Draft — pending legal review. Not yet binding. Do not publish or link from a live signup flow.

Privacy Policy

This explains what we collect, why, how long we keep it and what you can do about it. It covers two very different groups of people, and it says which is which — because a policy that blurs them is not telling either group anything useful.

1. Who this covers

2. Who we are

LEGAL: full registered entity name, company number, registered address, and the identity of the data controller. If you appoint an EU/UK representative or a Data Protection Officer, name them here with contact details.

Privacy contact: [email protected]

3. If you hold an account

What we collect

What we do with it

Run your account, serve and bill your campaigns, give you reporting, provide support, prevent fraud and abuse, meet our tax and accounting obligations, and tell you about things that materially affect your account. LEGAL: if you intend to send marketing email to account holders, say so here and describe the opt-out.

4. If you were shown one of our ads

When an advertising opportunity is offered to us, we receive information from the publisher or supply partner about the context, decide in a few milliseconds whether one of our advertisers wants it, and respond. What we keep from that is a record of the opportunity and the outcome.

What is recorded

5. What we deliberately do not keep

We do not store your IP address in our advertising records. It is used at the moment of the request to work out approximate location, connection type and network, and it is not written to our reporting systems. Our per-auction records contain no IP address field at all.

We also do not collect or store: your name, email address, phone number, postal address, payment details, precise GPS location, contacts, photos, or the content of anything you type on a publisher's site.

We do not knowingly build profiles about special-category matters — health, religion, sexual orientation, political opinions, ethnicity or trade union membership — and advertisers are prohibited from targeting on them. LEGAL: if you ever permit adult, gambling, dating or health verticals, revisit this sentence; inventory category can imply inference even when you do not target on it.

Note that approximate location, device signals and network identity can still be personal data under laws such as the GDPR, even without your name. We treat them as such.

6. Why we are allowed to process it

LEGAL: confirm this mapping with counsel for each territory you operate in.

WhatLawful basis (GDPR/UK GDPR)
Running an account holder's accountPerformance of a contract
Terms acceptance record, tax and accounting recordsLegal obligation
Fraud prevention, security, invalid-traffic detectionLegitimate interests
Aggregated reporting and product improvementLegitimate interests
Serving and measuring personalised advertisingConsent, where required — obtained by the publisher or its consent platform before the opportunity reaches us

How consent reaches us. We are not on the page when you arrive, so we cannot ask you directly. We rely on the publisher and its consent management platform to obtain consent where the law requires it, and to pass us the resulting signal. Our terms require advertisers and supply partners to comply with applicable privacy law.

LEGAL: this is the highest-risk paragraph in the document. Confirm whether the platform reads and enforces the transmitted consent signal — for example the IAB Transparency and Consent Framework string, or the US privacy string — before asserting reliance on it. If those signals are not yet enforced in the bid path, this paragraph overstates the position and must be narrowed until they are.

7. How long we keep things

These are the actual retention periods configured in our systems, not aspirations.

DataKept forWhy
Opportunities we declined to bid on7 daysShort-term troubleshooting only
Per-auction records (bids we made)90 daysBilling detail, dispute resolution, fraud investigation
Impression, win and click records90 daysAs above
Hourly aggregated reporting180 daysTrend reporting
Daily aggregated reporting2 yearsYear-on-year reporting
Conversion recordsIndefinitelyLong-horizon performance analysis for the advertiser
Account recordsLife of the account, then LEGAL: state the periodContract, then tax and audit obligations
Terms acceptance recordAs long as needed to evidence the agreementLegal obligation and defence of claims

Indefinite conversion retention needs a decision. It is genuinely useful to advertisers, and each record is limited to the fields in section 4 with no direct identifiers. But "indefinitely" is difficult to defend against the GDPR storage-limitation principle without a stated justification and review. LEGAL: either set a maximum period (for example 25 months, matching common analytics practice) or document why an indefinite period is necessary and proportionate. This is a configuration change, not a redesign.

8. Who we share with

We do not sell personal information for money. Note that some US state laws define "sale" and "sharing" broadly enough to cover cross-context behavioural advertising. LEGAL: determine whether your activity is a "sale" or "sharing" under the CCPA/CPRA and equivalents, and if so provide a "Do Not Sell or Share My Personal Information" mechanism — that is a legal requirement with a specific link and title.

9. Cookies and identifiers

On our own website and platform we use only what is necessary: a session cookie to keep you signed in and a token to protect against cross-site request forgery. Our marketing site loads no third-party scripts and sets no advertising cookies.

In advertising we may set a first-party identifier cookie named dsp_uid on our own measurement domain, with a one-year lifetime, used to limit how often you see the same advertisement and to measure whether a click led to a conversion. We also recognise an opt-out cookie named dsp_optout.

LEGAL / ENGINEERING: do not publish this section as-is. The opt-out endpoint currently sets dsp_optout and tells the visitor they will no longer be tracked, but nothing in the bidding path reads that cookie yet (see TODO.md). Telling a person their opt-out has taken effect when it has not is a materially false statement to a data subject exercising a choice.

Fix one of two ways before launch: honour dsp_optout in the bid and serve path, or change what the opt-out page says until you do. This document deliberately does not claim the opt-out currently stops personalisation.

Your browser and operating system also offer controls — blocking third-party cookies, resetting or limiting your advertising identifier on mobile, and private browsing. Those work regardless of anything we do.

10. Your choices

11. Your rights

Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict processing, to withdraw consent, to receive a copy in a portable form, and not to be discriminated against for exercising any of these.

Write to [email protected] and we will respond within the period the law requires (one month under the GDPR, 45 days under the CCPA).

An honest limitation. For people shown ads we hold no name, email or account, and no IP address, so in most cases we genuinely cannot connect a request to your records. That is a consequence of collecting less, not an evasion. If you can give us a dsp_uid cookie value or a click identifier from an ad you interacted with, we can search on that. Otherwise the most effective route is the website or app where you saw the ad, which does hold your identifiers.

12. International transfers

We operate infrastructure in more than one region so that bidding is fast, which means data may be processed outside the country you are in, including in the United States. LEGAL: list the regions you actually deploy in and the transfer mechanism you rely on — Standard Contractual Clauses, the UK Addendum, an adequacy decision — and complete a transfer impact assessment.

13. Security

Passwords are stored only as one-way hashes. Sessions use secure, same-site cookies. Access to production data is limited to staff who need it. Measurement tokens are cryptographically signed so they cannot be forged or altered, and the click redirect is bound to its intended destination to prevent it being repurposed.

No system is perfectly secure. If a breach affects you and the law requires it, we will notify you and the relevant regulator within the required time. LEGAL: confirm the 72-hour GDPR notification process and who owns it.

14. Children

The platform is for businesses and is not directed at children. We do not knowingly collect data from children, and advertisers must not target children or advertise on child-directed inventory. LEGAL: if you ever serve child-directed inventory, COPPA and the UK Age Appropriate Design Code impose substantial additional obligations.

15. Changes

We publish changes as a new version with a new version string and effective date, and keep superseded versions in the archive. Where a change materially affects you we will give notice before it takes effect.

16. Contact and complaints

Privacy: [email protected]
Security: [email protected]

If you are unhappy with our response you can complain to your data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority for your country. LEGAL: name your lead supervisory authority if you have one.