Skip to main content
    All Blog articles
    Data & Privacy
    13 min read

    The Company That Knew You Were "Wealthy and Not Healthy" (And Sold That to Advertisers)

    InMarket tracked 100 million devices per year, categorizing Americans into segments like "Wealthy and not healthy" based on their medical visits. The FTC issued its first-ever blanket ban on selling precise location data.

    Author
    By Catherine “Cat” Karow
    Published
    Published January 10, 2025
    Updated
    Updated May 10, 2026
    Data & Privacy

    ZoraSafe Blog

    The Company That Knew You Were "Wealthy and Not Healthy" (And Sold That to Advertisers)

    The Data Brokers: InMarket

    Article 11: The Company That Knew You Were "Wealthy and Not Healthy" (And Sold That to Advertisers)

    Series: The Data Brokers | The Shield Blog


    Reading time: 13 minutes


    The Pitch

    Imagine you're an advertiser looking to sell a new medication.

    You don't just want to reach "health-conscious consumers." You want to reach people who have actually visited cardiologists. People who've been to pharmacies. People who go to church on Sundays (religious folks tend to respond well to family-oriented messaging, after all).

    You want to know who's a parent of preschoolers. Who attends political rallies. Who visits fast food restaurants versus organic grocery stores.

    And you want to target them with ads the moment they walk within 200 meters of a store where they might buy your product.

    This is what InMarket sold.

    The Texas-based data aggregator built one of the most comprehensive consumer surveillance systems in the advertising industry—tracking the real-time movements of over 100 million devices per year and categorizing Americans into nearly 2,000 audience segments based on where they went, what they bought, and who they appeared to be.

    One of those segments was called "Wealthy and Not Healthy."

    The FTC had questions.


    The Origin Story

    InMarket was founded in 2010 by brothers Todd and Mark Dipaola as CheckPoints—a mobile app that offered shopping rewards for completing tasks like watching videos, taking quizzes, and scanning product barcodes in stores.

    The value proposition for consumers was simple: earn points, get rewards.

    The value proposition for InMarket was even simpler: every time users scanned a product or walked into a store, they were handing over their precise location.

    By 2012, the company rebranded as InMarket and pivoted from a consumer app company to something bigger: a data aggregation platform that could track consumers across hundreds of apps and sell that intelligence to advertisers.

    Over the next decade, InMarket grew through aggressive acquisitions:

    • 2016: Acquired ThirdChannel (retail execution and analytics)
    • 2019: Acquired ThinkNear from Telenav (location marketing platform GeoLink)
    • 2020: Acquired NinthDecimal (location attribution and analytics)
    • 2020: Acquired Key Ring (loyalty app)
    • 2021: Acquired Out of Milk (shopping list app)

    By 2020, InMarket claimed $100 million in annual revenue, 200+ employees, and partnerships with major brands including Coca-Cola, Procter & Gamble, and Unilever.

    The company positioned itself as "the definitive leader in real-time, data-driven marketing."

    What it was actually leading was one of the most invasive consumer tracking operations in America.


    How It Worked

    InMarket operated through two primary channels:

    1. Its Own Apps

    InMarket owned and operated several consumer apps:

    • CheckPoints: Shopping rewards for completing tasks (30+ million downloads since 2017)
    • ListEase: Helps consumers create shopping lists
    • Key Ring: Stores loyalty cards digitally
    • Out of Milk: Another shopping list app

    These apps all requested location access—and users generally granted it, assuming the data would be used to provide relevant shopping rewards or remind them about items on their lists.

    2. Third-Party Apps via SDK

    InMarket created the InMarket SDK—a software development kit that third-party app developers could embed in their apps.

    In exchange for including the SDK, developers got a cut of InMarket's advertising revenue from each ad served through their app.

    The SDK was embedded in more than 300 third-party apps, which were downloaded onto over 390 million unique devices.

    Here's what the SDK did: "If the user allows access, InMarket SDK receives the device's precise latitude and longitude, along with a timestamp and a unique mobile device identifier, as often as the mobile device's operating system provides it—ranging from almost no collection when the device is idle, to every few seconds when the device is actively moving—and transmits it directly to [InMarket's] servers."

    Every few seconds. While you're moving. For years.


    The Audience Segments

    InMarket didn't just collect location data. It combined that data with:

    • Purchasing histories
    • Demographic information
    • Socioeconomic data
    • Other third-party data sources

    Then it used algorithms and machine learning to categorize consumers into nearly 2,000 audience segments.

    The FTC's complaint highlights some of these segments:

    • "Parents of preschoolers"
    • "Christian church goers"
    • "Wealthy and not healthy"

    Think about what it takes to build a segment called "Wealthy and not healthy."

    InMarket would track that your device frequently appears at addresses in high-income neighborhoods (wealthy). Then it would note that your device regularly appears at medical facilities—cardiologists, endocrinologists, pharmacies, maybe even specialty infusion centers (not healthy).

    Cross-reference those signals. Add some demographic data. Confirm with purchasing behavior.

    Now you're in a segment. And advertisers can target you specifically.


    The Geofencing

    InMarket offered advertisers a product that sent push notifications based on a consumer's real-time location and "geofencing"—the creation of virtual boundaries around physical locations.

    Here's how the FTC described it: "For example, a consumer who was within 200 meters of a pharmacy might have seen an ad for toothpaste, cold medicine, or similar products."

    This sounds almost benign. Convenient, even.

    But consider the implications.

    If InMarket could geofence a pharmacy, it could geofence:

    • An abortion clinic
    • An addiction recovery center
    • A political rally
    • A union hall
    • A place of worship
    • A domestic violence shelter

    And it could trigger ads—or sell that visitation data to third parties—the moment you crossed the virtual fence.

    The FTC noted that InMarket's data could reveal: "where consumers live and work, where they attend religious services, the locations of the schools their children attend, and what medical providers consumers use."


    The Deception

    The core of the FTC's case against InMarket was that consumers never knew what was really happening with their data.

    The Half-Truth Consent Screens

    When iOS users downloaded CheckPoints, the app asked: "Allow CheckPoints to access your location? This allows us to award you extra points for walking into stores."

    True. But incomplete.

    When Android users downloaded ListEase, the app said: "Allow Location Permissions to unlock reminders. Get a reminder when you're in the store so you never forget to grab the items you need!"

    Also true. Also incomplete.

    What neither consent screen mentioned:

    • That location would be tracked "often multiple times per hour"
    • That location data would be combined with data from other sources
    • That users would be profiled into audience segments
    • That those profiles would be sold to advertisers
    • That data would be retained for five years

    The FTC's conclusion: "Consent to one use without an explanation of other uses is no consent at all."

    The Third-Party Failure

    InMarket didn't just fail to inform users of its own apps. It failed to require that third-party app developers using its SDK obtain proper consent either.

    The company didn't tell app developers that InMarket would combine location data with other data to create consumer profiles. Developers couldn't disclose what they didn't know.

    And InMarket's contracts with developers? They only stated that InMarket would serve ads in exchange for user data transmission. No mention of profiling, no mention of audience segments, no mention of the vast data combination happening behind the scenes.


    The Retention Problem

    The FTC alleged that InMarket retained consumer geolocation data for five years.

    Five years of knowing everywhere you went. Every church. Every doctor. Every bar. Every protest. Every late-night drive to somewhere you'd rather not explain.

    The FTC found this retention period "far longer than reasonably necessary to accomplish the purpose for which the data was collected."

    The longer data is retained, the greater the risk of:

    • Data breaches exposing years of movement history
    • Misuse by employees or contractors
    • Sale to parties who shouldn't have it
    • Subpoenas by law enforcement or civil litigants

    InMarket argued it needed the data for analytics and attribution. The FTC disagreed.


    The FTC Action

    On January 18, 2024, the Federal Trade Commission announced a proposed settlement with InMarket Media.

