Privacy Policy
This explains what we collect, why, how long we keep it and what you can do about it. It covers two very different groups of people, and it says which is which — because a policy that blurs them is not telling either group anything useful.
1. Who this covers
- Account holders — advertisers, media buyers and their colleagues who sign in and run campaigns. See section 3.
- People shown our ads — anyone who visits a website or app where an advertisement was served through our platform. You almost certainly never chose to interact with us, and we hold far less about you than you might assume. See section 4.
2. Who we are
LEGAL: full registered entity name, company number, registered address, and the identity of the data controller. If you appoint an EU/UK representative or a Data Protection Officer, name them here with contact details.
Privacy contact: [email protected]
3. If you hold an account
What we collect
- Registration details — your name, work email, company name, and a password (stored only as a one-way hash, never in a form we can read).
- Terms acceptance record — which version of our terms you accepted, when, and the IP address you accepted from. We keep this because it is the evidence of what you agreed to.
- A referral code, if you entered one at signup.
- Federated sign-in details, if you use Google: the stable account identifier Google gives us, your email address and your name. We never receive your Google password.
- Your activity in the platform — campaigns and creatives you create, changes you make (with who made them and when), funds added or refunded, and support conversations.
- Technical logs — IP address, browser and timestamps, for security and debugging.
What we do with it
Run your account, serve and bill your campaigns, give you reporting, provide support, prevent fraud and abuse, meet our tax and accounting obligations, and tell you about things that materially affect your account. LEGAL: if you intend to send marketing email to account holders, say so here and describe the opt-out.
4. If you were shown one of our ads
When an advertising opportunity is offered to us, we receive information from the publisher or supply partner about the context, decide in a few milliseconds whether one of our advertisers wants it, and respond. What we keep from that is a record of the opportunity and the outcome.
What is recorded
- Approximate location — country, region/state and city, derived from your IP address.
- Connection and network — connection type (cellular, Wi-Fi, wired) and your internet provider or mobile carrier, identified by network number.
- Device and software — device type (phone, tablet, desktop, TV), operating system, browser and language, derived from the request.
- Context — the website domain or app, the placement, the ad position, and whether it was web or in-app.
- Outcome — timestamps, whether an ad was shown, whether it was clicked, the price, and which advertiser and creative were involved.
- Conversions — if you go on to complete an action on an advertiser's site and that advertiser reports it back to us, we record that it happened together with the details above. The advertiser tells us the event; we do not receive your name, email, payment details or order contents.
5. What we deliberately do not keep
We do not store your IP address in our advertising records. It is used at the moment of the request to work out approximate location, connection type and network, and it is not written to our reporting systems. Our per-auction records contain no IP address field at all.
We also do not collect or store: your name, email address, phone number, postal address, payment details, precise GPS location, contacts, photos, or the content of anything you type on a publisher's site.
We do not knowingly build profiles about special-category matters — health, religion, sexual orientation, political opinions, ethnicity or trade union membership — and advertisers are prohibited from targeting on them. LEGAL: if you ever permit adult, gambling, dating or health verticals, revisit this sentence; inventory category can imply inference even when you do not target on it.
Note that approximate location, device signals and network identity can still be personal data under laws such as the GDPR, even without your name. We treat them as such.
6. Why we are allowed to process it
LEGAL: confirm this mapping with counsel for each territory you operate in.
| What | Lawful basis (GDPR/UK GDPR) |
|---|---|
| Running an account holder's account | Performance of a contract |
| Terms acceptance record, tax and accounting records | Legal obligation |
| Fraud prevention, security, invalid-traffic detection | Legitimate interests |
| Aggregated reporting and product improvement | Legitimate interests |
| Serving and measuring personalised advertising | Consent, where required — obtained by the publisher or its consent platform before the opportunity reaches us |
How consent reaches us. We are not on the page when you arrive, so we cannot ask you directly. We rely on the publisher and its consent management platform to obtain consent where the law requires it, and to pass us the resulting signal. Our terms require advertisers and supply partners to comply with applicable privacy law.
LEGAL: this is the highest-risk paragraph in the document. Confirm whether the platform reads and enforces the transmitted consent signal — for example the IAB Transparency and Consent Framework string, or the US privacy string — before asserting reliance on it. If those signals are not yet enforced in the bid path, this paragraph overstates the position and must be narrowed until they are.
7. How long we keep things
These are the actual retention periods configured in our systems, not aspirations.
| Data | Kept for | Why |
|---|---|---|
| Opportunities we declined to bid on | 7 days | Short-term troubleshooting only |
| Per-auction records (bids we made) | 90 days | Billing detail, dispute resolution, fraud investigation |
| Impression, win and click records | 90 days | As above |
| Hourly aggregated reporting | 180 days | Trend reporting |
| Daily aggregated reporting | 2 years | Year-on-year reporting |
| Conversion records | Indefinitely | Long-horizon performance analysis for the advertiser |
| Account records | Life of the account, then LEGAL: state the period | Contract, then tax and audit obligations |
| Terms acceptance record | As long as needed to evidence the agreement | Legal obligation and defence of claims |
Indefinite conversion retention needs a decision. It is genuinely useful to advertisers, and each record is limited to the fields in section 4 with no direct identifiers. But "indefinitely" is difficult to defend against the GDPR storage-limitation principle without a stated justification and review. LEGAL: either set a maximum period (for example 25 months, matching common analytics practice) or document why an indefinite period is necessary and proportionate. This is a configuration change, not a redesign.
