route.
  - [https://unsubscribe.buyerlink.com/](https://unsubscribe.buyerlink.com/): Buyerlink exposes a separate email-unsubscribe route that accepts an email address. Limitation: Email unsubscribe is a marketing-communication control and is not proof of sale opt-out, deletion, or suppression from lead-generation systems.
  - [https://oag.ca.gov/data-brokers](https://oag.ca.gov/data-brokers): The current catalog retains a California registry context for Buyerlink Inc and the provider’s legal or route history. Limitation: The bounded review did not resolve a current direct registry record URL; preserve registry identity and route evidence separately until reconciled.

### Remodeling.com, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Map Remodeling.com LLC to Ignite Visibility and its affiliates, then preserve California-only form scope, homeowner versus contractor data, enterprise-client processing, partner lead sharing, marketing consent, deletion, and current privacy-email boundaries before promotion.
- **Official evidence:**
  - [https://remodeling.com/privacy-policy/](https://remodeling.com/privacy-policy/) — source date 2026-04-01: The current policy identifies Ignite Visibility and affiliates including Remodeling.com LLC, covers website, social, communications, and offline interactions, and describes identifiers, contact details, project information, device and online activity, marketing, and partner processing. It states that the policy does not govern information processed for enterprise customers as a service provider or processor.
  - [https://remodeling.com/do-not-sell/](https://remodeling.com/do-not-sell/): The current form allows California residents to request Do Not Sell and Delete choices, does not require an account, and asks for name, email, phone, address, California residence, and ZIP information; the provider may verify identity. Limitation: The form is explicitly limited to verifiable California consumer requests and its dynamic submission behavior was not independently tested.
  - [https://remodeling.com/terms-of-use/](https://remodeling.com/terms-of-use/): The provider terms identify Remodeling.com as a home-project lead and matching platform and state that homeowner submissions may result in email, telephone, mobile, SMS, mail, or fax contact by Remodeling.com and affiliates. Limitation: Contact consent, marketing unsubscribe, data-broker suppression, and deletion are separate workflow actions.

### SheerID
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile SheerID, Inc., Audience Development, Remember Me, verification-client, retailer, government-ID, and marketing-preference contexts, then preserve controller-versus-processor scope and current Privacy Center verification before promotion.
- **Official evidence:**
  - [https://www.sheerid.com/global-privacy-policy/](https://www.sheerid.com/global-privacy-policy/) — source date 2025-03-10: The Global Privacy Policy identifies SheerID, Inc. and affiliates and distinguishes SheerID-controlled Remember Me and Audience Services from verification processing performed for Clients, where the Client is the controller. It documents access, correction, deletion, portability, sale or sharing, targeted-advertising, authorized-agent, identity-verification, and 45-day-response contexts.
  - [https://www.sheerid.com/privacy-notice-for-audience-development-products-services/](https://www.sheerid.com/privacy-notice-for-audience-development-products-services/) — source date 2024-03-28: The Audience Development notice describes audience profiles and the sharing or sale of names, email addresses, birth dates, employer, educational institution, employment title, student status, medical-professional status, and military status to customer retailers. It provides a Privacy Center Do Not Sell route available regardless of residence and states that the entity maintaining the website is a data broker under Texas law. Limitation: This audience-data notice is distinct from client-controlled verification transactions and does not establish removal from a retailer or other SheerID client.
  - [https://www.sheerid.com/global-privacy-policy/](https://www.sheerid.com/global-privacy-policy/): The current policy gives privacy@sheerid.com, 1-833-317-3372, and Privacy Choices routes and says verification may use recent-interaction details such as account information, name, address, email, or phone. Limitation: The live Privacy Choices form was not independently tested for acceptance, delivery, or completion.

### Disqus
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Disqus account, comment, publisher-embedded, cookie, ad-partner, Zeta, data-broker, GPC, and privacy-form contexts, and replace stale aggregate metrics with the current 2025 statistics before promotion.
- **Official evidence:**
  - [https://help.disqus.com/en/articles/1717103-disqus-privacy-policy](https://help.disqus.com/en/articles/1717103-disqus-privacy-policy) — source date 2026-07-10: The current policy describes Disqus as a public comment platform and marketing or data company collecting through Disqus and service-enabled third-party websites, and describes sale or sharing, targeted advertising, cookies, device and browser identifiers, hashed email, IP, professional or educational data, and data-broker or advertising-partner disclosures. It provides access, correction, deletion, sale or sharing opt-out, sensitive-data limitation, email opt-out, GPC, authorized-agent, and identity-verification contexts. Limitation: The policy does not control the independent privacy practices of publisher websites where Disqus is embedded.
  - [https://help.disqus.com/en/articles/1717117-how-to-edit-your-data-sharing-settings](https://help.disqus.com/en/articles/1717117-how-to-edit-your-data-sharing-settings) — source date 2026-06-05: The provider help article distinguishes commenter account-level data-sharing settings from publisher-level tracking controls and states that commenters can disable data sharing through the Disqus settings route or supported browser signals. Limitation: A data-sharing preference is not equivalent to deletion of account, comment, publisher-site, ad-partner, or downstream data copies.
  - [https://help.disqus.com/en/articles/1717233-delete-account-or-access-account-data](https://help.disqus.com/en/articles/1717233-delete-account-or-access-account-data): The provider help article separates account deletion or export from profiles managed by publisher websites and points users to a Disqus data-rights form. Limitation: Publisher-managed profiles and third-party reposts require separate review.

### Narvar, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Map Narvar corporate, Consumer Services, Fraud Prevention Services, Merchant Services, merchant controller, and downstream retailer contexts, then verify the Privacy Rights Tool and preserve processor-versus-controller, profiling, GPC, marketing, and request-channel boundaries before promotion.
- **Official evidence:**
  - [https://corp.narvar.com/legal/privacy-policy](https://corp.narvar.com/legal/privacy-policy) — source date 2025-07-08: The current Narvar policy identifies Narvar, Inc. as a software platform provider and separates corporate, Consumer Services, and Fraud Prevention Services processing. It provides access, correction, deletion, portability, objection, sale or sharing, targeted-advertising, profiling, sensitive-data, authorized-agent, and identity-verification contexts.
  - [https://narvar.my.onetrust.com/webform/04b3731f-2a9a-42ce-bd6b-106d4b4ec3bf/a7c944bf-3cec-4f00-9dc5-dea5bf2b6f4f](https://narvar.my.onetrust.com/webform/04b3731f-2a9a-42ce-bd6b-106d4b4ec3bf/a7c944bf-3cec-4f00-9dc5-dea5bf2b6f4f): The policy links the current Narvar Privacy Rights Tool for privacy requests and states that requests involving Merchant Services processed solely on behalf of a merchant must be directed to the relevant merchant. Limitation: The live form field requirements, acceptance, delivery, and completion behavior were not independently tested.
  - [https://corp.narvar.com/legal/privacy-policy](https://corp.narvar.com/legal/privacy-policy): The policy states that Narvar does not honor browser DNT signals, provides a corporate marketing unsubscribe distinction, and exposes separate privacy settings for California sale or sharing choices. Limitation: A marketing unsubscribe or Narvar corporate request does not establish removal from the relevant merchant, carrier, retailer, fraud customer, or third-party systems.

### AutoWeb, Inc.
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile AutoWeb, Autodata, Chrome Data, dealer, OEM, advertising, partner, consumer-support, unsubscribe, sale opt-out, and protected-person deletion contexts before promotion; retain the current OneTrust route as review-only until its live behavior is verified.
- **Official evidence:**
  - [https://www.autoweb.com/privacy](https://www.autoweb.com/privacy): The current AutoWeb site identifies AutoWeb, Inc., exposes a Privacy Policy, Do Not Sell or Share, and Unsubscribe footer route, and identifies Autodata, Inc. dba Chrome Data as a source of some content. Limitation: The substantive privacy policy is dynamically rendered in the bounded review; do not infer current request semantics beyond the linked first-party routes.
  - [https://privacyportal.onetrust.com/webform/27aa5d67-8136-4a08-ae4b-9860992e2375/f84362ef-6901-4a8c-9a52-e7b06dbb4e6b](https://privacyportal.onetrust.com/webform/27aa5d67-8136-4a08-ae4b-9860992e2375/f84362ef-6901-4a8c-9a52-e7b06dbb4e6b): The current AutoWeb Privacy Request Form is the provider-linked route for Do Not Sell, deletion, and other privacy requests. Limitation: The live form’s field requirements, acceptance, verification, and completion behavior were not independently tested.
  - [https://oag.ca.gov/data-broker/registration/562147](https://oag.ca.gov/data-broker/registration/562147) — source date 2023-02-02: The California Department of Justice registration identifies AutoWeb, Inc., records the privacy form, ConsumerCare@autoweb.com, and 800-267-2015, and describes sale opt-out and protected-person deletion routes. Limitation: The registration is historical; prefer the current AutoWeb footer and Privacy Request Form for route semantics.
  - [https://www.autoweb.com/contact-us](https://www.autoweb.com/contact-us): The current provider contact page identifies Consumer Support and Dealer Sales and Services at 844-205-9097 and distinguishes general business contact from consumer support. Limitation: General contact and dealer support are not substitutes for the privacy request form unless the provider directs the requester there.

### DataX Ltd. Consumer Opt-Out
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Preserve DataX, Equifax, prescreen-list, permanent-versus-five-year, FCRA, credit-report, dispute, freeze, identity, postal, and sensitive-information boundaries before promotion; never describe this route as erasing a credit file or downstream copies.
- **Official evidence:**
  - [https://consumers.dataxltd.com/consumerOptOut](https://consumers.dataxltd.com/consumerOptOut): The current DataX consumer route identifies DataX as an Equifax company and explains five-year and permanent opt-out choices for prescreen lists. Limitation: This route concerns prescreen-list use and does not establish deletion from all Equifax systems, credit files, downstream users, or other databases.
  - [https://consumers.dataxltd.com/assets/pdf/datax_notice_of_election_to_opt_out.pdf](https://consumers.dataxltd.com/assets/pdf/datax_notice_of_election_to_opt_out.pdf): The official permanent opt-out notice lists the information and signature fields for a permanent prescreen opt-out and states that the request becomes effective within five days after receipt. Limitation: The provider-stated timing is an effectiveness estimate for the prescreen route, not a guarantee of universal suppression or removal.
  - [https://consumers.dataxltd.com/](https://consumers.dataxltd.com/): The provider describes DataX as a credit-information services provider and separates consumer-report, prescreen, dispute, and identity-related contexts. Limitation: Credit-reporting, FCRA, dispute, freeze, and prescreen rights must not be merged into a generic data-broker deletion workflow.

### Harmon Research Group, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the current Harmon Research policy, then preserve survey-participant consent, study invitations, calls, email lists, database removal, sale or sharing scope, identity matching, and copies held by research clients before promotion.
- **Official evidence:**
  - [https://www.harmonresearch.com/privacy-policy](https://www.harmonresearch.com/privacy-policy) — source date 2024-06-06: The first-party policy describes Harmon Research survey participation as voluntary and consent-based and provides a route to request removal from its database or calls and email lists. Limitation: The published policy is older than the current review date; confirm the live policy and exact request semantics before promotion.
  - [https://oag.ca.gov/data-broker/registration/187673](https://oag.ca.gov/data-broker/registration/187673) — source date 2020-02-07: The California registry identifies Harmon Research Group, LLC as a registered data broker and lists its consumer request contact context. Limitation: The registry is historical and supporting evidence only; it does not prove current form acceptance, deletion, or non-republication.

### Preferred Communications
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm the current consumer form and entity relationship, then preserve sale opt-out, access, deletion, protected-person, minimum-matching-data, verification, email, and registry-history boundaries before promotion.
- **Official evidence:**
  - [https://preferredcommunications.com/consumer-opt-out/](https://preferredcommunications.com/consumer-opt-out/): The first-party domain exposes a consumer opt-out route for the cataloged Preferred Communications entity. Limitation: The bounded review did not independently test the live form’s fields, verification, acceptance, delivery, or completion behavior.
  - [https://oag.ca.gov/data-broker/registration/563583](https://oag.ca.gov/data-broker/registration/563583) — source date 2023-02-24: The California Department of Justice registry identifies Preferred Communications and lists the same consumer opt-out route, privacy email, sale opt-out, CCPA request, and protected-person deletion context. Limitation: The registry is historical; retain current first-party route evidence and registry identity separately until reconciled.

### Results Only Consulting and Advertising (ROC Advertising)
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the current ROC policy and privacy mailbox, preserve one-time mailing, data-broker source, rental or sale, ten-day advertising, 45-day request, identity, authorized-agent, and email-typo boundaries before promotion.
- **Official evidence:**
  - [https://www.rocadvertising.com/privacy-policy/](https://www.rocadvertising.com/privacy-policy/) — source date 2019-12-27: The first-party policy describes direct-mail and marketing use cases and says ROC may receive consumer data from a data broker for one-time mailing lists. It directs a Data Removal Request to privacy@rocadvertising.com and describes access, correction, deletion, sale or rental opt-out, identity matching, and possible additional verification. Limitation: The policy is dated and contains an inconsistent privacy-email spelling in one section; use the consistently published address only after current route recheck.
  - [https://www.rocadvertising.com/](https://www.rocadvertising.com/): The current provider homepage identifies ROC Advertising as a direct-mail and marketing business. Limitation: A current homepage does not by itself update or supersede the dated privacy-policy terms.

### BLACK KNIGHT DATA & ANALYTICS, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Black Knight Data & Analytics, Black Knight Inc, ICE, ICE Mortgage Technology, lender, servicer, mortgage-broker, public-record-suppression, employment, affiliate, and client-controller boundaries before promotion.
- **Official evidence:**
  - [https://www.ice.com/privacy-security-center](https://www.ice.com/privacy-security-center) — source date 2025-01-01: The current ICE Privacy and Security Center states that Black Knight, Inc. is now part of Intercontinental Exchange and preserves the Black Knight privacy policy. It provides access, correction, deletion, sale or sharing, targeted-advertising, GPC, authorized-agent, identity-verification, and public-record-suppression contexts. Limitation: The successor page covers multiple ICE and Black Knight contexts; it does not prove that one request reaches every lender, servicer, mortgage broker, affiliate, or client-held record.
  - [https://ice-privacy.my.onetrust.com/webform/cca3ac39-00b6-45f4-819b-bec660878b46/124d1692-407b-4384-9036-bef3ece530e3](https://ice-privacy.my.onetrust.com/webform/cca3ac39-00b6-45f4-819b-bec660878b46/124d1692-407b-4384-9036-bef3ece530e3): The current ICE privacy web form is the provider-stated route for privacy-rights requests. Limitation: The live form’s entity selection, field requirements, acceptance, and completion behavior were not independently tested.
  - [https://www.blackknightinc.com/](https://www.blackknightinc.com/): The historical Black Knight domain is retained as the catalog entity context while the current privacy route is served through ICE. Limitation: A legacy domain and successor relationship do not establish a separate current Black Knight route or removal from client systems.

### IQ Data Systems, Inc. dba Backgrounds Online
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile IQ Data Systems, Backgrounds Online, consumer-report, FCRA, employment-screening, report-access, dispute, account, identity-verification, retention, and client-employer contexts before promotion; do not present it as a generic public-record deletion route.
- **Official evidence:**
  - [https://partners.backgroundsonline.com/privacypolicy.aspx](https://partners.backgroundsonline.com/privacypolicy.aspx) — source date 2024-01-18: The first-party Backgrounds Online policy identifies I.Q. Data Systems dba Backgrounds Online, describes consumer-reporting and privacy-rights contexts, and says deletion requests may be limited by retention exceptions. It states that the provider generally does not accept deletion requests except in some account-closure contexts and may require identity information for non-account requests. Limitation: The policy does not establish a universal people-search opt-out route; a consumer-report disclosure or FCRA dispute route may be the appropriate path.
  - [https://www.backgroundsonline.com/products-and-services](https://www.backgroundsonline.com/products-and-services): The current first-party product page describes background screening, identity, criminal, employment, education, and consumer-report services. Limitation: Product descriptions are scope evidence, not proof of a consumer request route or deletion outcome.
  - [https://www.backgroundsonline.com/privacy-policy](https://www.backgroundsonline.com/privacy-policy): The cataloged provider privacy-policy destination remains a first-party route candidate for Backgrounds Online privacy context. Limitation: The bounded review did not independently confirm a current stable page at this exact URL or a current form accepting a generic removal request.

### CoStar Realty Information, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the CoStar portal availability and preserve CoStar product, marketplace, Professional Directory, commercial-real-estate, affiliate, cookie, GPC, brand-selection, one-request-per-submission, and identity-matching boundaries before promotion.
- **Official evidence:**
  - [https://www.costar.com/about/privacy-notice](https://www.costar.com/about/privacy-notice) — source date 2026-04-01: The current CoStar Global Privacy Notice identifies CoStar Realty Information, Inc. and affiliates, covers commercial-real-estate products and services, and describes access, correction, deletion, portability, sale or sharing, targeted-advertising, and profiling rights in listed jurisdictions. Limitation: The notice covers multiple CoStar products, marketplaces, affiliates, and service contexts; it does not by itself prove that a request reaches every brand, customer, or public-record source.
  - [https://privacy.costar.com/](https://privacy.costar.com/): The current CoStar Data Privacy Portal identifies the request route, requires a separate request type per submission, asks the requester to select a CoStar brand or service, and lists name, email, address, state, ZIP, and phone fields. Limitation: The portal currently states that the form is temporarily unavailable; do not present it as an independently confirmed live submission route until rechecked.
  - [https://www.costar.com/about/cookie-policy](https://www.costar.com/about/cookie-policy): The provider cookie policy separates browser-based targeted-advertising controls from broader privacy-rights requests. Limitation: Cookie choices and marketing unsubscribe are not equivalent to deletion or suppression from CoStar product or directory records.