    The complaint alleged that InMarket violated Section 5 of the FTC Act through:

    1. Unfair collection and use of consumer location data from its own apps
    2. Unfair collection and use of consumer location data from third-party apps
    3. Unfair retention of consumer location data
    4. Deceptive failure to disclose InMarket's use of consumer location data

    For each unfairness claim, the FTC asserted that InMarket's practices resulted in "substantial injury in the form of a loss of privacy about the day-to-day movements of millions of consumers and an increased risk of disclosure of such sensitive information."

    The settlement was finalized in May 2024 with a 3-0 vote.


    The Settlement Terms

    The FTC's order imposed the agency's first-ever blanket prohibition on selling or licensing precise location data:

    Banned from selling location data:

    InMarket is prohibited from "selling, sharing or licensing any precise location data and any product or service that categorizes or targets consumers based on sensitive location data."

    This is a complete ban. Not just sensitive locations—all precise location data.

    Required to delete previously collected data:

    InMarket must "delete or destroy all the location data it previously collected and any products produced from this data" unless it obtains consumer consent or ensures the data has been de-identified.

    Five years of location history. Gone. (In theory.)

    Required to provide easy opt-out:

    InMarket must provide "a simple and easy-to-find way for consumers to withdraw their consent for the collection and use of their location data" and a mechanism to request deletion of previously collected data.

    Required to notify affected consumers:

    InMarket must notify consumers whose location data was collected through its apps about the FTC's action and provide them with a way to opt out or request deletion.

    Required to create a sensitive location data program:

    InMarket must implement a program to prevent the company from using, selling, or sharing any products or services based on sensitive location data.

    Required to establish a comprehensive privacy program.


    The Company's Response

    InMarket issued a statement: "We fundamentally disagree with the FTC's allegations. Notably, the FTC does not claim there were any issues with our privacy policy nor any specific instances of consumer harm."

    The company added: "We have no interest in selling consumer location data, and we have confirmed we will not do so."

    It's worth noting that InMarket's business model was built on monetizing location data for targeted advertising. The company's stated "disinterest" in selling that data came only after the FTC forced its hand.

    InMarket also claimed it was "expanding its existing sensitive location protections for consumers to provide a model for the industry."

    The industry that InMarket helped create.


    Why InMarket Matters

    The InMarket case illustrates several critical truths about consumer surveillance:

    1. "Free" apps aren't free.

    When you download a shopping rewards app or a list-making tool, you're often paying with something more valuable than money: your location history. InMarket's apps offered small rewards while harvesting data worth far more.

    2. Consent screens are designed to deceive.

    InMarket's consent screens told users just enough to get them to tap "Allow." They omitted the vast machinery of tracking, profiling, and sale happening behind the scenes. This is the industry standard.

    3. You're not just being tracked—you're being categorized.

    InMarket didn't just know where you went. It used that information to decide who you are. Parent. Christian. Wealthy. Unhealthy. These labels followed you across the advertising ecosystem.

    4. Data retention is a ticking time bomb.

    Five years of location data is five years of vulnerability. Every breach, every subpoena, every bad actor who gains access has half a decade of your movements to exploit.

    5. Enforcement comes too late—but it sets precedent.

    The FTC's first-ever ban on selling precise location data is significant. It signals that the agency views this practice as inherently harmful, not just when done badly.


    The Bigger Picture

    InMarket was the FTC's second location data enforcement action in two weeks, following X-Mode/Outlogic.

    Since then, the agency has also taken action against:

    • Gravy Analytics/Venntel (December 2024)
    • Mobilewalla (December 2024)

    The pattern is clear: the FTC is systematically targeting the location data industry.

    But InMarket is not unique. The company's practices—SDKs embedded in apps, deceptive consent screens, audience segmentation, geofencing, data retention—are standard across the industry.

    For every InMarket the FTC catches, there are dozens more doing the same thing.


    Protecting Yourself

    Here's what you can do:

    1. Be suspicious of "rewards" apps.

    If an app offers points or rewards for seemingly simple tasks, ask yourself: what's the real product being sold? Usually, it's you.

