Privacy Policy

Effective: March 27, 2026 · Last Reviewed: July 20, 2026 · Quorum Data, Inc.

Quorum Data, Inc. is a registered data broker in California and Texas; registration is in progress in Oregon and Vermont. This notice also serves as our Notice at Collection: the categories we collect, the purposes, whether they are sold or shared, and retention periods are described in Sections 1, 3, and 4.

Quorum Data, Inc. ("Quorum," "we," "us," or "our") operates quorum.inc, quorum.works, and related services, APIs, and platforms (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, retain, and protect information when you use our Services, advertising platform, and audience intelligence tools.

By using the Services, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of the Services.

1. Information We Collect

1.1 Account & Contact Information

When you register, request a demo, or contact us, we may collect your name, email address, phone number, company name, job title, billing address, and payment information to manage your account and provide Services.

1.2 Usage Data

We automatically collect information about how you access and use the Services, including IP address, browser type and version, operating system, device identifiers, pages visited, time and date of access, referring URLs, clickstream data, and session duration.

1.3 Cookies & Tracking Technologies

We use cookies, web beacons, pixels, and similar technologies to operate our Services, remember preferences, analyze traffic, and improve user experience. We are implementing support for the Global Privacy Control (GPC) signal; once enabled, a detected GPC signal will be treated as a valid opt-out request under applicable state privacy laws. You can also control cookies through your browser settings, though some features may not function properly without them.

Quorum's own websites do not permit third parties to collect personal information about your online activities over time and across different websites or online services. Through our advertising-measurement services on our clients' websites, third-party advertising and analytics providers may collect such information under those clients' own privacy notices.

1.4 Location & Device Data (Advertising Services)

Through our advertising and measurement services, we process anonymized, opt-in location data from mobile devices via partner applications. Key facts about this data:

1.5 Data We Do Not Collect

Quorum does not collect Social Security numbers, driver's license numbers, financial account numbers, biometric data (fingerprints, facial recognition), genetic data, or precise real-time location tracking of identified individuals.

1.6 Sources of Personal Information

We collect personal information from the following categories of sources:

Source categoryWhat we obtain
Directly from youAccount, contact, and billing information; support communications
Automatically from your devicesUsage data, cookies, and pixel events on our own websites and apps
Mobile application partnersOpt-in, pseudonymous device location signals (MAIDs)
Advertising clients and their platformsAd-impression logs, web-pixel events, and campaign metadata clients direct to us for measurement
Data and identity partnersDevice-to-household and identity-resolution data
Publicly available and licensed sourcesBusiness location (point-of-interest) data; brand and category reference data

2. How We Use Your Information

We use collected information for the following purposes:

2.1 Data Minimization

We limit our collection of personal data to what is adequate, relevant, and reasonably necessary for the purposes disclosed in this policy, and we do not process personal data for purposes incompatible with those disclosed or beyond a consumer's reasonable expectations. We do not collect, use, retain, or share personal data for additional purposes not disclosed here without first disclosing the new purpose and, where required by law, obtaining the consumer's affirmative, voluntary consent. We are implementing additional data-minimization controls, including removing collection at sensitive locations (see Section 13).

3. Advertising Services & Audience Data

Quorum provides deterministic location attribution and audience intelligence to advertising clients. Our advertising services operate as follows:

3.1 Categories of Personal Information Processed (CCPA Disclosure)

In the preceding 12 months, we have collected and/or processed the following categories of personal information:

CategoryExamplesPurpose
IdentifiersName, email, IP address, device IDs (MAID/IDFA/GAID), pseudonymous household IDsAccount management, ad services
Commercial InformationTransaction records, service historyBilling, service delivery
Internet/Network ActivityBrowsing history, search history, ad interactionsAnalytics, ad measurement
Geolocation DataAnonymized location signals from opted-in devicesAudience intelligence, attribution
InferencesBehavioral cohorts, brand affinity, media preferencesAudience segmentation
Professional/EmploymentCompany name, job titleAccount management

3.2 Sale and Sharing of Personal Information

Under the CCPA/CPRA, "selling" means disclosing personal information for monetary consideration, and "sharing" means disclosing for cross-context behavioral advertising.

Quorum may "share" device identifiers and geolocation data with advertising clients for the purpose of targeted advertising and campaign measurement. We do not "sell" personal information as traditionally understood (i.e., for direct monetary compensation for the data itself). However, because our business involves providing audience data to advertising clients, certain disclosures may constitute a "sale" or "share" under the broad definitions of applicable state privacy laws.

You have the right to opt out. See Section 6 (Opt-Out Procedures) below. We do not sell or share the personal information of consumers we know to be under 16.

Sensitive personal information: precise geolocation is the only category of sensitive personal information we process. We process it only from opt-in sources, aggregate it to household-level cohorts, and honor the right to limit its use (Section 8).

