All Vendors
call_tracking

Marchex

Call tracking provider with aggressive pre-consent behavioral capture and session recording capabilities.

110 IOCs1 detections100% pre-consent1 sites
70
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Marchex discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

1 detection across 1 site100% pre-consent activity
CRITICAL

Pre-Consent Activity

Marchex was observed loading and executing before user consent was obtained on 100% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

disclosure

HIGH
They Claim

Pending claims extraction

Observed Behavior

High Broker score (50) and Counselor score (70) indicate significant undisclosed data sharing and consent violations. Behavioral biometrics and session recording likely not mentioned in privacy policy.

Customer Impact

What This Means For You

Sales teams lose call attribution visibility if Marchex is removed. Marketing cannot connect phone conversions to campaigns. However, retention creates liability: class action exposure for voice biometric collection without BIPA compliance, regulatory fines for processing special category data pre-consent, reputational damage if call recordings leak containing customer PII.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Marchex

  • Immediate consent gate implementation before any Marchex script loads
  • BIPA compliance review for voice biometric processing
  • Data Processing Agreement audit for call recording retention and third-party sharing
  • Explicit opt-in for voice analysis separate from general marketing consent

If You're Evaluating Marchex

  • Defer all Marchex scripts until post-consent confirmation
  • Require vendor attestation on biometric data processing lawfulness
  • Implement call recording disclosure on every phone interaction
  • Consider privacy-respecting call tracking alternatives without session recording

Negotiation Leverage

  • Marchex contract likely permits third-party data sharing for "service improvement" - demand explicit prohibition
  • Voice recordings may be retained indefinitely - negotiate 30-day maximum retention aligned to attribution window
  • Request evidence of BIPA compliance in Illinois, GDPR Article 9 lawful basis documentation for EU visitors
  • Confirm whether behavioral biometric models are trained on your call data - demand opt-out and model deletion rights
Runtime Detections

Runtime Detections

3 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C09Consent Bypass

Ignoring CMP signals

IOC Manifest

IOC Manifest

106 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.marchex.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/js/auto-dealer.js*
Tracking script
TRACK
*www.marchex.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/vendors/match-height/jquery.matchHeight.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/vendors/counter/jquery.waypoints.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/vendors/counter/jquery.countup.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/js/script.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/vendors/slick/slick.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/vendors/fancybox/jquery.fancybox.js*
Tracking script
TRACK
*www.marchex.com/wp-content/themes/ss_theme/theme/js/search.js*
Tracking script
TRACK
*www.marchex.com/wp-includes/js/hoverIntent.js*
Tracking script
TRACK
*www.marchex.com/wp-content/plugins/megamenu/js/maxmegamenu.js*
Tracking script
TRACK
*www.marchex.com/wp-content/plugins/sassy-social-share/public/js/sassy-social-share-public.js*
Tracking script
TRACK
*www.marchex.com/wp-includes/js/wp-emoji-release.js*
Tracking script
TRACK
www.marchex.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/js/auto-dealer.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/vendors/match-height/jquery.matchHeight.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/vendors/slick/slick.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/vendors/fancybox/jquery.fancybox.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/vendors/counter/jquery.waypoints.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/vendors/counter/jquery.countup.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/js/script.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/themes/ss_theme/theme/js/search.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/plugins/sassy-social-share/public/js/sassy-social-share-public.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-includes/js/hoverIntent.min.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-content/plugins/megamenu/js/maxmegamenu.js
Auto-extracted from scan
TRACK
www.marchex.com/wp-includes/js/wp-emoji-release.min.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Marchex integrates with call center platforms, marketing automation systems, and advertising networks. Voice data flows to analytics warehouses where it merges with web behavioral profiles. Often deployed alongside other pre-consent trackers that benefit from shared phone number linkage.
Loads (1)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

110 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details