    2. Don't grant location access unless absolutely necessary.

    Most apps that request location don't need it—or don't need it "Always." Set permissions to "Never" or "While Using the App" and see if the app still works.

    3. Audit your installed apps.

    Go through your phone and delete apps you don't actively use. Each dormant app is potentially still tracking you.

    4. Reset your advertising ID regularly.

    On iPhone: Settings > Privacy & Security > Tracking > Toggle off "Allow Apps to Request to Track"

    On Android: Settings > Privacy > Ads > Delete advertising ID

    5. Read the full privacy policy—or assume the worst.

    If a consent screen tells you location will be used for one purpose, assume it's also being used for others. The half-truth is the industry standard.

    6. Support privacy legislation.

    Meaningful reform requires laws that ban this behavior industry-wide, not just FTC enforcement actions against individual companies.


    The Bottom Line

    Todd Dipaola founded CheckPoints to help shoppers earn rewards. Fourteen years later, his company had tracked the movements of 100 million Americans, categorized them into segments like "Wealthy and not healthy," and sold that intelligence to advertisers eager to target vulnerable populations.

    When users agreed to share their location for shopping rewards, they didn't agree to years of surveillance. They didn't agree to be profiled by their medical visits. They didn't agree to have their data combined with dozens of other sources to build a comprehensive dossier on their lives.

    But that's what happened. Because in the surveillance economy, consent is a technicality. What you think you agreed to and what you actually agreed to are two different things.

    InMarket knew where you went to church. Where your kids went to school. What doctors you visited. And it sold that knowledge to anyone willing to pay.

    The FTC finally said no.

    But for 100 million Americans, the damage was already done.


    Cat Karow is the CEO of ZoraSafe, an AI-powered cybersecurity platform protecting families and seniors from scams and digital threats. She has 20+ years in cybersecurity, including roles at Apple, the White House OCIO, and GuidePoint Security. Follow The Shield Blog for more investigations into the companies that profit from your data.


    Sources:

    • Federal Trade Commission, "FTC Order Will Ban InMarket from Selling Precise Consumer Location Data" (January 18, 2024)
    • Federal Trade Commission, "FTC Finalizes Order with InMarket Prohibiting It from Selling or Sharing Precise Location Data" (May 1, 2024)
    • Federal Trade Commission, Complaint: In the Matter of InMarket Media, LLC
    • FTC Business Blog, "How 'location, location, location' can lead to 'enforcement, enforcement, enforcement'" (January 2024)
    • FTC Tech@FTC Blog, "FTC Cracks Down on Mass Data Collectors: A Closer Look at Avast, X-Mode, and InMarket" (March 20, 2024)
    • The Record, "FTC settles second case with geolocation data broker in two weeks" (January 18, 2024)
    • WilmerHale, "Recent Enforcement Actions Signal FTC Focus on Protecting Location Data" (February 9, 2024)
    • Arnold & Porter, "FTC Poised to Ban Data Broker From Selling and Licensing Precise Geolocation Data" (January 2024)
    • The Hacker News, "FTC Bans InMarket for Selling Precise User Location Without Consent" (January 22, 2024)
    • Hunton Privacy Blog, "FTC Bans Data Broker from Selling Precise Consumer Location Data" (January 2024)
    • PRNewswire, "InMarket Acquires Assets from NinthDecimal" (September 9, 2020)
    • MediaPost, "InMarket CEO Says NinthDecimal Acquisition Will Push Revenue To $100M" (September 10, 2020)
    • Search Engine Land, "InMarket buys NinthDecimal to compete with Foursquare more effectively" (September 2020)
    • Crunchbase, "Todd Dipaola - CEO and Cofounder @ InMarket"
    • EverybodyWiki, "InMarket"

    Next in the series: "The Data Broker Ecosystem: How All These Companies Connect (And What You Can Do About It)"


    Tags: #DataBrokers #LocationTracking #InMarket #FTC #Privacy #AudienceSegmentation #Geofencing #Surveillance #DataPrivacy #ConsumerProtection #TargetedAdvertising

    Share this article

    Share: