Remove Your Address From Mosaic Records' Mailing List

The Privacy Risk Behind a Mosaic Records Order

Picture a retiree filling out a mail-in order form for a limited-edition jazz box set — a name, a shipping address, sometimes a phone number, written by hand and mailed off to a company they've never dealt with online. Weeks later, catalogs start arriving from other specialty retailers that customer never contacted directly, and eventually a piece of mail shows up asking to "verify" account details tied to a recent order. That small paper trail — a name and address sitting in a mail-order company's customer file — is the raw material behind a much larger pattern: in 2023, Americans age 60 and older reported $3.4 billion in losses to the FBI's Internet Crime Complaint Center — 101,068 complaints, an average loss of $33,915, up roughly 11% from the year before (FBI IC3 2023 Elder Fraud Report). That figure is the backdrop for why a name and address sitting in any mail-order company's customer file is worth taking seriously, regardless of what the company itself promises to do with it.

Mosaic Records is an American jazz record company and label established in 1982 by Michael Cuscuna and Charlie Lourie. It produces limited-edition box sets sold only by mail, leasing recordings from major record companies — typically for a three- to five-year period — and pressing each edition to a limited count, typically 5,000 copies. Every one of those orders requires a name and a physical shipping address, which means every order creates a customer-file record whether or not the buyer thinks about it that way.

Physical mail remains part of the identity-theft threat landscape for a reason that has nothing to do with any single catalog. The FTC's guidance on how to stop junk mail treats mailing-list participation — not any individual mailer — as the underlying driver of unwanted mail volume, and notes that meaningfully reducing exposure requires opt-outs at multiple registry levels rather than discarding each piece as it arrives. For the broader mechanics of how catalog mailing-list data circulates and connects to identity-theft exposure across categories, see Catalog Mail and Identity Theft Risk. This page focuses on what Mosaic Records specifically discloses about its own data practices, where that disclosure has gaps, and what to do about it.

What Mosaic Records Says About Your Data

Mosaic Records' privacy policy is more restrictive than many catalog retailers'. It states plainly that the company does not ask for personal information it doesn't need, does not share personal information "with anyone except to comply with the law, develop our products, or protect our rights," and does not store personal information on its servers beyond what's required to run the site. The policy separates two categories of data: non-personally-identifying information collected automatically from any website visitor (browser type, language preference, referring site, and the date and time of a visit), and personally-identifying information collected only when a visitor interacts directly — a username and email address from someone commenting on the company's blog, or an email address from someone who signs up for updates. The policy states outright that Mosaic Records "does not share, rent or in any way disclose e-mails."

On disclosure, the policy says personally-identifying information goes only to employees, contractors, and "affiliated organizations" that need it to operate the business and that have agreed not to disclose it further — with a note that some of those parties may be located outside a customer's home country. Beyond that circle, the policy states Mosaic Records "will not rent or sell potentially personally-identifying and personally-identifying information to anyone," and that any other disclosure happens only in response to a subpoena, court order, or other governmental request. The site also uses cookies to track visitor behavior and preferences.

The Gaps a "We Don't Sell Your Data" Policy Doesn't Close

A policy that rules out renting or selling data to marketers is a real commitment, and it's a stronger stance than several catalog retailers put in writing. But two clauses in the same policy describe circumstances where a customer's information can still end up somewhere new.

The first is the Business Transfers clause. The policy states that if Mosaic Records — or substantially all of its assets — were acquired, or if the company goes out of business or enters bankruptcy, "user information would be one of the assets that is transferred or acquired by a third party," and that any acquirer "may continue to use your personal information as set forth in this policy." That's a meaningful qualifier: the no-sale promise travels with the data to a new owner, but the new owner's actual security practices, business model, and interpretation of that same policy are not something a customer who placed an order years earlier has any way to evaluate in advance.

The second is the Ads clause. The policy discloses that ads appearing on the site "may be delivered to users by advertising partners, who may set cookies" to recognize a visitor's computer and "compile information about you or others who use your computer" for targeted advertising — and it states directly that its own privacy policy "does not cover the use of cookies by any advertisers." In other words, the no-share commitment applies to Mosaic Records' own conduct; it does not extend to whatever separate tracking practices a third-party ad network runs on the same page.

