For the Audience Vault data collected through your website (visitor events, hashed identifiers, conversions), you are the controller and we are the processor — we collect and process that data only on your instructions, for the purposes you configure (running your campaigns, building your audiences, generating your reports). If you're an agency managing this on behalf of your own client, your client is typically the controller, you act as their agent, and we're a sub-processor in that chain. We do not use Audience Vault data for any purpose other than operating the service for the account it belongs to, and we do not sell it.
Ads and Pixels / Data Processing Agreement
Data Processing Agreement
Draft — pending legal review. Who owns the Audience Vault, what we do with it, and how deletion actually works.
Roles — who's the controller, who's the processor
The Audience Vault is yours
Each customer's Audience Vault is a physically isolated data store — no cross-customer database, no shared table with a filter, an actually separate store per client. You can export it at any time, in a portable format (CSV, Parquet, or a SQL dump), including after you leave, or during a billing dispute. No person-level data from your vault is ever pooled with another customer's data, used to build another customer's audiences, or used to train or improve a model in a way that could re-identify anyone. The only exception is described in the next section, and it's deliberately narrow.
The one thing we do use in aggregate
With your data processing agreement's consent, we use anonymized, aggregate statistics only — figures published only when at least 5 agencies and 20 clients stand behind them (checked again for every metric; an agency counts only once its account is at least 60 days old and has a verified, spending ad account, and a client only with spend on at least 30 days), when no single agency accounts for more than 30% of those clients, and only for industries from a fixed list, never a free-text label; each client counts toward one goal only; percentiles are rounded to 2 significant figures and client counts down to a multiple of 5, and a metric whose contributing clients changed by fewer than 3 clients, or by clients of fewer than 3 agencies, since its last publication repeats its previous figures (and the group's counts) instead of new ones, so comparing two days can't isolate one client. Money figures are converted to one reporting currency with that day's European Central Bank rate (days without a rate are left out). Aggregates are stored with no identifiers, no way to trace a number back to an individual person or even to a specific customer — to build cross-industry benchmarks (for example, "restaurant clients in this size range typically see X range of cost per lead") and to improve the AI Optimizer's general judgment. This is never person-level data, never raw events, and never your data identified as yours in a benchmark shown to anyone else. To stop a client contributing to aggregate benchmarks, turn on Exclude this client from anonymized benchmarks in that client's AI Optimizer settings (it leaves every benchmark from the next nightly computation), or contact [email protected] to opt your whole account out.
What we store, and how
We store hashed identifiers, never plaintext contact information: SHA-256 of a normalized email address, SHA-256 of an E.164-formatted phone number, and comparable hashed values for other fields each advertising network's audience-matching API requires. Where a network requires a field in the clear to function (for example, ZIP code or country for Meta or Google's own matching), we store only what that network's own published matching requirements call for. Raw browsing events are archived separately from identity data and are subject to the retention schedule below.
Retention
| Data | Kept for |
|---|---|
| Raw events | 25 months by default, adjustable per customer |
| Profiles | 25 months after the person was last seen |
| Synced audiences | Capped at each network's own retention window (for example, Meta's website-audience window, Google's Customer Match window) |
| Suppression list (deletion requests) | Kept indefinitely, as hashes only, so a deleted person isn't re-imported later |
| Export | Available to you at any time |
These are defaults, not fixed limits — a shorter retention period can be set per customer on request.
Deletion requests
Send a deletion request to [email protected], or trigger one from inside the app where that control is available. When we process a deletion request, we: (1) remove the person's data from your Audience Vault; (2) add their hashed identifiers to a permanent suppression list so they aren't re-imported by a later sync; and (3) send a removal instruction to every advertising network you've synced that person's data to, using each network's own deletion API — for example, Meta's customer-list DELETE /users endpoint, Google's equivalent removal path through the Data Manager API, and TikTok's and Snap's own removal endpoints. We aim to complete deletion within 30 days of a verified request, faster where a network's own API allows a shorter turnaround, and we'll confirm completion in writing.
