McDonald’s Built a 515-Page File on One Customer. Yours Could Be Bigger.

A reporter at Wired did something most of us never think to do. He asked McDonald’s to hand over everything it knew about him.

What came back was 515 pages long.

Not a summary. Not a tidy little profile. Five hundred and fifteen pages of his life as a customer — every order, every loyalty point, every promo offer, going back years. Even the codes he’d scanned for the McDonald’s Monopoly game were in there.

His name’s Reece Rogers, and he only got the file because he lives in California, one state where the law lets you demand your data.

But this story isn’t just about McDonald’s. This is happening everywhere you swipe, tap or scan a rewards app.

A file longer than most novels

So what’s in 515 pages? Pretty much everything.

Rogers’ file didn’t just log what he bought. It tried to predict his future. Wired reported McDonald’s had calculated he’d visit 2.16 times over the next six weeks, spend about $13.49 an order, and drop roughly $29 in that stretch.

It also estimated how likely he was to walk away and stop coming back. Several outlets reporting this story noted the file rivaled the size of the FBI’s old dossier on John Lennon.

To be fair, McDonald’s says this is standard for loyalty programs and helps it serve up more relevant deals, and that customers have privacy choices spelled out in its policy. Maybe so. But “everybody does it” isn’t exactly comforting. And, as all merchants know, very few people read data-collection policies.

This isn’t really about McDonald’s

Here’s the uncomfortable truth. If you carry a single rewards app, a store loyalty card or a gas-station points program, someone’s building a version of that file on you right now.

In my 35-plus years as a consumer reporter, I’ve watched companies invent new ways to squeeze a few more dollars out of their customers. This is one of the slickest yet. You trade your habits for a free fry now and then, and they use it to engineer your behavior.

It’s not just fast food. Retailers pull the same move — one national chain was recently accused of selling shopper data, and I recently broke down five sneaky ways stores cash in on you.

Hospitals have handed website-visitor data to outside firms without telling patients. Insurers have mined patient records for profit. Even a data leak this year put a scare into people about their Social Security records. It’s everywhere.

And when you try to opt out? Good luck. A Wired investigation found more than 30 data brokers had buried their opt-out pages so search engines couldn’t even find them.

Quick aside — most internet financial advice comes from people who weren’t alive during the last recession. I’ve been writing about money for more than 35 years. Want rock-solid advice? Sign up for the free Money Talks Newsletter. Takes 10 seconds. No fluff. No spam.

So what can you actually do? More than you’d think

Here’s where to start.

1. See exactly what a company has on you

You don’t have to live in California to fight back anymore. Twenty states now have comprehensive privacy laws on the books, and most give you the right to ask a company for a copy of the data it’s collected.

To see if your state’s on the list (more are added monthly), search your state attorney general’s website for “consumer privacy.” They’re the ones who enforce these laws, so if your state has one, there’ll be a page spelling out exactly what you’re owed.

Look for a company’s privacy center or “your privacy rights” page, usually buried in the website footer. Submit a request. Under California’s law, they’ve got 45 days to respond. Brace yourself for what shows up.

No law yet? You’ve still got option No. 3 below — it works everywhere.

2. Tell them to delete it

The same laws that let you see your file usually let you demand it be erased. Rogers asked McDonald’s to delete his. You can do the same.

If your personal details are also showing up in Google search results, there’s a separate process to get those pulled. And California residents can use a free state tool called DROP, which fires off deletion requests to registered data brokers on your behalf at consumer.drop.privacy.ca.gov.

It won’t stop companies from collecting fresh data going forward — but it clears out the years of history they’ve stockpiled. Start with the ones you’ve quit but never truly left.

3. Flip on the setting that opts you out automatically

This one’s free, and most people have never heard of it. It’s called Global Privacy Control, a browser signal that tells websites you don’t consent to having your data sold or shared.

In states like California, Colorado, Connecticut, New Jersey, Oregon and Texas, companies have to honor it. It’s built into Firefox and Brave, and you can add it to Chrome with an extension. Turn it on once and it works everywhere you go.

4. Think hard before you tap ‘join’

Every loyalty program is a trade. You get the deals; they get a permanent record of your life as a shopper. Sometimes that trade is worth it. Often it isn’t.

Before you sign up for one more app to save a buck, ask whether the discount’s worth becoming the product. For a lot of these programs, the honest answer is no.

The bottom line

You’re not paranoid. Companies really are keeping a file on you — and it’s fatter and creepier than you ever imagined.

The good news? For the first time, the law is starting to hand you the keys. You can see the file. You can wipe it. And you can make yourself a whole lot harder to track from here on out.

Reece Rogers had to become a 515-page cautionary tale to find that out. You don’t.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *