Advertising & Marketing

The industry files

The moment a page loads, details of your visit go out to the companies bidding to show you an ad. Other firms never go near you and build your file from bought sources instead. Opt-outs are usually tied to one device, and retention runs from a week to no limit at all.

The read at a glance

Tracking priority High

The profile is bought, enriched and resold between firms you have never heard of.

If it leaks High

A leak exposes the inferences drawn about you: your spending power, your habits, and segments covering health and politics you never disclosed.

Expect it kept Indefinitely

Ad and broker profiles are kept and traded with no end date; "anonymised" segments never expire.

Identity demanded None

You never signed up: the profile is built from data collected elsewhere.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

A leak exposes an inference file: what you buy, what you earn, what you are worth targeting for. UK and US regulators found segments covering mental health, sexual health, substance use and politics, tied to precise location: conclusions you never stated.

What repeats in the policies

Who's collecting

You never signed up for this

Open an ordinary website or app and it runs tracking code from advertising firms you have never heard of. There is no account, no login and no sign-up. They collect your device, your IP address and the pages you open, and none of them is a company you chose.

How you get in it

One half watches you. The other buys you.

An ad platform learns you by being on the page: the moment it loads, details of your visit go out to the companies bidding to show you an ad, and the UK's data regulator reported that a single request can reach hundreds of companies. A list compiler never goes near you and builds its file from client companies, public registers and bought sources. The two meet in an identity graph, where a scrambled copy of your email address joins the browser to the offline record.

What stays

Deleted rarely means gone

How long the data lives is their claim, and it varies widely: some policies name a week, some thirteen months, several name no limit at all. When a stated period ends, the common wording is de-identified or aggregated rather than deleted. What was learned from you is kept, sometimes for years more.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Browsing & ActivityLocation Contact Info · maybeAccount Profile · maybePurchases · maybeFinancial · maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Money and net worth Likely

Wealth brackets and spending power are core targeting data.

Political views Likely

Segments explicitly model political leanings.

Health Likely

Inferred health conditions are sold as segments.

Sexual orientation Possible

Orientation is an inferred and traded segment.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

A do-not-contact record They set it kept indefinitely, by design

A minimal note kept on purpose so they do not contact you or re-add you.

Anonymised, aggregated, or AI-trained data They set it often kept indefinitely

They treat it as no longer being about you, though such data can sometimes be re-identified.

Fraud-prevention markers They set it about 2 to 6 years

To flag suspected fraud, often on a shared industry database you cannot reach through the company.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

Most of this market is mundane: advertisers buying intent, in-market segments, spending power. The edges are documented too. The UK's data regulator reported that the fields broadcast in a bid request can include mental health, sexual health, substance abuse and politics. The US trade regulator banned one broker after it sold precise location tied to advertising IDs, enough to place a phone at a reproductive health clinic or a domestic abuse shelter. Other firms in this trade hold offline records down to a name, home address and social security number.

Sold or shared Highly likely

Selling and enriching your profile is the entire business.

AI training High

Behavioural profiles train targeting and inference models.

Even anonymised, this can still be you

In 2024 the US Federal Trade Commission found a broker's location data "is not anonymized" and could match a person's device to the places they visited, and four location points single out 95% of people (de Montjoye et al., 2013).

Name, date of birth, postcode Sometimes

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces Typical

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns Sometimes

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

Browsing fingerprint Typical

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)·FTC order prohibits data broker X-Mode Social and Outlogic from selling sensitive location data (US Federal Trade Commission, 2024)

Before writing to a company like this

Deleting here creates a file. Brokers and ad platforms honour a deletion by putting you on a suppression list and keeping it indefinitely, so the next batch of data they buy does not re-import you. That is the system working as intended, and it means the one permanent record they hold on you is the one your own request created. If a removal service filed it for you, you are paying a subscription to have that record made.

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“your consent, obtained for us by the operators of the sites that use our technology”

“your consent, obtained for us by the operators of the sites that use our technology”

The firm never asks you anything. Its permission to track you comes second-hand, from a cookie banner on a site you visited, and that site decides whether you were asked at all. The UK's data regulator reported that consent collected this way was not compliant.

The move Which basis they claim, and who collected it for them, is theirs to state.

“these opt outs are specific to the device or browser on which they are exercised”

“these opt outs are specific to the device or browser on which they are exercised”

The opt-out is a cookie or a device setting, because you have no account here. Clear your cookies, switch browser or pick up a new phone and it is gone, and the collection starts again. You have to repeat it for every company, on every device.

The move A request goes to the company itself, not to a cookie on one device.

“certain activities described here may constitute 'sharing', 'selling' or processing for 'targeted advertising'”

“certain activities described here may constitute 'sharing', 'selling' or processing for 'targeted advertising'”

An admission that the ordinary running of the platform counts as a sale of your personal data under US state privacy law. The word may lets the same sentence carry the opt-out link the law requires while never stating the sale plainly.

The move In the US you can direct them not to sell or share your data, and state law backs the request.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.