My husband found something online he thought I’d like and texted me the link. I clicked and looked at it on my phone and moved on. I didn’t buy it, never signed up for anything, and definitely never typed my email address into that site.
Within a day, I had a “Welcome to [Retailer]” email sitting in my inbox.
Ninety minutes later: “Still thinking about it?”
Two days after that: two more emails, ninety minutes apart.
Day three: two more, this time three hours apart.
Then nothing. I guess that’s the end of the welcome sequence. They gave up on me.
To protect this brand, who likely thinks this is awesome, I’m sharing just a snippet of the first email.

When I told my husband this scenario, his first question was what most people would say: “How did they get your email?”
I didn’t give it to them. I don’t have an account with this retailer, and I’ve never bought anything from them. My husband has, on his own account, using his own email. It would be easy to assume that’s the connection. It’s not, and it’s worth explaining why.
Oh, and the best part – it went to my work email. If I were to make a personal retail purchase, I would use my personal email, not work. And there’s a long list of implications if it’s a work email (so keep reading).
This is the universe of adtech
I want to be clear about where I stand on this, because I don’t think privacy people should pretend advertising is the enemy. I believe in adtech. Businesses need to advertise, and there can be real value in using data to do that well. But there’s a difference between advertising that’s useful and advertising that’s creepy, and this sits firmly in the second category.
Here’s roughly how this situation likely played out. Most retail sites run pixels from ad tech and data companies in the background, invisible to the person browsing. That’s what all those cookies we talk about all day are doing.
When I visited that page, one of those pixels could see me (and I don’t remember if there was or wasn’t a cookie banner. If you’ve heard me speak before, you know I say I live in Georgia and have no privacy rights, so I likely would have cookies dropping immediately anyway).
There’s a whole industry built around connecting anonymous visits to real identities. Data companies collect emails from all kinds of sources: other retailers, loyalty programs, co-op data pools where companies share customer lists, and plenty of places where an email got passed along or sold without much thought. Cue the data brokers, and for those of you in California and soon other states, you get the option to opt out of data brokers from selling your data. Lucky you!
If you want to check out a list of data brokers, you can see those registered in CA here.

Back to our situation … a retailer can plug into an “identity resolution” or “email onboarding” vendor, and when an anonymous visitor’s pixel data lines up with an email sitting in one of those purchased pools, the retailer gets a name and an address to email, no sign-up required. This is true for direct mail (ever wonder how all those mailers show up in your mailbox? That’s an entire other discussion).
I never opted in or created an account with this company, and I never gave my permission for any of it. The connection wasn’t about who sent me the link or what device I was on. It was about my email existing somewhere in a data pool a vendor bought and had access to, and a pixel that happened to catch my visit.
What happens when this lands in a work email?
This is where the work email part matters, and it’s bigger than my inbox.
I’m a small business owner, so my work email isn’t sitting inside a big company with an IT department, a monitoring tool, or a manager who might notice six retail emails showing up in three days. It’s just me. So for me, this is annoying, and I can explain it away in one sentence.
Now picture this happening to someone at a large company instead. Their work email ends up in the same kind of purchased data pool mine did, for reasons that have nothing to do with anything they did at work. A pixel catches a visit somewhere, an identity resolution vendor matches it to that work email address, and a “welcome” sequence starts landing in their corporate inbox. They never signed up. They may never have even visited the site themselves, depending on how the match happened.
But now there’s a paper trail. If IT flags outbound mail from unfamiliar retailers, or a manager happens to see the inbox, the assumption is easy to make: this employee signed up for something, probably on company time, probably on a company device. What if it’s what a company deems a questionable product or service?
What if it’s really personal or private and an employee doesn’t want their personal information, habits, or interests shared with their employer?
That’s the risk I don’t think gets enough attention. It’s not just about a company guessing at my shopping habits. It’s also about a company’s assumption that an employee is potentially doing something “wrong” when the employee had no control over any of it.
The privacy risk underneath this
This is where I want to slow down, because the marketing outcome is annoying, but the underlying practice is a real privacy risk, not just a mild irritation.
Identity resolution vendors work by connecting data points that were never collected from me directly and never collected by this retailer at all. My email exists in a pool somewhere, probably because I gave it to a different company entirely for a completely different reason, and that company’s data ended up feeding into a marketplace that I couldn’t tell you the name of.
A pixel on a retailer’s website caught an anonymous visit, ran it against that marketplace, got a hit, and handed the retailer my email. I have no account with this retailer, and I have never made a purchase. I shared above that the likelihood of my getting an opt-in banner is unlikely, so I didn’t consent to cookies.
Even if I DID consent, do I really know what I consented to? Ask your friends who don’t talk about privacy, pixels, and privacy notices all day long, and I feel fairly confident they don’t have a clue about the entire web of companies behind the scenes connecting all their clicks to their email, phone number, or home address.
It’s not enough for a privacy team to JUST ensure there’s a cookie banner set up and opt-outs are managed properly. Is there actually an understanding of what the marketing team is doing with that data? What pixels are there and what do they really do? Is this in line with the customer’s expectations? Is there a clear explanation in the privacy notice that says we’re going to connect your data and send you personalized advertising you never asked for?
This situation doesn’t stop at just the welcome email or the six emails I received. The same identity graph that tied me to this retailer can be resold, shared with other advertisers, or used to build lookalike audiences elsewhere. I didn’t just get emailed once. I became a data point that can keep getting used, without ever knowing it happened.
Why this doesn’t build trust with the customer
Here’s what I keep coming back to: this didn’t make me more likely to buy. It made me actively unwilling to.
Getting six emails in three days from a brand I never signed up with doesn’t feel personalized. The attempts to make the emails fun and as if I have joined a club felt the opposite because it feels invasive.
The moment a customer feels tracked instead of understood, the relationship is already damaged, no matter how good the product is.
Trust with a customer is built by respecting the boundary between what they’ve shared and what a system has guessed about them. When a brand crosses that line, even unintentionally, the customer doesn’t read it as clever marketing. They read it as a company that doesn’t know where its own boundaries are.
Once someone feels that, they don’t just ignore the emails. They tell people. I’m telling you, right now, in this newsletter, about a company I won’t name because I’m not really a fan of public company shaming. Instead, I’d rather share and have more companies discuss and learn.

