1. Introduction & Scope
Welcome to Auctera. This Privacy Policy ("Policy") describes how Auctera, its affiliates, and subsidiaries (collectively, "Auctera", "we", "us", or "our") collect, use, process, share, and protect personal data. This Policy is designed to comply with global data protection regulations, including but not limited to the General Data Protection Regulation (GDPR), the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), and other applicable frameworks.
This Policy applies to our diverse suite of products and services, primarily categorized into three operational domains:
- The Auctera Demand Side Platform (DSP): Our programmatic advertising platform, RTB infrastructure, and cross-channel frequency capping tools.
- The Auctera Affiliate Network: Our performance marketing infrastructure connecting advertisers with publishers via tracked attribution links.
- The Auctera Corporate Website: This website (auctera.io) and related subdomains used for corporate communications, sales, and general visitor interaction.
Please read this Policy carefully. By using our services, accessing our platforms, or interacting with our digital properties, you acknowledge that you have read and understood the data practices described herein. If you do not agree with these practices, you must not use our services.
2. DSP & Programmatic Data Collection
Auctera operates an industry-leading Demand Side Platform (DSP) that facilitates real-time bidding (RTB) and programmatic media buying. In this capacity, we process vast amounts of digital advertising data to serve relevant ads, measure campaign performance, and prevent ad fraud. We do not generally collect "directly identifiable" information (like names or emails) through the DSP unless provided voluntarily via a lead generation ad format. Instead, we collect pseudonymous identifiers.
Types of DSP Data Collected:
- Bidstream Data: Data received from Supply Side Platforms (SSPs) and ad exchanges during the real-time bidding process. This includes device type, operating system, browser type, IP address (often truncated or hashed), and general location data (e.g., city, region, or zip code level).
- Unique Identifiers: Mobile advertising IDs (e.g., Apple IDFA, Google AAID), cookie IDs, proprietary Auctera D-REVX IDs, and third-party deterministic or probabilistic identifiers used for cross-device graphing.
- Contextual & Behavioral Data: Information about the website URL or mobile application where an ad is displayed, the content category of that property, and inferred user interests based on browsing history or app usage.
- Interaction Data: Metrics regarding how an end-user interacts with an advertisement, including impressions served, clicks, video completion rates, hover times, and post-click conversion events.
- Fraud Prevention Signals: Telemetry data used by our pre-bid IVT (Invalid Traffic) shield, including device orientation, touch events, connection speed, and bot-detection heuristics to ensure human interaction.
We aggregate and analyze this pseudonymous data within our D-REVX Data Layer to optimize bidding algorithms, enforce frequency capping across channels, and provide transparent attribution reporting to our advertisers.
3. Affiliate Network & Performance Data
The Auctera Affiliate Network connects premium advertisers with elite publishers to drive measurable actions (e.g., sales, leads, app installs) via a Cost-Per-Action (CPA) model. To facilitate accurate tracking, attribution, and payout calculations, we collect specific interaction data when end-users interact with publisher affiliate links.
Types of Affiliate Data Collected:
- Click and Referral Data: When an end-user clicks an Auctera tracking link, we log the referring URL, the destination URL, the time of the click, and a unique transaction ID.
- Device Information: We log the end-user's IP address, User-Agent string (browser and OS details), and screen resolution to aid in probabilistic attribution and fraud detection.
- Conversion Data: When an end-user completes a desired action on an advertiser's site (a "conversion"), the advertiser fires an Auctera postback pixel. This transmits the transaction ID, conversion amount, currency, and sometimes an anonymized order ID.
- Publisher & Advertiser Account Data: For the businesses operating on our network, we collect corporate entity names, contact details, payment routing information (bank accounts, PayPal, wire details), and tax identification numbers (W-9/W-8BEN forms) to facilitate legal payouts.
4. Corporate Website & Direct Interactions
When you visit auctera.io, request a demo, or contact our sales team, you are interacting directly with us as a B2B prospect or partner. In these scenarios, we act as a Data Controller and collect direct personal information.
Information You Provide:
- Contact Information: Name, business email address, corporate phone number, job title, and company name submitted via our "Contact Sales" or "Registration" forms.
- Communications: The contents of emails, chat transcripts, or support tickets you send to our team.
- Account Credentials: Usernames and passwords created to access the D-REVX terminal or the Affiliate dashboard.
