Marketing Box campaigns run on one of the industry's largest and most rigorously governed consumer identity graphs, powering direct mail, email, SMS, and social activation across the automotive industry. When you hand us your data, here is exactly how it is sourced, secured, and governed.
- US-only data — no foreign data is accepted or processed.
- Sensitive categories excluded — no minors, SSNs, driver's license numbers, credit/FICO data, or health information.
- Monthly USPS Move-Update hygiene (NCOA + CASS) on every postal address.
- Least-privilege security with MFA, VPN, and encryption at rest and in transit.
- Full support for consumer choice — DAA, NAI, and CCPA mechanisms.
1. Data Sourcing & Origin
The identity graph includes 240M+ names and addresses, 1B+ emails, and 2B+ device IDs. Data is sourced from public records, warranty cards, consumer surveys, ecommerce and transactional data, directory assistance (phones), opted-in email partners, and mobile apps (MAIDs).
Automotive data is VIN-linked and sourced independently — never from state DMV/MVA records, keeping it compliant with the Shelby Act and the Driver's Privacy Protection Act (DPPA). All data is US-based only.
2. What We Will Not Touch
We explicitly do not accept, store, or distribute any of the following:
3. How We Comply With Regulations
| Regulation | How We Comply |
|---|---|
| CCPA / CPRA | California data broker registration maintained. Consumers can request deletion or learn what data is held. |
| COPPA | Strict exclusion of anyone under 18. |
| DPPA / Shelby Act | Vehicle data sourced independently via VIN — never from state DMV/MVA records. |
| FCRA | No credit reporting data accepted. |
| CAN-SPAM | 3-level email hygiene, physical address in mailings, and clear opt-out. |
| TCPA | Platform enforces suppression lists and supports consent flags. |
| GDPR | No EU personal data collected or sold. |
| USPS Move Update | Monthly NCOA + CASS processing on all postal addresses. |
| DAA / NAI / IAB | Partners are members. We support AdChoices, AppChoices, and universal opt-out portals. |
4. Hygiene, Validation & Suppression
- Monthly NCOA + CASS + address standardization.
- Quarterly full identity graph rebuild.
- Email: 3-level hygiene (spam traps, hard bounces, complainers, invalid domains).
- IP addresses from opt-outs are scrubbed monthly.
- Full suppression-list management integrated into CRM and campaign execution.
This is the same hygiene discipline behind our 10-step data cleanse — and why we can say zero budget is wasted on bad records. For the deeper story, see The Hidden Cost of Dirty Dealer Data.
5. Security & Data Handling
- Client-specific SFTP (IP whitelisted) or encrypted per-client S3 buckets.
- PII is minimized — emails hashed for matching, an internal platform ID assigned, and PII stripped for downstream use.
- Least-privilege access, MFA + VPN, and encryption at rest and in transit.
- SOC 2 Type II security controls, with HITRUST e1 certification arriving Summer 2026.
- Secure data destruction with certificate available on request.
- Formal incident response with contractual client notification.
Why this matters: under the FTC Safeguards Rule, dealers are accountable for every vendor that touches customer data. We wrote the dealer's guide to it — see The FTC Safeguards Rule and Your Marketing Vendors.
6. Consumer Rights & Opt-In Evidence
Every email record in the graph includes its source website, the IP address at time of opt-in, the registration date, and a link to the partner's privacy policy. Consumers can exercise their rights through the original source, DAA/NAI portals, or by contacting us directly.
7. Contact
Marketing Box, LLC
For compliance inquiries or data-subject requests: compliance@marketingbox.com or through your account representative.
Run campaigns on data you can stand behind.
Compliant sourcing, rigorous hygiene, and SOC 2 Type II security — built into every Marketing Box campaign.
Get Your Free Campaign Plan →This document is derived from our Annual Data Collection & Privacy Certification, internal processes, and the current platform architecture. It is reviewed and updated regularly and is provided for informational purposes; it is not legal advice. Effective June 2026.