Back to the blog
SaaSDataPrivacy

Customer data: McDonald's 515-page dossier

August 26, 2026·6 min read·Diego Horvatti

A Wired reporter asked McDonald's for a copy of the data the company had on him. He got 515 pages back. He is not an employee, not a supplier, not an influencer. He is just a guy who downloaded the app to get free fries.

Five hundred and fifteen pages. From a fast food loyalty program. And here is the part that should bother more business owners: that mountain of customer data was not built by a spy team. It built itself, through ordinary tools, running the way they ship from the factory. The same tools probably running in your company right now.

What fits in 515 pages

It is not just "he bought a Big Mac in March". It is every app open. Every screen viewed. Every coupon that showed up, got clicked or got ignored. Time of day, rough location, phone model, OS version. Which notifications were sent and what he did after each one.

And buried in there, the most uncomfortable piece: an assessment that he was unlikely to ever leave. The system was not just taking notes. It was predicting.

This is not corporate evil. It is the default behavior of any modern SaaS stack. You install a loyalty app, an email tool, a site chat, an analytics tool, a CRM. Each one logs everything by default, because logging is cheap and because someone might want to look one day. Nobody chooses to keep it. Nobody chooses to stop, either.

Your business already has a version of this

You do not have 40 million customers. You have 300, 2,000, 15,000. And you probably have, without ever deciding to:

  • The full WhatsApp Business chat history, including voice notes of people complaining
  • Full name, ID number and address of someone who bought once in 2021
  • Session recordings of site visitors, if someone installed Hotjar or Clarity and forgot about it
  • A Drive spreadsheet called "customers_final_v3_UPDATED" that three former employees can still open
  • Saved cards in the payment gateway from accounts cancelled two years ago

None of that was a strategic decision. It was accumulation. And accumulation has a nasty property: it only shows up on the day something goes wrong.

Data you store and never use is not an asset. It is a stockpile of risk.

The email test: a customer asks for their data

Here is the exercise I recommend running this week, and that almost nobody runs.

Imagine an email arrives: "Under data protection law, I request a copy of all personal data you hold about me, and then its deletion."

You have 15 days to respond. That is what the law allows for a right of access request. And the practical question is: could you?

To answer, you would need to know:

  1. Which systems hold that customer's data. All of them, not the three you remember off the top of your head.
  2. Who has access to each one.
  3. How to export it in a readable format.
  4. How to actually delete it, including backups and integrations that copied the record somewhere else.

In most companies I see, item 1 already stalls it. Nobody has the inventory. Sales bought the CRM, marketing bought the email tool, finance bought the invoicing tool, and the booking app came from a freelancer who vanished. That is five partial copies of the same customer in five places that do not talk to each other.

The point is not fear of a regulator's fine. It is that if you cannot answer that question, you cannot answer any useful question about your customer data either.

The flip side: you have the data and never use it

Let us turn it around, because this part is more interesting.

McDonald's kept 515 pages and used them. It knew when the guy was about to stop buying. It knew which coupon worked on him and which one was wasted. It knew it did not need to give him a discount, because he was coming back anyway.

The average small company has a fraction of that data and uses zero percent of it. It sends the same Black Friday promo to the entire list, including people who bought at full price the day before yesterday. In other words: it pays to discount people who were already buying, and never talks to the ones who were one nudge away from coming back.

A real example at small scale. A clinic with about 1,200 patients in the system. The data was already there: date of last visit, procedure, amount. Nobody had cross-referenced it. We filtered for people who had a procedure with a recommended 6 month follow-up and had not come back after 9. That was 84 people. One message, written by hand, nothing that looked like a mass blast. Nineteen came back. No new technology, no system purchased. Just looking at what was already sitting there.

That is what stings. The data that exposes you in a breach is exactly the same data that would make money if anyone looked at it.

What to do over the next two weeks

No six month project. Three steps, in order.

1. Build the inventory. A spreadsheet, seriously. Columns: tool name, who bought it, what customer data it holds, who has access, monthly cost. Ask each team to list theirs. You will find two to four subscriptions nobody uses anymore that are still holding people's data. Cancel them.

2. Set expiration dates. For each type of data, decide how long it makes sense to keep it. A lead who never replied in 18 months: delete. Site session recordings: 30 days is plenty. Invoices: legal retention period applies, keep them. Most SaaS tools have automatic retention settings and ship with them turned off. Turn them on.

3. Pick one question and answer it with what is left. Just one. "Who bought once and never came back?" or "which channel brings customers who stay?". If answering that takes more than a day of work, the problem is not missing data. It is that the data is scattered too far.

"But I am small, nobody is going to attack me"

Attacks are almost never personal. They are automated sweeps looking for an open door, and a list of 2,000 customers with ID numbers is worth money on the grey market, proportionally, just like a list of 2 million. Besides, the bigger damage is usually mundane: the ex-salesperson who walked out on Friday with the whole list exported to a personal Gmail.

And there is the customer side. Nobody cares about privacy in the abstract. Everybody cares when they get a message that knows too much. The line between "what attentive service" and "how do you know that?" is thinner than it looks, and whoever crosses it does not get a complaint. They get silence and a block.

McDonald's can afford the 515 pages because it has lawyers, a data team and scale. You do not need any of that. You need the opposite: keep less, know exactly what you kept, and use the little that is left in a way that makes the customer grateful instead of uneasy.

If you just looked at your company's list of tools and could not say how many of them hold customer data, that is where to start. Tell me how your operation is running and we will see what can be sorted out first.

LinkedIn summary

A reporter asked McDonald's for the data the company had on him. He got 515 pages back.

He is not an employee. Not a supplier. He just downloaded the app to get free fries.

And here is the uncomfortable part: none of it was a strategic decision. It was ordinary tools running on factory settings. The same ones probably sitting in your company right now, holding WhatsApp threads, customer IDs from 2021 and a spreadsheet three former employees can still open.

Try this test this week: if a customer asked you today for a copy of everything you have on them, could you answer within 15 days?

In most companies I see, it stalls on the first question: which systems hold that customer. And then comes the irony. The same data that exposes you in a breach is the data that would make money if anyone actually looked at it.

If you cannot say how many of your tools hold customer data, that is where to start. Tell me how your operation is running.

#DataPrivacy #CustomerData #SmallBusiness #Privacy #Operations