3.3 Categories Sold or Shared (preceding 12 months)

Category sold or sharedCategories of third parties
Identifiers (pseudonymous device IDs; hashed household identifiers)Demand-side and ad-buying platforms (e.g., The Trade Desk, Xandr, DV360, Magnite); identity-resolution and data-onboarding providers (e.g., LiveRamp); advertising clients and their agencies
Geolocation-derived audience data (aggregated cohorts)Same categories of recipients as above
Internet or other network activity (ad-interaction signals)Advertising clients and their agencies (measurement)
Inferences (behavioral cohorts, brand affinity)Demand-side platforms; advertising clients and their agencies

We have not sold or shared account/contact information, commercial information, or professional/employment information.

3.4 Categories Disclosed for a Business Purpose (preceding 12 months)

Category disclosedCategories of recipients (service providers/contractors)
Identifiers; internet/network activity; geolocation data; inferencesCloud infrastructure and data-warehouse providers (e.g., Amazon Web Services, Snowflake); AI-platform infrastructure providers (e.g., Anthropic, for the Connector Service); security and fraud-prevention vendors
Account/contact and commercial informationPayment processors; email/communications providers; professional advisers (legal, accounting)

4. Data Retention

We retain personal information only as long as necessary for the purposes described in this policy or as required by law. Specific retention periods:

Data TypeRetention Period
Account informationDuration of account + 2 years after closure
Device location signals (MAIDs)Rolling 30-day active window; historical aggregates retained up to 24 months
Campaign measurement dataDuration of campaign + 12 months
Audience segmentsRefreshed every 30 days; stale segments purged after 90 days
Usage/analytics data24 months
Billing records7 years (legal/tax requirements)
Consumer rights request records24 months (CCPA requirement)

When retention periods expire, data is deleted or irreversibly anonymized within 30 days.

5. Data Sharing & Disclosure

We may share information in the following circumstances:

We do not share personal information with data brokers or sell consumer contact information (names, emails, phone numbers) to third parties for their own marketing purposes.

6. Opt-Out Procedures

Do Not Sell or Share My Personal Information — use this link to opt out of the sale or sharing of your personal information. You have several options to opt out of interest-based advertising and data processing:

6.1 Global Privacy Control (GPC)

We are implementing support for the Global Privacy Control signal. Once enabled, if your browser or device sends a GPC signal, we will treat it as a valid opt-out of the sale and sharing of your personal information under applicable state laws (including CCPA/CPRA, VCDPA, CPA, CTDPA, and others). In the meantime, you may opt out through any of the methods below. When implemented, the GPC signal will be honored at the level of the browser or device from which it is sent. Because our advertising data is pseudonymous and not tied to a named consumer account, the opt-out applies to that browser or device and its associated pseudonymous identifiers rather than to an account, and it does not apply to offline sales.

6.2 Device-Level Opt-Out

When you opt out or reset your advertising identifier, Quorum can no longer associate your device with previously collected data. Your device may still receive non-targeted ads.

6.3 Industry Opt-Out Programs

6.4 Direct Request

You may submit a privacy request through either of two methods: our online request form at app.quorum.live/privacy-request, or by email to privacy@quorum.inc. Neither method requires you to create an account.

7. Data Security

We implement commercially reasonable technical and organizational measures to protect your data, including:

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security. If we become aware of a security breach affecting your personal information, we will notify you and applicable regulators in accordance with applicable law.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

You may exercise these rights through either of two methods: our online privacy-request form at app.quorum.live/privacy-request, or by email to privacy@quorum.inc. You do not need to create an account to submit a request. We will respond within the timeframe required by applicable law (generally 45 days under CCPA, extendable by an additional 45 days where reasonably necessary, with notice of the extension to you).

We handle verifiable requests free of charge, up to twice in a 12-month period per consumer. If a request is incomplete, deficient, or cannot be verified, we will either treat it as properly submitted where feasible or promptly inform you how to correct or complete it. Requests concerning consumer health data governed by the Washington My Health My Data Act, where applicable, are handled within the shorter timeframe that law requires.

How we verify requests. To verify a request to know, delete, correct, or access information about automated decision-making, we will ask you to provide identifying information — such as the email address or the device/advertising identifier associated with the data — so we can match it to records we hold. For sensitive or high-risk requests we may require additional verification. You do not need an account with us to submit a request.

Authorized agents. An authorized agent may submit a request on your behalf by emailing privacy@quorum.inc with written permission signed by you. This includes a parent or legal guardian acting on behalf of a child, and a guardian, conservator, or holder of another protective arrangement acting on behalf of a protected person. We may separately verify your identity and confirm the agent's authorization and relationship before processing the request.

Appeals. If we deny your request, you may appeal by emailing privacy@quorum.inc with "Appeal" in the subject line. We will respond with our decision and the reasons for it within the time required by applicable law (generally 45 days), and provide information on how to contact the relevant state attorney general if you remain dissatisfied.

We will not discriminate against you for exercising any of your privacy rights. We will not deny you goods or services, charge different prices, or provide a different level of quality.

We also prohibit the use of our data and audience products to discriminate against consumers in violation of applicable anti-discrimination laws — including targeting or excluding consumers based on protected characteristics (such as race, color, national origin, religion, sex, familial status, disability, or age) in connection with housing, employment, credit, insurance, or public accommodations. Our client terms restrict these uses and prohibit using our data as a factor in determining a consumer's eligibility for credit, insurance, employment, or housing.

9. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Automated Decision-Making Technology (ADMT): Quorum uses automated processing to generate audience segments, behavioral cohorts, and campaign attribution reports. These automated processes do not make decisions that produce legal or similarly significant effects on individual consumers. If you have questions about our use of ADMT, contact privacy@quorum.inc.

Financial Incentives: We do not offer financial incentives for the collection, sale, or deletion of personal information.

Shine the Light: California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing. Contact privacy@quorum.inc.

Consumer request metrics. In calendar year 2024, Quorum received 0 requests to know, 0 requests to delete, 0 requests to correct, and 0 requests to opt out of the sale or sharing of personal information.

Data broker registration. Quorum Data, Inc. is registered as a data broker with the California Privacy Protection Agency and the Texas Secretary of State; registration is in progress in Oregon and Vermont.

10. Other State Privacy Laws

Quorum complies with applicable state privacy laws, including but not limited to:

If your state has a privacy law that grants you rights not listed here, please contact us and we will work to accommodate your request.

Universal Opt-Out Mechanisms: We are implementing recognition of universal opt-out signals, including Global Privacy Control (GPC), as required by applicable state laws.

Oregon: Oregon residents may request the list of specific third parties to which we have disclosed personal data. Rhode Island: the categories of third parties to which we sell or may sell personally identifiable information are described in Section 3.3.

11. International Users (GDPR / UK GDPR)

Quorum's household intelligence graph and measurement panel cover United States residents only; we do not offer consumer-measurement services concerning individuals located in the EU, EEA, or UK. Where we process personal data of EU/EEA/UK individuals (for example, business-contact information of client personnel, or personal data a client submits to us for processing), such processing is subject to the EU GDPR and UK GDPR as applicable:

12. Children's Privacy

Our Services are not directed to anyone under the age of 16. We do not knowingly collect personal information from children under 16. In particular:

If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child, please contact us at privacy@quorum.inc.

A parent or legal guardian may exercise a child's privacy rights on the child's behalf — including the rights to know, delete, correct, and opt out of sale or sharing — through the methods in Section 8. A guardian, conservator, or holder of another protective arrangement may likewise exercise these rights on behalf of a protected person. We verify the requester's identity and their authority to act (for example, documentation of the parental or guardian relationship) before processing the request, and the requester may appeal a denial as described in Section 8.

13. Sensitive Location Data

Consistent with California AB 45 (effective January 1, 2026) and similar state protections, Quorum's policy is not to use, disclose, sell, or share personal information derived from an individual's presence within the precise geolocation of:

We contractually require our location-data suppliers to exclude these categories of sensitive locations before delivering data to us, and we are implementing and auditing additional internal geofence exclusion controls to enforce this policy across our own location library.

14. Do Not Track & Global Privacy Control

Some browsers offer a "Do Not Track" (DNT) signal. There is no industry consensus on how to respond to DNT, and we do not currently respond to DNT signals. We are implementing support for the Global Privacy Control (GPC) signal; once enabled, we will treat it as a binding opt-out of the sale and sharing of personal information under applicable state laws. Until then, you may opt out through the methods in Section 6 or by emailing privacy@quorum.inc.

15. Third-Party Links & Services

Our Services may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices, content, or security of those third parties. We encourage you to review the privacy policies of any third-party services you access.

16. Data Protection Impact Assessments

Quorum is implementing a risk-assessment and Data Protection Impact Assessment (DPIA) process for processing activities that present a heightened risk to consumer privacy, including targeted advertising, the sale or sharing of personal information, and the processing of sensitive personal information. Completed assessments will be made available to the California Privacy Protection Agency as and when required by applicable law.

17. The Quorum AI Connector (MCP) Service

Quorum offers a connector for AI assistants (the "Connector Service") at mcp.quorum.live, which gives AI agents access to deterministic, privacy-safe ground truth about real-world consumer behavior. The Connector Service operates under this Privacy Policy with the following additional guarantees:

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will:

Continued use of the Services after changes constitutes acceptance of the updated policy.

19. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a complaint, contact us at:

Quorum Data, Inc.
Privacy Inquiries: privacy@quorum.inc
General: sales@quorum.inc
Legal: legal@quorum.inc

We aim to respond to all privacy inquiries within 10 business days and to fulfill data subject access requests within the timeframes required by applicable law.