Information Collected Automatically:
Like most enterprise websites, we use essential and analytical cookies to understand how visitors navigate our corporate site. This includes logging pages visited, time spent on site, referring domains, and general geographic locations based on IP addresses. For granular details on our cookie usage, please review our comprehensive Cookie Policy.
5. How We Use Data
Auctera strictly limits the use of collected data to the purposes disclosed in this Policy. Our primary objective is to provide secure, transparent, and high-performance advertising technology infrastructure.
For Programmatic & Affiliate Operations:
- Ad Serving & Real-Time Bidding: To evaluate bid requests in milliseconds, determine ad relevance, and deliver creative assets to publisher properties.
- Attribution & Measurement: To track which ad impressions or affiliate clicks led to a conversion, ensuring advertisers only pay for verified performance and publishers receive accurate commissions.
- Cross-Device Graphing: Utilizing the D-REVX Data Layer to understand when multiple devices (e.g., a smartphone and a laptop) belong to the same household or individual, enabling cohesive frequency capping and retargeting sequences.
- Fraud Detection: To deploy our Pre-Bid IVT Shield, identifying botnets, click farms, domain spoofing, and other fraudulent activities that harm the advertising ecosystem.
- Billing & Settlement: To generate invoices for advertisers, calculate margins, and execute mass payouts to global publishers.
For Corporate & Business Operations:
- Service Provisioning: To create and manage your Auctera platform accounts and provide technical support.
- Marketing & Sales: To send promotional materials, industry insights, or sales outreach to B2B prospects who have opted in or have a legitimate business interest. You may opt out of these communications at any time.
- Legal Compliance: To comply with tax reporting obligations (e.g., IRS 1099 generation), respond to lawful subpoenas, and enforce our Master Service Agreements.
6. Data Sharing & Disclosure
Auctera does not sell your personal data in the traditional sense (e.g., selling lists of names and emails to data brokers). However, the nature of programmatic advertising and affiliate networks inherently requires the sharing of pseudonymous data within the digital ecosystem.
We may share data with:
- Supply Side Platforms (SSPs) & Ad Exchanges: We share bid responses containing pricing, creative markup, and sometimes synchronized cookie IDs to participate in RTB auctions.
- Advertisers & Agencies: We provide our clients with aggregated and granular reporting on campaign performance. This includes conversion logs, site-level performance, and attribution paths, but strictly excludes directly identifiable end-user data unless explicitly provided via a lead gen ad.
- Publishers: We share aggregated performance data and postback URLs with affiliate publishers so they can optimize their traffic sources.
- Infrastructure Providers: We utilize top-tier cloud providers (e.g., AWS, Google Cloud), Content Delivery Networks (CDNs), and database infrastructure partners to host the D-REVX Data Layer securely. These sub-processors are bound by strict Data Processing Agreements (DPAs).
- Third-Party Measurement & Verification: We may integrate with third-party viewability and brand safety vendors (e.g., Integral Ad Science, DoubleVerify) to validate inventory quality.
- Legal & Regulatory Authorities: We may disclose data if required to do so by law, or in the good faith belief that such action is necessary to comply with legal obligations, protect the rights of Auctera, or ensure the safety of the public.
7. Cookies & Tracking Technologies
Auctera employs cookies, web beacons, mobile SDKs, and server-to-server tracking APIs to facilitate its operations. Within the DSP context, we use third-party cookies to sync user identities across exchanges and manage frequency capping. Within the Affiliate Network, we rely heavily on first-party cookies, postback URLs, and cookieless server-side tracking to ensure accurate attribution in an era of stringent browser privacy controls (like Safari ITP and Firefox ETP).
Because the technical specifics of our tracking infrastructure are extensive, we have dedicated an entire document to this topic. Please read our detailed Cookie Policy for a comprehensive breakdown of our tracking methodologies, cookie lifespans, and opt-out instructions.
8. Data Security & Retention
Security Measures
Auctera implements enterprise-grade technical and organizational measures designed to secure your data against accidental loss, unauthorized access, alteration, and disclosure. Our security posture includes:
- Encryption: All data in transit is encrypted using TLS 1.3. Sensitive data at rest (such as billing details and passwords) is encrypted using AES-256 and one-way hashing algorithms (e.g., bcrypt).
- Access Controls: Access to the D-REVX Data Layer and production databases is restricted via strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), and zero-trust VPN architectures.