### PublicRecordCom, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Preserve PublicRecordCom identity, people-search-result opt-out, account deletion, public-record source, search-engine reindexing, FCRA disclaimer, identity matching, and downstream-copy boundaries before promotion.
- **Official evidence:**
  - [https://publicrecord.com/privacy-rights/](https://publicrecord.com/privacy-rights/): The current PublicRecord.com Data Privacy Rights page offers separate access, user-data deletion, and people-search-result opt-out choices. It states that the result opt-out applies whether or not the requester is a member and may take 5–7 days to take effect, with search-engine removal potentially taking longer. Limitation: The page distinguishes account/user-data deletion from people-search-result removal; neither proves deletion from public records, upstream sources, search engines, or third-party copies.
  - [https://publicrecord.com/contact](https://publicrecord.com/contact): The current contact page identifies PublicRecord.com LLC and states that it is not a consumer reporting agency under the FCRA. Limitation: The FCRA disclaimer is scope context and does not establish a privacy-request completion outcome.
  - [https://publicrecord.com](https://publicrecord.com): The current provider site presents people, phone, address, and public-record search services. Limitation: Search functionality and public-record aggregation do not by themselves prove the exact sources or persistence of an individual listing.

### Compact Information Systems (d/b/a Deep Sync)
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Compact Information Systems, Deep Sync, HomeData, listed legacy brands, consumer suppression, deletion, corporate/client data, partner licensing, prior addresses, and identity-verification boundaries before promotion.
- **Official evidence:**
  - [https://www.compactlists.com/privacy-policy/](https://www.compactlists.com/privacy-policy/): The first-party policy describes Deep Sync marketing-data services, licensed information, customer and partner sharing, consumer attributes, and access, deletion, and sale opt-out rights. It states that a deletion request may need to be distinguished from an opt-out because suppression records can be retained to prevent future sale. Limitation: The policy is older than the current review date; use the current privacy portal for route fields and recheck policy freshness before promotion.
  - [https://privacy.compactlists.com/](https://privacy.compactlists.com/): The current Compact Information Systems privacy route redirects to the Deep Sync privacy center and exposes a Do Not Sell form with requester role, name, email, additional emails, phone numbers, and current or prior addresses. Limitation: The form’s acceptance, identity-verification, and completion behavior were not independently tested.
  - [https://privacy.deepsync.com/request/opt-out](https://privacy.deepsync.com/request/opt-out): The current provider route is the Deep Sync opt-out destination for suppression and privacy choices, while the provider distinguishes corporate or client-data requests from consumer opt-out requests. Limitation: A consumer opt-out does not establish deletion from client databases, partner systems, or downstream copies.

### Quorum Analytics
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Preserve Quorum Analytics, public-affairs, policy-influencer, professional-profile, client-controller, public-information, retention, email-request, verification, and response-window boundaries before promotion.
- **Official evidence:**
  - [https://www.quorum.us/privacy-policy/](https://www.quorum.us/privacy-policy/) — source date 2026-06-22: The current Quorum privacy policy identifies Quorum Analytics Inc. and affiliates, covers websites, apps, and services, and provides access, correction, erasure, objection, restriction, and applicable sale or sharing request contexts. It directs U.S. privacy requests to privacy@quorum.us and says requests should identify the request type in the subject line. Limitation: Quorum’s policy distinguishes its own controller processing from client or service-provider contexts; one request may not reach client-controlled data.
  - [https://www.quorum.us/privacy-policy/](https://www.quorum.us/privacy-policy/) — source date 2026-06-22: The policy says it aims to acknowledge applicable U.S. requests within 10 days and substantively respond within 45 days, with a possible additional 45 days when reasonably needed; it requests name and email for verification. Limitation: These are published response aims, not a guarantee of deletion, suppression, or removal from backups, aggregate data, de-identified data, deletion records, or client copies.
  - [https://www.quorum.us/products/policy-influencer-advertising/](https://www.quorum.us/products/policy-influencer-advertising/): The provider’s current product context describes policy-influencer and public-affairs data services, which helps distinguish professional or public-individual profile scope from ordinary consumer people-search records. Limitation: Product marketing material is scope evidence, not proof that a particular profile is present or that an email request was accepted.

### FREEPEOPLESEARCH.COM, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile FreePeopleSearch, public-record report, people-search result, account data, sale opt-out, identity verification, search-engine indexing, third-party platform, FCRA disclaimer, and 5–7-day scope before promotion.
- **Official evidence:**
  - [https://freepeoplesearch.com/privacy-rights/](https://freepeoplesearch.com/privacy-rights/): The current FreePeopleSearch Data Privacy Rights page separates user-data deletion from people-search-result opt-out, states that opt-out removes the requester from its search results whether or not they are a member, and publishes a 5–7 day effectiveness estimate. Limitation: The stated timing is provider guidance for its own results; it does not establish removal from search engines, public records, upstream sources, or other people-search sites.
  - [https://freepeoplesearch.com/privacy-policy/](https://freepeoplesearch.com/privacy-policy/) — source date 2022-08-01: The provider policy identifies FreePeopleSearch.com, states that it sells information and reports obtained from public records, and describes access, correction, deletion, sale opt-out, identity verification, and third-party-platform boundaries. Limitation: The general policy is dated; use the current privacy-rights page for route semantics and recheck the policy before promotion.
  - [https://freepeoplesearch.com/frequently-asked-questions](https://freepeoplesearch.com/frequently-asked-questions): The current FAQ confirms that the provider’s opt-out is intended to remove records shown on its own site. Limitation: A provider-site result removal is not universal deletion or non-republication.

### USPeopleSearch.com, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve a current first-party USPeopleSearch privacy or result-removal route and confirm the legal operator before promotion; retain the redirect, people-search, public-record, advertising, email-unsubscribe, and FCRA-scope limitations.
- **Official evidence:**
  - [https://uspeoplesearch.com/privacy-rights/](https://uspeoplesearch.com/privacy-rights/): The cataloged privacy-rights URL currently redirects to the US People Search homepage, whose first-party content describes people-search, public-record, phone, address, and background-search services. Limitation: The redirect did not expose a current privacy-request form or stable opt-out workflow in the bounded review; do not treat the legacy route as confirmed.
  - [https://uspeoplesearch.com/privacy-policy](https://uspeoplesearch.com/privacy-policy): The current provider policy describes personal-information collection, cookies, advertising technology, and privacy choices, including third-party advertising controls. Limitation: The current policy route did not provide a confirmed people-search-result removal workflow in the bounded review.
  - [https://uspeoplesearch.com/terms-conditions/](https://uspeoplesearch.com/terms-conditions/): The current terms identify USPeopleSearch.com and distinguish electronic-communication unsubscribe controls from broader privacy rights. Limitation: Email or text unsubscribe is not equivalent to removal from people-search results or public-record data.

### Peoplewhiz, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve the current PeopleWhiz privacy or result-removal route and exact legal entity before promotion; preserve historical registry, people-search, profile-removal, identity, and route-availability uncertainty.
- **Official evidence:**
  - [https://www.peoplewhiz.com](https://www.peoplewhiz.com): The cataloged first-party PeopleWhiz domain is retained as the provider context for the registered entity. Limitation: The bounded review could not retrieve the current provider page or confirm a current privacy-rights form, fields, verification, or completion behavior.
  - [https://oag.ca.gov/data-brokers](https://oag.ca.gov/data-brokers): The California historical Data Broker Registry is the official source context for the cataloged Peoplewhiz registration, public contact, and consumer-request history. Limitation: The bounded review did not resolve a stable individual Peoplewhiz registration URL; historical registry content is not proof of a current route.

### Riv Data Corp. dba Carpe Data
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile RIV Data Corp, Carpe Data, Carpe, insurance carrier, claimant, insured, third-party-source, client-controller, public-web, score or inference, identity, sale, and retention boundaries before promotion.
- **Official evidence:**
  - [https://carpe.io/privacy-policy/](https://carpe.io/privacy-policy/) — source date 2025-04-14: The current policy identifies RIV Data Corp. d/b/a Carpe Data, describes a business-to-business insurance-data and analytics company, and states that it collects personal information from third-party data sources and clients for insurance underwriting and claims contexts. It describes access, correction, erasure, restriction, objection, portability, sale, California opt-out, and identity-verification rights. Limitation: Carpe’s client-provided claimant and insured data may be governed by client agreements or legal exceptions; a direct Carpe request may not reach client-controlled records.
  - [https://carpe.io/privacy-policy/#exercising-your-rights](https://carpe.io/privacy-policy/#exercising-your-rights) — source date 2025-04-14: The policy directs rights requests to RightToKnow@carpe.io and provides 877-342-2773 for California requests; it requires identity verification and says responses will be provided within the applicable legal period. Limitation: The policy does not promise deletion of all client, legal, retained, or third-party source copies.
  - [https://carpe.io/about/](https://carpe.io/about/): The current provider site describes Carpe as an insurance decision and intelligence platform, confirming the professional and insurance-data scope. Limitation: Corporate product context does not by itself establish that a particular individual profile is present.

### InCheck Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Preserve InCheck, consumer-reporting, FCRA, employer or landlord authorization, report access, dispute, correction, legal retention, identity verification, and support-route boundaries before promotion; do not present it as a generic marketing broker.
- **Official evidence:**
  - [https://www.inchecksolutions.com/privacy-policy/](https://www.inchecksolutions.com/privacy-policy/): The current InCheck privacy page identifies InCheck, Inc. as a consumer reporting agency governed by the FCRA and describes background-screening information, authorized screening purposes, employer or landlord recipients, and legal retention or disclosure boundaries. Limitation: The policy does not establish a generic people-search opt-out or universal deletion route; consumer-report access, correction, and dispute processes require separate treatment.
  - [https://www.inchecksolutions.com/contact/getting-started/](https://www.inchecksolutions.com/contact/getting-started/): The provider’s current contact and candidate-help context identifies InCheck as a background-screening service and exposes the public support route. Limitation: The general support route does not by itself confirm the consumer-request fields, identity verification, or FCRA dispute workflow.
  - [https://www.inchecksolutions.com/](https://www.inchecksolutions.com/): The current first-party site provides the company and screening-service context for InCheck. Limitation: A company homepage is not proof of a privacy-request submission or report correction outcome.