- 01
Remove
Remove the person's data from your Audience Vault.
- 02
Suppress
Add their hashed identifiers to a permanent suppression list so they aren't re-imported by a later sync.
- 03
Notify
Send a removal instruction to every advertising network you've synced that person's data to, using each network's own deletion API.
Meta data deletion
If a person asks Meta directly to delete their data, or asks you as the business to delete data Meta shared with you, we support that deletion the same way as any other request: the person's hashed identifiers are removed from the relevant Audience Vault and added to the suppression list, and any synced Custom Audience entry is removed through Meta's own API. If you operate a Meta app that requires a Data Deletion Callback URL or Instructions URL, this page and the deletion process described above are the basis for that disclosure — contact [email protected] if you need the specific technical detail for a Meta App Review submission.
Google API Services User Data Policy
Ads and Pixels' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice, that means: data from a connected Google account (Ads, Analytics, Search Console, Tag Manager) is used only to provide or improve the specific, user-facing features you've enabled — reporting, audience building, tag management, keyword research — is never used to serve advertising, and is never transferred to a third party except (a) to provide or improve those features, with your consent, (b) to comply with the law, or (c) as part of a merger, acquisition or asset sale, in which case the acquiring party must agree to these same restrictions before receiving the data. Human access to this data inside Ads and Pixels is limited to what's needed for support, security or legal compliance.
Global Privacy Control
Our collector honors the Global Privacy Control (GPC) signal wherever it's present. A visit tagged with GPC is marked opted-out at the point of collection and is excluded from every audience sync to every connected network — it's never a matter of removing it after the fact, since it's never synced in the first place.
International transfers
Where Audience Vault data includes people located in the EEA, UK or Switzerland, we rely on Standard Contractual Clauses (or another lawful transfer mechanism) for any transfer of that data outside those regions, consistent with the international-transfer terms in our Privacy Policy.
Sub-processors
The following categories of sub-processor may process data on our behalf. This list is a placeholder pending final legal review and vendor selection; a current, named list will replace it here, with advance notice of any change and a window to object before a new sub-processor is added, consistent with standard DPA practice.
| Category | Purpose |
|---|---|
| Cloud infrastructure | Hosting, compute, storage for the application and the Audience Vault |
| Payment processing | Billing and subscription payments |
| Email delivery | Transactional and account email |
| Advertising networks you connect | Receive only the data needed for the campaigns and audiences you configure (Meta, Google, Microsoft, TikTok, Snap, and others as added) |
Security measures
Encrypted token storage, role-based access, two-factor authentication and an append-only audit log are described in full on our Security page and apply to Audience Vault data the same as everything else in the platform.
Requesting a signed DPA
If your organization requires a formally signed Data Processing Agreement — for example, for your own GDPR compliance as a controller — email [email protected] and we'll provide one for signature. This page describes the same terms in plain language; a signed DPA doesn't change what's here, it formalizes it.
Frequently asked questions
Real answers before you make a decision.
Who owns the data in my Audience Vault?
You do. It's a physically isolated store per customer, exportable at any time, including after you leave.
What do you actually use my data for, beyond running my own campaigns?
Nothing beyond that, except anonymized, aggregate, minimum-group-size statistics for cross-industry benchmarks and general AI Optimizer improvement — never person-level, never traceable back to you or an individual.
How does deletion work across the advertising networks I've connected?
When you request deletion, we remove the person from your vault, add their hashed identifiers to a permanent suppression list, and send a removal instruction to every network you've synced their data to, using each network's own deletion API.
Is this a legally binding GDPR Data Processing Agreement?
Not yet in its current form — it's a draft describing our practices. A formally signed DPA is available on request at [email protected].
Do you honor Global Privacy Control?
Yes — a GPC-tagged visit is excluded from every audience sync at the point of collection.
Where's the current list of sub-processors?
The category list on this page is a placeholder pending final legal review; a current, named list will replace it, with advance notice before any new sub-processor is added.
Need a signed DPA?
Email [email protected] and we'll send one for your legal or compliance team.