- Audits & Monitoring: We conduct regular vulnerability scanning, penetration testing, and continuous monitoring of our infrastructure for anomalous activities indicating a potential breach.
Data Retention
We retain data only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required by law. Our standard retention schedules are as follows:
- Bidstream & Log Data: Raw bidstream data is typically aggregated or purged within 30 to 90 days.
- Cookie & Identifier Data: DSP tracking cookies generally expire within 13 months from the last interaction.
- Conversion & Affiliate Data: Transaction logs are retained for up to 7 years to comply with accounting, tax, and anti-fraud legal requirements.
- Corporate Account Data: Retained for the duration of the active business relationship and for a period thereafter as necessary to resolve disputes and enforce agreements.
9. International Data Transfers
Auctera is a global company. Data we collect may be transferred to, stored, and processed in the United States, the European Union, Singapore, and other regions where we or our sub-processors operate facilities.
For individuals residing in the European Economic Area (EEA), the UK, or Switzerland, please note that your data may be transferred outside of these regions. When such transfers occur, Auctera ensures an adequate level of protection is applied by utilizing approved transfer mechanisms, including:
- Executing the European Commission's Standard Contractual Clauses (SCCs) with our sub-processors and data partners.
- Relying on adequacy decisions issued by relevant regulatory bodies.
- Implementing supplementary technical measures, such as data pseudonymization and localized edge computing where feasible.
10. EU, UK, and Swiss User Rights (GDPR)
If you are located in the EEA, the UK, or Switzerland, the GDPR grants you specific rights regarding your personal data. Where Auctera acts as a Data Controller, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request the deletion of your personal data, subject to certain legal exceptions.
- Restriction: Request that we restrict the processing of your data under certain circumstances.
- Data Portability: Request to receive your data in a structured, commonly used, and machine-readable format.
- Objection: Object to our processing of your data based on legitimate interests or for direct marketing purposes.
- Withdraw Consent: If processing is based on consent, withdraw it at any time (without affecting the lawfulness of processing prior to withdrawal).
To exercise these rights regarding your corporate account, please email privacy@auctera.io. Regarding pseudonymous ad-tracking data, because we cannot tie an IP address or cookie ID to a named individual without additional context, we rely on industry-standard opt-out frameworks (like the IAB TCF or NAI opt-out tools) to honor data subject requests.
11. US State Privacy Rights (CCPA/CPRA, VCDPA, etc.)
Residents of California, Virginia, Colorado, Connecticut, Utah, and other applicable US states have specific rights regarding their personal information. Under the CCPA/CPRA, personal information is defined broadly and may include pseudonymous digital identifiers.
Your US State Rights:
- Right to Know: You may request details about the categories and specific pieces of personal information we have collected, the sources of that information, our business purposes, and the categories of third parties with whom we share it.
- Right to Delete: You may request the deletion of your personal information.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: Auctera does not "sell" data for monetary consideration. However, sharing pseudonymous identifiers for cross-context behavioral advertising may be considered "sharing" under the CPRA. You have the right to opt-out of this sharing.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
How to Opt-Out: If you are a consumer wishing to opt-out of cross-context behavioral advertising facilitated by the Auctera DSP, you may do so via the NAI Consumer Opt-Out Page or the DAA WebChoices Tool. You may also enable Global Privacy Control (GPC) signals in your browser, which our systems recognize and honor.
12. Children's Privacy
Auctera's services are designed for businesses and adult consumers. We do not knowingly collect, process, or target advertising based on the personal data of children under the age of 16 (or higher age thresholds as defined by local laws like COPPA). If we discover that we have inadvertently collected data from a child under the applicable age threshold, we will take immediate steps to delete that information from our servers. If you believe we may have collected data from a child, please contact us immediately.
13. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our technology, business practices, or legal requirements. When we make material changes, we will revise the "Last Updated" date at the top of this document. If the changes significantly alter how we process your previously collected data, we will provide more prominent notice (e.g., via email notification to registered account holders or a prominent banner on our corporate website). We encourage you to review this Policy periodically to stay informed about our data protection practices.
If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or your legal rights, please contact our Data Protection Officer (DPO) and privacy team.
By Email:
privacy@auctera.io
By Mail:
Auctera LLC
Attn: Privacy Department & Data Protection Officer
New York, NY, United States
If you reside in the EU/UK and feel that our processing of your personal data infringes data protection laws, you have the legal right to lodge a complaint with a supervisory authority responsible for data protection in your country of residence.