Please update your privacy and cookie policies ahead of our next release.
Marketing 2.0 will roll out in phases through the remainder of the year, but the changes affecting your published policies will begin with the next release. We will confirm the release date separately, so please begin reviewing the updated templates now.
What Is Changing
AWS announced last year that it would retire Amazon Pinpoint. We currently use Pinpoint for three functions:
-
Managing marketing messages sent by email, SMS and push notification
-
Managing transactional messages, including order confirmations and service updates
-
Providing campaign and marketing analytics
Since the announcement, we have spent the past year designing and building Marketing 2.0 in-house.
It will replace the messaging-management functions currently provided through Pinpoint while retaining the interfaces and workflows you already use. The initial changes are to the underlying technology rather than how you access and manage messaging. AWS will continue to provide the delivery infrastructure for all email, SMS and push notifications.
Further improvements will be introduced over time, including more intuitive tools and new capabilities for creating, targeting and measuring campaigns.
The campaign and platform analytics currently provided through Pinpoint will move to PostHog. This separates message delivery from analytics and gives us a clearer view of how customers use the platform, how it performs across marketplaces and where Redbox can be improved.
Our next release will also introduce:
-
Google Analytics 4 Ecommerce Tracking
-
Google Consent Mode v2
-
Meta Advanced Matching
-
Google Ads Enhanced Conversions
-
UTM Campaign Attribution
-
Deep Linking
These changes are explained in more detail below and are reflected in the updated privacy and cookie policy templates.
Our existing policy templates predate these technologies. Once the release is deployed, any marketplace continuing to use the previous policies may be collecting or sharing information in ways that its published policies do not fully describe.
We have therefore published updated templates so that each marketplace can review and implement the necessary changes before release.
How the Data-Protection Roles Apply
Redbox acts as an independent data controller where it processes personal information for its own platform purposes. Platform analytics is one such activity.
Redbox will use PostHog across the marketplaces it powers to understand platform usage, monitor performance and improve the Redbox platform as a whole. For this specific activity, Redbox determines the purpose of the processing and acts as a separate data controller rather than as the marketplace’s processor.
What is changing is the analytics technology and the information that needs to appear in your published privacy and cookie policies.
The updated templates explain:
-
What information is processed
-
Why it is processed
-
The lawful basis for the processing
-
How long the information is retained
-
How customers can exercise their rights directly with Redbox
For transactional and marketing messages sent by email, SMS and push notification, Redbox continues to process personal information on your behalf as your processor.
Although the messaging-management technology will change as Pinpoint is retired, Redbox’s role as your processor for these activities remains the same. AWS will continue to provide the underlying message-delivery infrastructure.
We will notify you if a later phase changes these processing arrangements.
Summary of the Policy Changes
-
Analytics and advertising services are identified individually. Google Analytics 4, the Meta pixel, Meta Advanced Matching, Google Ads Enhanced Conversions and PostHog are each described separately instead of being covered by a general reference to analytics providers.
-
Consent is described more accurately. Before a customer responds to the cookie banner, only essential storage is used. Measurement operates without analytics or advertising cookies, using a temporary identifier that changes regularly and is not used to create a persistent customer profile. Completed order information is still provided to Google Analytics for ecommerce reporting, as explained in the updated policies.
-
Hashed customer information is explained. Where a customer has accepted cookies, a securely hashed version of their name, email address and telephone number may be provided to Google and Meta to measure advertising performance. The original information is converted into the hashed value within the customer’s browser before transmission.
-
Apps and kiosks are addressed separately. Tracking within an app is governed by Apple’s App Tracking Transparency framework or the relevant Android advertising setting rather than the website cookie banner. On self-service kiosks and other Redbox-operated in-store devices, only PostHog analytics operates. The previous templates did not address these environments separately.
-
UTM campaign attribution is introduced. Campaign links can include standard labels identifying the source, channel and campaign. These labels are retained through the website ordering journey and associated with analytics events, including completed orders. This allows marketplaces to understand which campaigns generate traffic, orders and revenue. UTM values must not contain customer names, email addresses, telephone numbers or other personal information.
-
Campaign deep links are supported. Links used in email, SMS, social media, advertising, push notifications and QR codes can direct customers to a relevant marketplace destination, such as an outlet, menu item, category or account screen. Where supported, the same link can open the marketplace app if it is installed or continue to the website if it is not. Campaign attribution can be retained across the journey where the relevant platform supports it.
-
Session recording capability is covered. PostHog includes session recording functionality that Redbox may use, with the customer’s consent, to understand how the platform is used and identify areas for improvement. Form inputs are masked and are not visible within recordings. Where this capability is used, recordings are retained for up to three months.
What You Need to Do
Please complete the following steps ahead of the release:
-
Open the updated privacy and cookie policy templates using the links below.
-
Select ‘Use with AI’, followed by ‘Copy as Markdown’.
-
Paste the complete policy into your preferred document editor or drafting tool. Its headings, lists and links will be retained.
-
Replace every yellow-highlighted field with the relevant marketplace information.
-
Remove any sections that do not apply to your marketplace.
-
Confirm that the policies accurately reflect how your marketplace operates.
-
Arrange an independent legal review where required.
-
Publish the updated policies before the release date in Redbox Management > Marketplace > Legal.
We will confirm the release date separately. Please begin your review now, particularly where your own legal advisers need to approve policy changes.
Please note
The templates are provided for general guidance only and do not constitute legal advice. Each marketplace remains responsible for ensuring that its published policies accurately describe its activities and comply with applicable law.