### AGR Marketing Solutions LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck the current AGR domain and privacy route over HTTPS, reconcile the historical sample-page registration, and preserve email, lead or marketing, identity, route-availability, and registry-history boundaries before promotion.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/189348](https://oag.ca.gov/data-broker/registration/189348) — source date 2020-05-04: The California Department of Justice historical registration identifies AGR Marketing Solutions LLC, its public email, website, and the registered consumer-request URL. Limitation: The registry-listed route uses HTTP and a generic sample-page path; the registration itself is historical and does not prove a current functioning request route.
  - [https://www.agrmarketingsolutions.com](https://www.agrmarketingsolutions.com): The cataloged first-party domain is retained as the provider context for AGR Marketing Solutions. Limitation: The bounded review could not safely retrieve the current provider page or confirm current privacy policy, fields, identity verification, or completion behavior.

### ReallyGreatRate, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Resolve the current RGR consumer-facing Do Not Sell route and reconcile ReallyGreatRate, RGR Marketing, mortgage, solar, home-improvement lead, consent, telephone, email, registry, and identity boundaries before promotion.
- **Official evidence:**
  - [https://www.rgrmarketing.com/](https://www.rgrmarketing.com/): The current RGR Marketing site identifies lead-generation services for mortgage, solar, and home-improvement businesses and provides a business contact route. Limitation: The public site’s lead-generation content does not by itself expose a current consumer privacy request form.
  - [https://oag.ca.gov/data-brokers](https://oag.ca.gov/data-brokers): The California historical registry identifies ReallyGreatRate, Inc. dba RGR Marketing and states that its consumer-facing sites include Do Not Sell My Info links. Limitation: The bounded review did not resolve a stable individual registration URL or independently confirm a current consumer-facing link, form fields, verification, or completion behavior.

### Knowledge Works, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Knowledge Works, PayNet, Equifax, commercial-credit, consumer-reporting, FCRA, GLBA, client, identity, government-ID, registry, and current-domain boundaries before promotion; never frame this as a generic people-search deletion route.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/186836](https://oag.ca.gov/data-broker/registration/186836) — source date 2020-02-27: The California Department of Justice historical registration identifies Knowledge Works, Inc. d/b/a PayNet, lists Equifax’s privacy route and public email, and records that PayNet does not post personal information online in the protected-person context. Limitation: The registration is historical and does not by itself establish current PayNet or Equifax workflow semantics.
  - [https://myprivacy.equifax.com/opt-in-opt-out/personal-info](https://myprivacy.equifax.com/opt-in-opt-out/personal-info): The official registry points to the Equifax privacy request route for the cataloged PayNet entity. Limitation: The live Equifax form’s current fields, entity selection, verification, acceptance, and completion behavior were not independently tested.
  - [https://www.equifax.com/privacy/privacy-statement/](https://www.equifax.com/privacy/privacy-statement/): The Equifax privacy statement distinguishes consumer-reporting activity, financial and employment information, third-party data providers, public records, and applicable FCRA or GLBA contexts. Limitation: Equifax’s broad corporate policy does not prove that a request removes PayNet commercial-credit records, consumer reports, client-held data, or legally retained information.
  - [https://paynet.com/](https://paynet.com/): The historical registry identifies PayNet as the registered website context, while current Equifax materials identify PayNet as an Equifax business. Limitation: The domain, entity, acquisition, and current privacy-route relationships require separate reconciliation before promotion.

### Trestle Solutions, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Trestle Solutions, Trestle IQ, identity verification, API, customer-controller, customer data, data-subject, sale opt-out, deletion, suppression, and policy-freshness boundaries before promotion.
- **Official evidence:**
  - [https://trestleiq.com/privacy-policy-2024/](https://trestleiq.com/privacy-policy-2024/) — source date 2024-10-07: The Trestle notice identifies Trestle Solutions, Inc. and covers Trestle APIs, identity-verification products, the website, business interactions, and individual end users. It provides access, correction, deletion, portability, sale or sharing opt-out, marketing, and identity-verification contexts. Limitation: The accessible notice is older than the current review date; confirm the current policy and route before promotion.
  - [https://trestleiq.com/do-not-sell-my-personal-information/](https://trestleiq.com/do-not-sell-my-personal-information/): The notice identifies this first-party page as the CCPA request route and provides data@trestleiq.com as an alternative, with name, phone, address, and email used for verification when needed. Limitation: The bounded review did not independently test the live form’s acceptance, delivery, or completion behavior.
  - [https://trestleiq.com/data-processing-agreement/](https://trestleiq.com/data-processing-agreement/): The provider DPA distinguishes customer personal information, customer responsibility for consumer requests, and Trestle assistance or deletion on customer direction. Limitation: Customer-controller data may require a request to the relevant customer rather than a direct Trestle request.

### AnalyticsIQ Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile AnalyticsIQ, Alliant Cooperative Data Solutions, affiliates, marketing database, Data Products, website data, OneTrust, phone, GPC, deletion, opt-out, and customer-copy boundaries before promotion.
- **Official evidence:**
  - [https://analytics-iq.com/privacy-policy/](https://analytics-iq.com/privacy-policy/) — source date 2026-05-13: The current AnalyticsIQ policy is posted for Alliant Cooperative Data Solutions and affiliates, including AnalyticsIQ, and distinguishes website information from personal information processed in its Data Products. It provides access, deletion, correction, sale or sharing, targeted-advertising, GPC, authorized-agent, and verification contexts. Limitation: The policy covers Alliant and AnalyticsIQ together; entity and route selection must remain explicit.
  - [https://analytics-iq.com/your-privacy/](https://analytics-iq.com/your-privacy/): The current consumer privacy page says consumers may access, opt out of the marketing database, or request deletion through the OneTrust portal or by calling 833-533-1388. Limitation: The live OneTrust form’s field requirements, identity matching, acceptance, and completion behavior were not independently tested.
  - [https://analytics-iq.com/](https://analytics-iq.com/): The current provider site describes people-based marketing data and directs consumers to its privacy page for marketing-database controls. Limitation: Marketing-data suppression is separate from website cookie choices, company-email unsubscribe, customer-held copies, and other Alliant services.

### Share Local Media, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck Share Local Media’s HTTPS privacy center and policy, then reconcile current entity, California form, protected-person, email, identity, sale opt-out, deletion, and registry-history boundaries before promotion.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/561483](https://oag.ca.gov/data-broker/registration/561483): The California historical registration identifies Share Local Media, Inc. and lists a California Residents Rights Request Form and privacy email context for opt-out, CCPA requests, and protected-person deletion. Limitation: The registry is historical and does not establish current form fields, identity verification, acceptance, delivery, or completion.
  - [https://privacy.sharelocalmedia.com/](https://privacy.sharelocalmedia.com/): The cataloged first-party privacy subdomain is retained as the provider’s current route candidate. Limitation: The bounded review could not safely retrieve the page; do not treat the route as confirmed until independently rechecked.
  - [https://sharelocalmedia.com/privacy-policy](https://sharelocalmedia.com/privacy-policy): The cataloged first-party policy URL is retained as the current policy candidate for the provider domain. Limitation: The bounded review could not safely retrieve the page or confirm current request semantics.

### Advertise4Sales LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Recheck 4LegalLeads over HTTPS, verify Advertise4Sales legal-name and brand mapping, and preserve lead-delivery, customer-copy, CCPA, removal-form, email, identity, and route-availability boundaries before promotion.
- **Official evidence:**
  - [https://4legalleads.com/removal](https://4legalleads.com/removal): The cataloged first-party 4LegalLeads removal URL is the provider-stated route candidate for CCPA opt-out or deletion requests. Limitation: The bounded review encountered a cache miss; live form fields, entity selection, acceptance, verification, and completion were not independently confirmed.
  - [https://4legalleads.com/lawyer-faq/](https://4legalleads.com/lawyer-faq/): The cataloged first-party lawyer FAQ is retained as context for the 4LegalLeads and Advertise4Sales relationship and legal-lead service scope. Limitation: The bounded review timed out; do not infer current privacy or lead-disclosure semantics from the unavailable page.
  - [https://4legalleads.com](https://4legalleads.com): The first-party domain is retained as the provider context for the cataloged Advertise4Sales entity. Limitation: A reachable domain alone does not establish a current privacy request route or removal from leads already delivered to customers.

### Catalina Marketing Corporation
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Catalina Marketing Corporation, Catalina, Infillion, shopper, purchase, audience, CPG, privacy-choice, OneTrust, sale, deletion, marketing, and affiliate boundaries before promotion.
- **Official evidence:**
  - [https://www.catalina.com/](https://www.catalina.com/): The current Catalina site describes shopper-data, audience, CPG marketing, media activation, and consumer-relationship services and identifies a current Your Privacy Choices link in the footer. Limitation: The public site’s corporate and marketing context does not itself prove the current privacy form’s fields or completion behavior.
  - [https://privacyportal.onetrust.com/webform/7665c53e-aae8-4a03-9dd3-66fb6bce8f55/1bb0c042-b42f-49cc-8779-0bdf8f2ac522](https://privacyportal.onetrust.com/webform/7665c53e-aae8-4a03-9dd3-66fb6bce8f55/1bb0c042-b42f-49cc-8779-0bdf8f2ac522): The provider-linked OneTrust Privacy Web Form is the current route candidate for Catalina privacy choices. Limitation: The live form exposed no bounded text fields in review; acceptance, verification, and completion behavior were not independently tested.
  - [https://www.catalina.com/legal](https://www.catalina.com/legal): The current legal page preserves Catalina’s policy and privacy-choice navigation and confirms the active provider domain. Limitation: Catalina’s current ownership or affiliate relationship, including the site’s Infillion acquisition reference, requires separate entity reconciliation before promotion.

### People Data Labs
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile People Data Labs, professional data, marketing, hiring, fraud, public sources, Privacy Center, API versus licensed-data delivery, subject-request propagation, customer copies, identity, and deletion boundaries before promotion.
- **Official evidence:**
  - [https://privacy.peopledatalabs.com/policies?name=privacy-policy](https://privacy.peopledatalabs.com/policies?name=privacy-policy) — source date 2025-07-01: The current People Data Labs policy identifies People Data Labs, Inc., describes professional, hiring, marketing, fraud, and business-to-business data services, and provides opt-out, access, correction, deletion, marketing, authorized-agent, and identity-verification contexts. It states that an opt-out prevents the provided information and associated data from being shared or made available through its products. Limitation: The policy permits certain operational, legal, aggregate, de-identified, customer, or otherwise legally allowed processing to continue.
  - [https://www.peopledatalabs.com/do-not-sell-or-share](https://www.peopledatalabs.com/do-not-sell-or-share): The current first-party Do Not Sell form asks for full name and email and states that submission stops future sale of personal information. Limitation: The live form’s identity matching, confirmation, acceptance, and downstream customer propagation were not independently tested.
  - [https://docs.peopledatalabs.com/docs/data-sources](https://docs.peopledatalabs.com/docs/data-sources): The provider explains its proprietary and public data sources, privacy-rights handling, and that API opt-outs or deletions are applied immediately while licensed-data customers receive changes in future builds. Limitation: Customer-held copies and delivery schedules are separate from the provider’s own suppression state.
  - [https://docs.peopledatalabs.com/docs/subject-request-api](https://docs.peopledatalabs.com/docs/subject-request-api): The Subject Request API documentation explains how customer systems receive opted-out IDs, making downstream customer propagation a distinct operational context. Limitation: API documentation does not prove that every customer has applied a request or that all downstream copies were deleted.

### Media.net Advertising FZ-LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Media.net Advertising FZ-LLC, advertising technology, browser/device identifiers, privacy-rights request, sale-or-sharing, GPC, cookie opt-out, partner processing, email, identity, and deletion boundaries before promotion.
- **Official evidence:**
  - [https://www.media.net/privacy-policy/](https://www.media.net/privacy-policy/) — source date 2026-06-22: The current policy identifies Media.Net Advertising FZ-LLC and describes advertising technology, online identifiers, device identifiers, general location, third-party data, and consumer privacy rights. It links to a privacy-rights request route, a sale-or-sharing opt-out, GPC handling, and privacy@media.net. Limitation: The policy says much of the stored information may identify a browser or device rather than a directly named individual, and a request may be treated as a sale opt-out when identity cannot be verified.
  - [https://www.media.net/preferences/](https://www.media.net/preferences/): The first-party preferences page presents privacy-rights requests and sale-or-sharing or targeted-advertising preference controls by jurisdiction. Limitation: The bounded review did not independently test form acceptance, verification, or completion.
  - [https://www.media.net/optout/](https://www.media.net/optout/): The first-party opt-out page describes a browser-cookie choice for interest-based advertising and explains that the choice is browser-specific and does not stop data collection. Limitation: This is an advertising-cookie preference, not proof of deletion from all Media.net records or partner-held copies.

### Coast Technology, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Confirm Coast Technology I, LLC versus Dealership Toolkit and dashboard identity, locate the current public request route, and preserve advertising-cookie, sale, deletion, email, identity, and client-held-data boundaries before promotion.
- **Official evidence:**
  - [https://coasttechnology.com/privacy-policy/](https://coasttechnology.com/privacy-policy/) — source date 2024-10-01: The first-party policy identifies Coast Technology I, LLC and describes data products, website design, marketing-data services, third-party data providers, public sources, and consumer data categories. It describes NAI and DAA interest-based advertising choices, GPC, state privacy rights, and info@dealershiptoolkit.com. Limitation: The policy is dated October 2024 and the provider-stated privacy route was not independently confirmed in the bounded review.
  - [https://coasttechnology.com/policies/california-policy/](https://coasttechnology.com/policies/california-policy/): The first-party California policy describes access, deletion, correction, sale opt-out, and a stated target of responding to opt-out-of-sale requests within 15 business days. Limitation: The page does not by itself confirm current form fields, identity checks, acceptance, or completion.
  - [https://dashboard.coasttechnology.com/](https://dashboard.coasttechnology.com/): The first-party dashboard domain provides context for the cataloged Dealership Toolkit relationship. Limitation: A login dashboard is not a public consumer privacy request route.

### Exact Match Marketing Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Exact Match Marketing Inc, platform, third-party data, client-uploaded data, data-broker registrations, Do Not Sell, email, identity, request timing, profiling, and client-versus-controller boundaries before promotion.
- **Official evidence:**
  - [https://exactmatchmarketing.com/privacy-policy](https://exactmatchmarketing.com/privacy-policy) — source date 2026-02-04: The current policy identifies Exact Match Marketing Inc and describes a data-driven marketing platform, third-party data providers, data brokers, audience cohorts, targeted advertising, profiling, and state privacy rights. It provides a Do Not Sell or Share link and an email route for opt-out, deletion, access, correction, and profiling requests, with a stated 45-day response period for applicable requests. The policy states that Exact Match is registered as a data broker in California, Vermont, Texas, and Oregon. Limitation: The policy distinguishes client-uploaded data processed for clients from Exact Match-controlled data; requests about client-uploaded records may need to go to the client.
  - [https://exactmatchmarketing.com/terms-of-use](https://exactmatchmarketing.com/terms-of-use): The first-party terms connect the software platform to marketing, advertising, data, analytics, data-cleansing, and lead-generation functions and reference the privacy policy. Limitation: Terms do not prove that a public privacy form accepts or completes a consumer request.

### InMarket Media, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile InMarket Media, LLC, applications, SDKs, advertising, measurement, location, purchase data, device/browser controls, consumer forms, business contacts, and partner-copy boundaries before promotion.
- **Official evidence:**
  - [https://inmarket.com/privacy/](https://inmarket.com/privacy/) — source date 2026-02-12: The current policy identifies InMarket Media, LLC and describes mobile applications, SDKs, advertising, measurement, audience segments, purchase or receipt data, hashed identifiers, and precise geolocation contexts. It provides opt-out, access, deletion, correction, sensitive-information, GPC, phone, and first-party form routes and states that browser/device advertising choices are scoped to the device or browser. The policy publishes 2024 California request statistics, including 17,450 opt-outs and 55,981 deletions, with no denials reported and a seven-day median for each. Limitation: Advertising opt-out does not stop advertising, and device or browser choices do not by themselves prove deletion from all InMarket or partner-held records.
  - [https://inmarket.com/adchoices/](https://inmarket.com/adchoices/): The first-party AdChoices page is an advertising-choice route and links back to the current privacy policy. Limitation: AdChoices is not equivalent to a general deletion request.
  - [https://inmarket.com/business-contacts-opt-out/](https://inmarket.com/business-contacts-opt-out/): The first-party site separately exposes business-contact opt-out context. Limitation: Business-contact handling is a distinct route and should not be conflated with consumer advertising, location, or deletion requests.

### COMPACT INFORMATION SYSTEMS
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile COMPACT INFORMATION SYSTEMS, cisdirect.com, Deep Sync, Compact Information Systems, the separate compactlists.com profile, suppression, compiler data, corporate/client data, public form, mail route, phone, identity, and deletion boundaries before promotion.
- **Official evidence:**
  - [https://privacy.deepsync.com/](https://privacy.deepsync.com/): The current first-party Deep Sync privacy-choice page identifies a public Do Not Sell route, supports opt-out and deletion selections, accepts multiple emails, phones, and addresses, describes identity verification, and provides privacy.compliance@deepsync.com and a phone channel. The page states that deletion may take up to 45 days and creates a suppression record intended to prevent re-addition to active business files. Limitation: The page also says suppression does not remove data from compilers or other sources and that corporate or client data may require a separate email request.
  - [https://privacy.deepsync.com/request/data](https://privacy.deepsync.com/request/data): The first-party request route presents access, source, category, third-party, correction, and related privacy-request options and repeats the phone and mail alternatives. Limitation: The bounded review did not submit a request or independently test identity questions, acceptance, delivery, or completion.
  - [https://privacy.deepsync.com/forms/DeepSync-Opt-Out-Request-by-Mail-Form.pdf](https://privacy.deepsync.com/forms/DeepSync-Opt-Out-Request-by-Mail-Form.pdf) — source date 2023-08-15: The provider-hosted mail form names Compact Information Systems and describes the Deep Sync consumer opt-out process and mailing address. Limitation: The catalog profile uses cisdirect.com while the current route uses Deep Sync branding; the legal-entity, domain, and duplicate-profile relationship must be explicitly reconciled.

### DATAX LTD
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile DATAX LTD, dataxltd.com, the separate consumers.dataxltd.com profile, DataX and Equifax ownership, prescreen versus general privacy requests, phone, mail, identity, FCRA, and deletion boundaries before promotion.
- **Official evidence:**
  - [https://www.dataxltd.com/privacy-policy/](https://www.dataxltd.com/privacy-policy/) — source date 2019-12-01: The first-party DataX Online Privacy Policy identifies DataX, Ltd. and directs readers to the Equifax Privacy Statement for additional privacy information. Limitation: The policy is materially older than the current evidence snapshot and does not by itself establish current request fields, route behavior, or ownership scope.
  - [https://consumers.dataxltd.com/consumerOptOut](https://consumers.dataxltd.com/consumerOptOut): The first-party DataX consumer page identifies DataX as an Equifax company and provides a five-year phone opt-out and a permanent mail-based opt-out for prescreen lists, with stated five-day effectiveness after receipt of the permanent notice. Limitation: This route is for prescreen-list opt-out under the described credit-reporting context; it is not proof of deletion from all DataX or Equifax systems.
  - [https://www.equifax.com/privacy/privacy-statement/](https://www.equifax.com/privacy/privacy-statement/): The cataloged Equifax privacy statement is retained as the provider-linked corporate privacy context. Limitation: The DataX consumer route and the general Equifax statement may cover different products, legal bases, and records.

### FourthWall Media, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile FourthWall Media, Inc., television and device-viewership data, consumer versus customer processing, Do Not Sell form fields, privacy email, identity, deletion, downstream customer reports, and response evidence before promotion.
- **Official evidence:**
  - [https://www.fourthwall.tv/privacy-fourthwall](https://www.fourthwall.tv/privacy-fourthwall): The current privacy notice identifies FourthWall Media, Inc. and describes television, broadcast, cable, satellite, device-viewership, aggregation, reporting, and advertising-measurement services. It provides privacypolicy@fourthwall.tv and identifies consumers whose data is processed for customers as a covered audience. Limitation: The notice states that it does not respond to Do Not Track signals; it does not by itself establish deletion from customer-held reports or downstream advertising systems.
  - [https://www.fourthwall.tv/donotsellorshare-fourthwall](https://www.fourthwall.tv/donotsellorshare-fourthwall): The first-party Do Not Sell or Share form exposes fields for name, email, phone, street address, locality, region, postal code, and country, and presents a submit request action. Limitation: The bounded review did not submit the form or independently confirm identity verification, email confirmation, response timing, deletion behavior, or propagation to customers.
  - [https://www.fourthwall.tv/](https://www.fourthwall.tv/): The first-party site describes FourthWall as an addressable advertising and media-data provider, supporting the cataloged entity context. Limitation: Marketing context alone is not proof of a privacy request route or completed removal.

### Subgraph, Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Subgraph Inc, candidate and account data, customer-provided records, recruiting sources, Google Workspace data, privacy-rights versus privacy-choices routes, email, identity, profiling, deletion, and downstream customer copies before promotion.
- **Official evidence:**
  - [https://subgraph.tech/privacy-policy](https://subgraph.tech/privacy-policy) — source date 2026-06-29: The current policy identifies Subgraph Inc and describes recruiting, candidate information, professional data providers, advertising and social-media sharing, and Google Workspace integrations. It provides privacy-rights, opt-out, deletion, access, correction, profiling, and marketing-choice context through the first-party privacy-rights page and team@subgraph.tech. The policy states that a future sale or sharing opt-out should be acted on as soon as feasible and no later than 15 days, while certain state requests have different response periods. Limitation: The policy distinguishes account data, candidate information, customer-provided data, and third-party professional data; a request may not cover every data context.
  - [https://subgraph.tech/privacy-rights](https://subgraph.tech/privacy-rights): The first-party privacy-rights route is the provider-stated path for consumer requests and is linked from the current policy. Limitation: The bounded review did not submit the route or independently test form fields, verification, acceptance, or completion.
  - [https://subgraph.tech/privacy-choices](https://subgraph.tech/privacy-choices): The first-party privacy-choices route is separately named in the policy for certain sale-or-sharing requests. Limitation: The relationship between privacy-rights and privacy-choices routes should be confirmed before presenting a single workflow.

### Fifty Technology Ltd
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Fifty Technology Ltd, Fifty Media, public social-media sources, aggregated audience insights, source-platform controls, email, hotline, identity matching, erasure feasibility, and client-held aggregate boundaries before promotion.
- **Official evidence:**
  - [https://fifty.io/privacy-policy](https://fifty.io/privacy-policy): The current policy identifies Fifty Technology Limited trading as Fifty and Fifty Media and describes analytics, advertising technology, publicly available social-media data, audience insights, and media services. It describes access, opt-out, erasure, correction, restriction, portability, and objection rights and names a data-protection contact. Limitation: The policy says Fifty may not generally know names, full email addresses, physical addresses, or other identifiers for some web and social-media users, which can limit record matching and erasure.
  - [https://fifty.io/opt-out](https://fifty.io/opt-out): The first-party opt-out page describes publicly available social-media data, says the service does not collect cookie data or clear-text email addresses for the stated audience-insight activity, and provides a consumer email and California hotline for rights requests. Limitation: The page directs users to manage visibility on source social platforms as well as contact Fifty; those platform controls are not deletion from Fifty’s records or client-held aggregates.
  - [https://fifty.io/terms](https://fifty.io/terms): The first-party terms connect Fifty Technology Ltd and Fifty Media as the provider identity. Limitation: Terms do not establish current request-form behavior or downstream deletion.

### Integrated Direct Marketing, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Integrated Direct Marketing, LLC versus IDM, Inc., current privacy route availability, historical registry and policy evidence, data-provider sources, ccpa@idm.us.com, identity, deletion, and customer-copy boundaries before promotion.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/546429](https://oag.ca.gov/data-broker/registration/546429) — source date 2021-10-13: The California registration identifies IDM, Inc., describes it as a data brokerage company, and states that consumers may use the website’s Do Not Sell link or ccpa@idm.us.com for opt-out requests. The registration states that IDM acquires data from other providers and does not explicitly capture consumer data through its website or platforms. Limitation: The registry record is historical and does not establish current route fields, identity verification, confirmation, or completion behavior.
  - [https://idm.us.com/content/uploads/2021/10/IDM-Privacy-Policy.pdf](https://idm.us.com/content/uploads/2021/10/IDM-Privacy-Policy.pdf): The provider-hosted privacy policy describes sources including government sources, third-party vendors, data providers, data subjects, and public websites, and describes licensing business and professional contact information for marketing and data-management purposes. Limitation: This is an older provider-hosted policy; the current public privacy page and current legal-name relationship to the catalog record require recheck.
  - [https://www.idm.us.com/do-not-sell-my-personal-information/](https://www.idm.us.com/do-not-sell-my-personal-information/): The cataloged first-party Do Not Sell route remains the provider-stated URL referenced by the registration and catalog evidence. Limitation: The bounded web review could not safely fetch this URL, so current form fields, acceptance, identity checks, and completion remain unconfirmed.

### Rainbarrel USA LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Rainbarrel USA LLC, RainBarrel Inc., KnowerTech, rbarrel.com, advertising IDs, hashed email, source-platform controls, one-week effect statement, email, identity, deletion, and advertising/customer propagation before promotion.
- **Official evidence:**
  - [https://www.rbarrel.com/privacy-policy](https://www.rbarrel.com/privacy-policy) — source date 2025-10-21: The current RainBarrel policy identifies RainBarrel Inc. and describes mobile advertising IDs, IP addresses, location-based audience construction, hashed emails, aggregated demographics, and advertising-platform activation. It states that RainBarrel does not collect names, clear-text email addresses, clear-text phone numbers, or physical addresses for its audience products, and that requests may take up to one week to take effect. It provides CCPA access, deletion, and opt-out context and identifies info@rbarrel.com as a contact. Limitation: The catalog legal name is Rainbarrel USA LLC while the current first-party policy identifies RainBarrel Inc.; the corporate relationship to KnowerTech and the catalog record requires explicit entity review.
  - [https://www.rbarrel.com/opt-out](https://www.rbarrel.com/opt-out): The first-party opt-out form accepts an advertising ID and email for MAID and hashed-email audience opt-out and separately links Unified ID 2.0 controls. Limitation: This is an identifier- and audience-specific opt-out, not proof of removal from every RainBarrel system, source provider, advertising platform, or customer-held copy.
  - [https://www.rbarrel.com/company](https://www.rbarrel.com/company): The first-party company page identifies RainBarrel’s President as President of Knower Tech and describes the RainBarrel audience graph and consented advertising-data context. Limitation: A leadership reference is not sufficient evidence that KnowerTech, RainBarrel Inc., and the cataloged Rainbarrel USA LLC are the same legal entity.