8. Who we share with
- Supply partners and publishers — we send a bid response and fire measurement URLs. They necessarily learn that an ad was bought and shown.
- Advertisers — the account whose campaign served sees the reporting described in section 4 for their own campaigns. They do not receive your identity.
- Service providers acting on our instructions — hosting and infrastructure, the provider of the IP-intelligence database used to derive approximate location and network, error monitoring, and Google for federated sign-in. LEGAL: publish the actual sub-processor list, or commit to providing it on request.
- Professional advisers, auditors, and authorities where we are legally required, or to establish or defend legal claims.
- An acquirer, if the business is reorganised or sold, subject to this policy.
We do not sell personal information for money. Note that some US state laws define "sale" and "sharing" broadly enough to cover cross-context behavioural advertising. LEGAL: determine whether your activity is a "sale" or "sharing" under the CCPA/CPRA and equivalents, and if so provide a "Do Not Sell or Share My Personal Information" mechanism — that is a legal requirement with a specific link and title.
9. Cookies and identifiers
On our own website and platform we use only what is necessary: a session cookie to keep you signed in and a token to protect against cross-site request forgery. Our marketing site loads no third-party scripts and sets no advertising cookies.
In advertising we may set a first-party identifier cookie named
dsp_uid on our own measurement domain, with a one-year lifetime, used to limit how
often you see the same advertisement and to measure whether a click led to a conversion. We also
recognise an opt-out cookie named dsp_optout.
LEGAL / ENGINEERING: do not publish this section as-is. The opt-out endpoint
currently sets dsp_optout and tells the visitor they will no longer be tracked, but
nothing in the bidding path reads that cookie yet (see TODO.md). Telling a person
their opt-out has taken effect when it has not is a materially false statement to a data subject
exercising a choice.
Fix one of two ways before launch: honour dsp_optout in the bid and serve path, or
change what the opt-out page says until you do. This document deliberately does not claim the
opt-out currently stops personalisation.
Your browser and operating system also offer controls — blocking third-party cookies, resetting or limiting your advertising identifier on mobile, and private browsing. Those work regardless of anything we do.
10. Your choices
- Opt out of personalisation — LEGAL: link this once the opt-out is actually enforced (see section 9).
- Change your mind about consent — consent is normally collected by the website or app you were on, so its own privacy settings are the place to withdraw it.
- Device controls — reset or limit your mobile advertising identifier, or block cookies in your browser.
- Industry opt-out pages — LEGAL: only cite YourAdChoices, Your Online Choices or the DAA/NAI programmes if you are actually a member. Citing a programme you have not joined is itself a misleading statement.
11. Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict processing, to withdraw consent, to receive a copy in a portable form, and not to be discriminated against for exercising any of these.
Write to [email protected] and we will respond within the period the law requires (one month under the GDPR, 45 days under the CCPA).
An honest limitation. For people shown ads we hold no name, email or account, and
no IP address, so in most cases we genuinely cannot connect a request to your records.
That is a consequence of collecting less, not an evasion. If you can give us a
dsp_uid cookie value or a click identifier from an ad you interacted with, we can
search on that. Otherwise the most effective route is the website or app where you saw the ad,
which does hold your identifiers.
12. International transfers
We operate infrastructure in more than one region so that bidding is fast, which means data may be processed outside the country you are in, including in the United States. LEGAL: list the regions you actually deploy in and the transfer mechanism you rely on — Standard Contractual Clauses, the UK Addendum, an adequacy decision — and complete a transfer impact assessment.
13. Security
Passwords are stored only as one-way hashes. Sessions use secure, same-site cookies. Access to production data is limited to staff who need it. Measurement tokens are cryptographically signed so they cannot be forged or altered, and the click redirect is bound to its intended destination to prevent it being repurposed.
No system is perfectly secure. If a breach affects you and the law requires it, we will notify you and the relevant regulator within the required time. LEGAL: confirm the 72-hour GDPR notification process and who owns it.
14. Children
The platform is for businesses and is not directed at children. We do not knowingly collect data from children, and advertisers must not target children or advertise on child-directed inventory. LEGAL: if you ever serve child-directed inventory, COPPA and the UK Age Appropriate Design Code impose substantial additional obligations.
15. Changes
We publish changes as a new version with a new version string and effective date, and keep superseded versions in the archive. Where a change materially affects you we will give notice before it takes effect.
16. Contact and complaints
Privacy: [email protected]
Security: [email protected]
If you are unhappy with our response you can complain to your data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority for your country. LEGAL: name your lead supervisory authority if you have one.