Privacy teams:
- Ask marketing directly which identity resolution or household matching tools are in place, and get the vendor names, not just the category of the tool.
- Ask the vendor, in writing, how they source the email addresses that trigger a “welcome” or “still thinking about it” sequence, and whether that’s disclosed anywhere a person would really see it.
- Map whether consent was collected from the person who actually receives the message, not just from the account holder tied to the original purchase.
- Put identity resolution and pixel-based matching on your vendor risk review list, not just your cookie and pixel review list. It’s a different mechanism, and it needs its own scrutiny.
- Ask whether the vendor’s matching pool could include corporate or work domains, and whether that’s something your privacy notice or data processing agreements account for at all.
- Review your privacy notice to see how any of this activity is explained in the privacy notice.
Marketing teams:
- Pull the actual conversion data on cold “welcome” sequences triggered by inferred identity, not assumed sign-up, and compare it against complaint or unsubscribe rates. How well are these campaigns doing? What’s the lifetime of the customer?
- Before renewing any platform that does pixel-based identity matching, ask what happens to the match after the campaign ends. If you don’t know, you don’t actually control the tool you’re using.
- Treat “creepy” as a real success metric to test for, the same way you’d test open rate or click-through. Ask a handful of real customers, not your team, whether a sequence like this would make them buy or make them leave.
- Ask your vendor whether their matching logic excludes or flags corporate domains, since a purchased consumer email pool sending retail campaigns into work inboxes creates a problem your team didn’t intend and can’t easily undo.
HR teams:
- If your organization monitors network activity, email sign-ups, or browsing tied to a work address or device, get a clear answer from IT and legal on how pixel-based identity matching could produce false signals.
- Build in a step before any disciplinary or performance conversation that references online activity that might be questionable, as it could be just like this situation and a company just added an email to their list.
- Loop in privacy or legal before treating an inbox message, a browser history entry, or a flagged domain as evidence of anything. The data behind it may not mean what it appears to mean.
Where this leaves me
I still believe in advertising, and I got started in this space with what we now call “classic retargeting” back in the late 2000s. It’s now moved past that into what I think is questionable.
Just because we can, doesn’t mean we should.
Cold emailing a work account, welcoming me to a community I never opted into or tried to join, is not the best customer experience or first impression.
If your organization is building out identity resolution, pixel-based matching, or any kind of vendor-driven audience targeting, it’s worth stepping back and mapping what data is actually flowing and who’s really consenting to what.
That’s exactly the kind of gap a marketing and cookie governance assessment is built to catch, before a vendor’s “smart” matching turns into a real risk for your customers or your employees.
Jodi
💡 When you’re ready, here’s how we can help:
⚙ Privacy Advisory & Implementation: We help companies navigate privacy requirements with confidence. Our advisory support covers strategy, operations, and real-world implementation.
⚙ Fractional Privacy Services: We provide fractional privacy leadership tailored to your needs and pace. From program development to day-to-day support, we help you build and sustain a strong privacy program.