### ASL MARKETING INC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile ASL Marketing Inc, aslmarketing.com, Deep Sync, Compact Information Systems, student and young-adult data, the family-wide privacy route, suppression, identity, deletion, and customer-copy propagation before promotion.
- **Official evidence:**
  - [https://deepsync.com/privacy-policy/](https://deepsync.com/privacy-policy/): The current Deep Sync policy identifies Compact Information Systems, LLC d/b/a Deep Sync and expressly lists ASL Marketing, Inc. among its branded lines of business and affiliates. It describes marketing, hygiene, analytics, consumer information, direct-mail, email, online channels, identity verification, deletion, opt-out, and suppression handling. Limitation: The policy covers a family of brands and distinguishes controller processing from other contexts; it does not by itself establish that every ASL-branded record is held in the same system.
  - [https://privacy.deepsync.com/](https://privacy.deepsync.com/): The current Deep Sync privacy route provides opt-out, targeted-advertising, profiling, deletion, address, phone, and email fields; it states that identity questions may be dynamically generated and that deletion can take up to 45 days with a suppression record. The first-party ASL site redirects into Deep Sync-branded content and the Deep Sync footer links to the same privacy route. Limitation: The route was not submitted; acceptance, identity outcome, confirmation, and brand-level propagation were not independently tested.
  - [https://help.deepsync.com/knowledge-base/student-and-young-adult-data](https://help.deepsync.com/knowledge-base/student-and-young-adult-data): The provider’s help content identifies ASL Marketing as a Deep Sync brand and describes student, young-adult, parent, college, and self-reported data products and source categories. Limitation: Marketing coverage and sourcing context do not prove deletion from customer-held datasets or every affiliated brand.

### Deep Root Analytics, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Deep Root Analytics, direct versus client-linked processing, audience and polling data, CCPA form, email, phone, identity matching, GPC, protected-person requests, deletion, and client-held copies before promotion.
- **Official evidence:**
  - [https://www.deeprootanalytics.com/privacy-policy](https://www.deeprootanalytics.com/privacy-policy): The current policy identifies Deep Root Analytics, LLC and describes processing for services, clients, website visitors, and individuals whose information is processed without a direct relationship. It describes access, deletion, correction, sale-or-sharing opt-out, profiling, GPC, and a first-party interactive webform plus a toll-free channel. The policy publishes 2025 request metrics and states that requests are verified against data points in the provider’s records. Limitation: The page states an effective date of March 2023 and a last-updated month of June 2026 without an exact day; the webform’s live fields and completion behavior were not independently tested.
  - [https://www.deeprootanalytics.com/ccpa](https://www.deeprootanalytics.com/ccpa): The first-party California page states that opt-out requests may be submitted with full name, physical address, and telephone number by webform, email, or phone, and describes authorized-agent verification. Limitation: The page provides request instructions but does not prove acceptance, response, deletion, or propagation to Deep Root customers.
  - [https://www.deeprootanalytics.com/](https://www.deeprootanalytics.com/): The first-party site describes Deep Root audience, polling, focus-group, and media-measurement services, supporting the cataloged entity context. Limitation: Business context alone is not proof of a current consumer request route.

### DataDelivers, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile DataDelivers, client-controlled processing, opt-out form fields, privacy email, identity matching, GPC, response targets, suppression, campaign copies, and deletion boundaries before promotion.
- **Official evidence:**
  - [https://datadelivers.com/privacy-policy/](https://datadelivers.com/privacy-policy/) — source date 2026-06-12: The current policy identifies DataDelivers, LLC and describes data strategy, analytic insights, customer-management technology, direct mail, email, website, and social-media marketing services. It provides access, deletion, correction, opt-out, portability, profiling, GPC, identity-matching, and authorized-agent context, with stated targets of 15 business days for opt-outs and 45 calendar days for deletion or access requests. The policy states that client data practices may differ and are not controlled by DataDelivers. Limitation: The policy’s route links and the separate form were not submitted; client-held copies and downstream campaign systems remain outside the provider’s own stated control.
  - [https://datadelivers.com/opt-out-form/](https://datadelivers.com/opt-out-form/): The first-party individual opt-out form exposes identity, name, address, email, phone, signature, date, and CAPTCHA fields and states that the information is used for database matching and suppression. The form identifies DataDelivers contact email and phone details. Limitation: The bounded review did not submit the form or independently confirm acceptance, verification, confirmation, or actual suppression.
  - [https://datadelivers.com/](https://datadelivers.com/): The first-party site describes DataDelivers customer-data-platform and marketing analytics services, supporting the provider context. Limitation: A reachable homepage does not prove a completed privacy request.

### Hivestack Technologies Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Hivestack Technologies Inc, Hivestack, Perion Network, perion.com, device identifiers, MAIDs, DOOH data, cookie opt-out, DSR route, privacy email, identity, deletion, and partner propagation before promotion.
- **Official evidence:**
  - [https://perion.com/ccpa/](https://perion.com/ccpa/): The Perion CCPA notice identifies Hivestack Technologies Inc. as a Perion affiliate and data broker, describes sale or sharing for advertising, and provides privacy, DSR, and opt-out context. It states that Hivestack’s offerings may rely on device identifiers such as MAIDs rather than direct identifiers such as email addresses, which can limit identity matching. The notice provides Hivestack contact information and reports a prior request-statistics table. Limitation: The page states a July 2025 last-modified month without an exact day and covers Perion and Hivestack contexts together; it does not prove current form acceptance or deletion from partner systems.
  - [https://perion.com/opt-out/](https://perion.com/opt-out/): The current Perion opt-out page provides a browser-cookie choice for interest-based advertising and explains that the choice is browser- and cookie-dependent. Limitation: The Perion cookie route is not equivalent to deletion of Hivestack device identifiers or customer-held advertising data.
  - [https://www.hivestack.cn/privacy-policy/](https://www.hivestack.cn/privacy-policy/) — source date 2025-02-24: The provider-hosted Hivestack policy identifies Hivestack Technologies Inc. as part of Perion Network Ltd, provides privacy@hivestack.com, describes DOOH advertising and device data, and links to DSR and industry opt-out mechanisms. Limitation: This policy is hosted on a regional Hivestack domain and has an older exact date; reconcile it with the current Perion route before promotion.

### Revenue Roll Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Revenue Roll Inc, Tie, meettie.com, public and partner sources, opt-in versus opt-out data, data-subject request route, identity, GPC, deletion, retention, and customer-held copies before promotion.
- **Official evidence:**
  - [https://meettie.com/privacy-policy](https://meettie.com/privacy-policy): The current policy identifies Revenue Roll Inc DBA Tie and describes public databases, marketing partners, social-media platforms, data providers, mailing addresses, email, phone, intent data, and targeted advertising contexts. It provides access, correction, deletion, sale-or-sharing, profiling, GPC, authorized-agent, identity-verification, and data-subject-request context through info@meettie.com. The policy describes prior request metrics and states that deletion or account termination may retain limited information for security, fraud, legal, or operational reasons. Limitation: The policy states a last-updated month of June 2025 without an exact day; the linked data-subject request form was not independently tested.
  - [https://meettie.com/revenue-roll](https://meettie.com/revenue-roll): The provider’s first-party transition page states that Revenue Roll is now Tie and describes its identity-network and opt-in framework. Limitation: Brand-transition context does not itself establish the current privacy form’s acceptance or record scope.
  - [https://meettie.com/terms](https://meettie.com/terms) — source date 2026-06-18: The current terms identify Revenue Roll Inc d/b/a Tie and connect the meettie.com platform to the provider identity. Limitation: Terms do not establish a consumer deletion outcome or downstream customer propagation.

### DataMentors LLC dba V12
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile DataMentors LLC, V12 Data, V12 Group, Porch Group Media, PGM Solutions, optout.porchgroupmedia.com, dataset scope, identity fields, response target, deletion, and affiliate/customer copies before promotion.
- **Official evidence:**
  - [https://optout.porchgroupmedia.com/](https://optout.porchgroupmedia.com/): The current PGM Solutions opt-out form identifies a first-party Porch Group Media route, states that submitted data is used to remove name, address, phone, and email information from PGM databases, and states a processing target of no longer than 10 business days. The form exposes name, address, email, phone, date, identity-role, and submission fields and provides privacy@porchgroupmedia.com. Limitation: The route uses PGM Solutions branding while the catalog profile uses DataMentors/V12; legal-entity, brand, and cross-database coverage require explicit reconciliation.
  - [https://www.v12groupinc.com/privacy-policy/](https://www.v12groupinc.com/privacy-policy/): The V12 Group policy describes direct-mail, online, email, and cookie-based services and browser/device-specific online advertising opt-outs. Limitation: The policy identifies V12 Group and Datagence rather than the cataloged DataMentors/Porch Group Media record; it is retained as historical or related-brand context, not proof of current PGM coverage.
  - [https://porchgroup.com/privacy](https://porchgroup.com/privacy): The Porch privacy policy provides parent-company access, deletion, and sale-opt-out context and identifies separate request timing for opt-out versus access/deletion requests. Limitation: Porch parent-company requests may cover different records from PGM Solutions or V12 datasets.

### MV Digital Group, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile MV Digital Group, LLC, CinqDI, voter-file and publisher data, psychographic modeling, privacy-rights route availability, identity, deletion, model retraining, and customer activation copies before promotion.
- **Official evidence:**
  - [https://www.cinqdi.com/](https://www.cinqdi.com/): The current first-party CinqDI site describes contextual and behavioral data, attitudinal and demographic insights, proprietary first-party publisher data, polling research, voter-file data, and audience-persona modeling. Limitation: The public page confirms audience-data activity but does not itself confirm a current consumer privacy request route or deletion workflow.
  - [https://www.cinqdi.com/company/](https://www.cinqdi.com/company/): The first-party company page describes CinqDI’s use of publication first-party data, voter-file data, audience segments, and psychographic models, supporting the provider and brand context. Limitation: Audience and modeling descriptions do not prove current request-form fields, identity verification, or deletion from models and customer activations.
  - [https://www.cinqdi.com/privacy-policy/#section-rights](https://www.cinqdi.com/privacy-policy/#section-rights): The cataloged first-party privacy-rights URL remains the route candidate associated with MV Digital Group/CinqDI. Limitation: The bounded review did not independently confirm this route’s current availability, form fields, acceptance, identity process, or completion behavior; do not promote the cataloged Equifax-route assumption without current entity evidence.

### Carry Technologies Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Carry Technologies, Hightouch, Match Booster, customer processor data, third-party enrichment, privacy preferences, email, identity, deletion, and original-provider or customer copies before promotion.
- **Official evidence:**
  - [https://hightouch.com/platform-privacy](https://hightouch.com/platform-privacy) — source date 2026-03-20: The current Platform Privacy Notice identifies Carry Technologies, Inc. dba Hightouch and describes Match Booster, audience enrichment, and third-party data-provider inputs. It distinguishes Hightouch’s processor or service-provider role for customer data from its own controlled processing and provides access, correction, deletion, opt-out, identity-confirmation, and authorized-agent context. It provides datadeletion@hightouch.com and a first-party privacy-choices route. Limitation: The notice distinguishes Hightouch-controlled data from customer data processed on behalf of customers; a request to Hightouch may not remove data held by the customer or original provider.
  - [https://hightouch.com/privacy-policy](https://hightouch.com/privacy-policy) — source date 2026-06-29: The current general policy identifies Carry Technologies, Inc. dba Hightouch and provides preferences.hightouch.com, datadeletion@hightouch.com, access, deletion, targeted-advertising, and identity-verification context. It states that it does not apply to personal information processed on behalf of customers as a processor or service provider. Limitation: The policy’s consumer route and form behavior were not submitted or independently tested.
  - [https://preferences.hightouch.com](https://preferences.hightouch.com): The first-party preferences subdomain is the provider-stated privacy-choice route linked from current Hightouch policies. Limitation: The bounded review did not confirm live fields, acceptance, verification, or completion.

### Decide Technologies Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Decide Technologies Inc, Decide’s advertising platform, publisher and platform partners, current privacy-page availability, registry email and phone, identity, deletion, cookie/device data, and partner-held copies before promotion.
- **Official evidence:**
  - [https://decide.co/](https://decide.co/): The current first-party site identifies Decide as an AI-powered performance advertising and unified advertising platform connecting advertisers, publishers, supply, and platform partners. Limitation: The current homepage confirms advertising-platform context but does not by itself establish a consumer privacy request route or the exact data-controller entity for every platform partner.
  - [https://decide.co/privacy](https://decide.co/privacy): The cataloged first-party privacy URL is retained as the route candidate associated with Decide Technologies Inc. Limitation: The bounded fetch returned no usable policy text; current request fields, entity identity, acceptance, verification, and completion remain unconfirmed.
  - [https://oag.ca.gov/data-brokers](https://oag.ca.gov/data-brokers): The catalog evidence links Decide’s California data-broker registration context to the official registry. Limitation: Registry discovery does not prove the current live route or downstream suppression.

### Digital Viking Media Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Digital Viking Media Inc, current first-party domain and privacy route, historical registry email/mail channels, identity, deletion, protected-person handling, and downstream customer copies before promotion.
- **Official evidence:**
  - [https://oag.ca.gov/data-broker/registration/571148](https://oag.ca.gov/data-broker/registration/571148) — source date 2023-08-01: The California registration identifies Digital Viking Media Inc and states that consumers may submit opt-out or other CCPA requests by email or postal mail, including protected-person requests. Limitation: The registry record is historical and does not provide the current privacy email, current form fields, identity verification, response timing, or completion behavior.
  - [https://www.digitalvikingmedia.com/privacy-policy](https://www.digitalvikingmedia.com/privacy-policy): The cataloged first-party privacy-policy URL is retained as the provider-stated route candidate. Limitation: The bounded review could not safely fetch the current page, so its route semantics and freshness are unconfirmed.
  - [https://www.digitalvikingmedia.com](https://www.digitalvikingmedia.com): The cataloged first-party domain is retained as the provider context for Digital Viking Media Inc. Limitation: A domain or contact page does not prove a current consumer privacy workflow.

### FreeWheel Media Inc
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile FreeWheel Media, Inc., publisher and media-buyer roles, device identifiers, CTV, cookie opt-out, CCPA email and phone route, identity, deletion, DMPs, publishers, and downstream advertising partners before promotion.
- **Official evidence:**
  - [https://www.freewheel.com/privacy-policy](https://www.freewheel.com/privacy-policy) — source date 2025-07-15: The current policy identifies FreeWheel Media, Inc. and affiliates and describes site visitors, publisher and media-buyer services, device identifiers, IP addresses, audience segments, advertising delivery, and connected-TV or streaming contexts. It provides access, portability, correction, deletion, Do Not Sell or Share, sensitive-information, phone, email, and identity-verification routes. It distinguishes FreeWheel’s role from publishers, media buyers, DMPs, and other advertising-ecosystem entities. Limitation: The policy says a FreeWheel cookie opt-out does not remove data controlled by publishers, demand partners, DMPs, or other ecosystem participants.
  - [https://www.freewheel.com/optout.html](https://www.freewheel.com/optout.html): The first-party opt-out page provides a FreeWheel cookie choice and explains that the preference is stored in a cookie. Limitation: Cookie opt-out is browser-specific and is not equivalent to deletion of all FreeWheel or partner-held information.
  - [https://www.freewheel.com/legal](https://www.freewheel.com/legal): The first-party legal center confirms the current FreeWheel provider domain and legal navigation. Limitation: Legal navigation alone does not prove a completed consumer request.

### Matchbook Data, LLC
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Matchbook Data, location and device identifiers, advertising ID or installation ID, privacy-choice versus deletion routes, email, phone, identity, recipient databases, and device-specific limitations before promotion.
- **Official evidence:**
  - [https://www.matchbookdata.com/privacy-policy/](https://www.matchbookdata.com/privacy-policy/): The provider policy describes Matchbook as a platform for collecting, aggregating, licensing, and managing location and device data for audience building, advertising measurement, and research. It describes browser, mobile-device, email, access, deletion, opt-out, appeal, privacy-email, and phone routes. Limitation: The policy does not by itself prove that an advertising-ID opt-out removes previously collected data from every recipient or licensed database.
  - [https://www.matchbookdata.com/your-privacy-choices/](https://www.matchbookdata.com/your-privacy-choices/): The current first-party privacy-choice page distinguishes opt-out from deletion and explains that requests require a device or advertising ID plus an email address. It exposes device ID and email fields, provides privacy@matchbookdata.com and a toll-free number, and describes device-setting limitations, including Android zeroing behavior. Limitation: The live form was not submitted; identity matching, confirmation, acceptance, and downstream recipient deletion were not independently tested.
  - [https://www.matchbookdata.com/](https://www.matchbookdata.com/): The first-party site navigation and footer identify Matchbook as the provider context for the privacy-choice route. Limitation: Business context alone is not proof of request completion.

### Milestone Marketing Solutions
- **Status:** review-only; not promoted to customer-ready catalog fields
- **Reviewed:** 2026-08-15
- **Next action:** Reconcile Milestone Marketing Solutions, LLC, third-party sources, Do Not Sell form, email, phone, mail, identity, response evidence, CCPA deletion, and customer-held copies before promotion.
- **Official evidence:**
  - [https://www.milestonemarketingsolutions.com/privacy-policy](https://www.milestonemarketingsolutions.com/privacy-policy) — source date 2026-03-26: The current policy identifies Milestone Marketing Solutions, LLC and describes information collected through services, communications, and third-party sources including data brokers. It provides rights to opt out of targeted advertising, profiling, and sales, along with access, deletion, correction, identity, and request context. Limitation: The policy’s current form fields and completion behavior were not independently tested.
  - [https://www.milestonemarketingsolutions.com/do-not-sell-my-information](https://www.milestonemarketingsolutions.com/do-not-sell-my-information): The first-party Do Not Sell page states that consumers may request removal by toll-free phone, written request, email, or a form and that all form fields must be complete and accurate. Limitation: The page was not submitted; confirmation, verification, response timing, and deletion from downstream customer copies remain unconfirmed.
  - [https://www.milestonemarketingsolutions.com/ccpa](https://www.milestonemarketingsolutions.com/ccpa): The first-party California policy provides CCPA access, deletion, correction, and sale opt-out context and states that information will not be shared after an opt-out unless the consumer later consents. Limitation: The page does not establish that every affiliated customer or historical recipient has deleted earlier copies.

## Source boundary

Customer-ready catalog records, provider-published material, official registries, and bounded read-only observations are separate evidence types. Route reachability does not prove request acceptance, delivery, deletion, monitoring, or non-republication.

Machine-readable version: [content-authority-plan.json](/content-authority-plan.json).