Neither clause is unusual for a small e-commerce operation, and neither amounts to evidence that Mosaic Records mishandles customer data. But both are worth knowing before assuming "we don't sell your information" closes every path an address can travel. And the policy, as written, addresses data collected through the website — browser activity, blog comments, email sign-ups — without separately spelling out how a printed mail-order catalog list, the thing that put the company's name on the map in the first place, is managed or retained.

What to Do: Opt Out and Protect Yourself

  1. Contact Mosaic Records directly. Use the contact page email form, or call 203-327-7111, to ask what mailing-list or account data the company holds and to request removal. Mosaic Records' mailing address is PO Box 113475, Stamford, CT 06911. A direct request addresses your specific record; it does not undo any disclosure already made under the policy's subpoena or business-transfer provisions.

  2. Register with DMAchoice to cut catalog volume broadly. Per the FTC's junk-mail guidance, registering through DMAchoice — operated by the Association of National Advertisers — costs $6 online and lasts 10 years; it stops most, though not all, promotional mail from participating companies. This addresses catalog volume across retailers generally, not just Mosaic Records.

  3. Opt out of prescreened credit and insurance offers. The same FTC guidance lays out two options through optoutprescreen.com or by calling 1-888-5-OPT-OUT (1-888-567-8688): a five-year opt-out, or a permanent one that requires signing and returning a form after starting the process online or by phone.

  4. Consider a mail-management app for mailers a registry doesn't reach. Services like PaperKarma let you request removal from unwanted catalogs and solicitations without contacting each sender individually.

  5. Shred mail bearing your full name, address, and any order or account reference number before disposal. Use a cross-cut shredder — strip-cut models don't adequately prevent reconstruction.

  6. Consider a security freeze at the major credit bureaus. A freeze prevents new accounts from being opened in your name without explicit authorization and has no effect on existing accounts or credit scores.

Signs Your Information Has Been Shared

A sudden increase in catalogs or solicitations from adjacent collectible-music, specialty-media, or hobbyist retailers you never contacted is a common sign an address has entered a broader mailing-list pool through some channel other than the retailer that originally collected it. An uptick in prescreened credit-card or insurance offers is a general indicator of active participation in the credit-bureau prescreen system, independent of any single catalog.

Any mailing that asks for financial account numbers, a Social Security number, or account details in response to an unsolicited piece should be treated as a fraud attempt — no legitimate retailer or financial institution requests that information by mail without a prior application or account relationship.

Frequently Asked Questions

Can Mosaic Records legally share my mailing address with third parties?

Mosaic Records' own privacy policy states it will not rent or sell personally-identifying information to anyone, and shares it only with employees, contractors, and affiliated organizations bound not to disclose it further, or in response to a subpoena or court order. That's a company-specific commitment rather than a legal guarantee — U.S. law generally permits retailers to share mailing-list data unless their own policy says otherwise, which is exactly why the wording of a company's stated policy matters.

What happens to my data if Mosaic Records is sold or goes out of business?

The privacy policy's Business Transfers clause states that if the company or substantially all of its assets are acquired, or if it enters bankruptcy, customer information is one of the assets that transfers to the new owner, who "may continue to use your personal information as set forth in this policy." The commitment travels with the sale, but a new owner's actual practices are not something you can verify in advance.

Does Mosaic Records' privacy policy cover its printed mail-order catalog?

The policy's specifics — non-personally-identifying browser data, blog-comment usernames and emails, email sign-ups — describe information collected through the website. It does not separately address how a physical mailing-list record tied to a mail-order box-set purchase is retained or managed, which is a gap worth raising directly with the company through its contact page if it concerns you.

Does shredding a Mosaic Records catalog protect my identity?

Shredding destroys the physical document already in hand, preventing it from being reconstructed if recovered from recycling or trash before disposal. It doesn't stop a future mailing or remove your address from any list that already exists. The FTC's junk-mail guidance treats shredding and registry-based opt-outs as complementary steps, not substitutes for each other.

References

Posts in this series