01Who is responsible
The data controller is AdvertiserSystem, using that name as the company name, with a principal place of business in the State of Florida, United States. Website: https://advertisersystem.com. Privacy contact: privacy@advertisersystem.com or an in-product support ticket after you sign in.
If we appoint an EU or UK representative because the law requires it, we will publish those details on this page.
02Whose data this covers
This policy covers personal data we process about:
- Advertisers and publishers who create accounts.
- People who visit our marketing and legal pages.
- End users who see or click ads on publisher sites, limited to delivery, billing, and fraud signals described below.
- People who email us or open a ticket.
Publishers remain responsible for their own sites, including their privacy notices to visitors. Advertisers remain responsible for their landing pages and offers. We are an independent controller for network operation, billing, and abuse prevention; we are not your lawyer or your DPO.
03Personal data we collect
Depending on how you use the Service, we may process:
- Account data: name, email, password hash (email sign-up), optional Google account identifier and profile image if you use Google sign-in, role, email verification status, ban status, and timestamps.
- Campaign and site data: ads, creatives stored on our servers, landing URLs, targeting, budgets, domains, and verification records.
- Money data: wallet balances, ledger entries, Stripe deposit references, withdrawal destinations, and related status fields.
- Support data: tickets, messages, and inbox notifications.
- Security data: session records (IP and user agent when available), Turnstile bot checks, impersonation audit trails for operators, and server logs.
- Ad-event data: event id, event type, ad/domain/plan identifiers, country, IP address, user agent, creative size, billed flag, reject reason, and cost fields, stored in ClickHouse for measurement and fraud control.
- Diagnostics: error reports sent to Bugsink without default personally identifying fields enabled.
We do not ask for government ID as a default signup field. We may request additional identity or tax information before a payout or if the law or fraud review requires it.
04Where it comes from
- Directly from you (registration, settings, ads, domains, tickets, cookie choices).
- Automatically from your browser or our tag (IP, user agent, timestamps, consent cookie).
- Payment processors (Stripe deposit success or failure).
- Email delivery providers (bounces or failures on transactional mail).
- Our own fraud and billing systems derived from the data above.
05Why we use it
- Create and secure accounts, including email verification, Google sign-in, and password reset.
- Review, serve, measure, and bill ads; pay publishers; operate wallets.
- Detect invalid traffic, abuse, and policy breaches, including fail-closed measurement.
- Provide support, notices, and product emails you need to use the Service.
- Keep tax, accounting, and dispute records.
- Improve reliability (error reports) and, with consent, count public-page visits (Umami).
- Comply with law, including lawful requests and Florida breach-notice duties.
06Legal bases (EEA/UK and similar)
Where GDPR, UK GDPR, or a similar regime applies, we rely on:
- Contract — to provide the account, dashboard, billing, and payouts you request.
- Legitimate interests — network security, fraud prevention, service operations, and limited B2B communications, balanced against your rights.
- Consent — optional analytics cookies, and any other processing we ask for clearly.
- Legal obligation — tax, accounting, sanctions screening we are required to perform, and responding to valid legal process.
08Processors and service providers
- Hosting and application infrastructure used to run advertisersystem.com.
- PostgreSQL and ClickHouse datastores in our deployment environment.
- Stripe, for advertiser deposits.
- SMTP2GO, for transactional email.
- Cloudflare Turnstile, for bot checks on email sign-in and registration.
- Google, if you choose Continue with Google. Google authenticates you and shares your name, email, and (when provided) profile image.
- Umami, for privacy-oriented analytics on public pages, only after you accept analytics cookies.
- Bugsink (Sentry-compatible), for error reports with default PII fields disabled.
09Ad delivery and end users
When a publisher tag requests an ad, we may receive IP address, user agent, and derived country to choose an eligible creative, apply frequency and fraud rules, and bill the event. We sign impression and click tokens so they cannot be trivially forged. This is advertising measurement and security, not a consumer profile we sell.
End users who want to exercise rights about ad-event data can contact privacy@advertisersystem.com. We may need enough detail (approximate time, IP, publisher site) to locate records, and we may refuse requests that are unfounded, excessive, or would compromise fraud controls, to the extent the law allows.
11Retention
We keep account data while the account is open. After an approved erasure request we delete sessions and credential records, anonymize name and email, and ban the leftover row so it cannot sign in.
Wallet ledgers, billed ad events, and tax-relevant records may be kept for the period Florida and U.S. federal recordkeeping rules require (often several years), even after erasure of the profile. ClickHouse ad events are also subject to the table TTL configured on our cluster (currently up to 24 months unless we must export a subset for a dispute).
Support tickets and audit logs are kept as long as needed for security and dispute handling.
12Security
We use HTTPS, hashed passwords, role checks, signed ad-event tokens, upload type sniffing, and operator audit logs. No method of transmission or storage is perfectly secure. You must protect your password and tell us promptly if you believe an account was compromised.
13International transfers
AdvertiserSystem is established in the United States. If you access the Service from the EEA, UK, or elsewhere, your data is processed in the United States and in any region where our processors operate. Where a transfer tool is required, we rely on the mechanism the processor offers (such as Standard Contractual Clauses) plus the technical measures described above.
14Your rights
How to access, export, correct, or delete account data is spelled out on the privacy rights page. In short: sign in and use Privacy in the advertiser or publisher dashboard, or email privacy@advertisersystem.com. We will need to verify the request.
GDPR / UK GDPR: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent, subject to exceptions (including contract, legal claims, and legal obligation). You may complain to your supervisory authority.
California (CCPA/CPRA), to the extent applicable: the right to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined there. We will not discriminate against you for exercising those rights.
Florida Digital Bill of Rights (Fla. Stat. §§ 501.701–501.721), to the extent we are a “controller” covered by it: the right to confirm processing, access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, sale, or certain profiling. We do not sell personal data or use it for cross-context targeted advertising of the kind that statute is aimed at. Appeals of a denied request: reply to our decision email; if still unresolved you may contact the Florida Attorney General.
15Florida breach notice
If we determine that personal information as defined in Florida’s Information Protection Act (Fla. Stat. § 501.171) was subject to unauthorized access, we will notify affected Florida residents and, when required, the Florida Department of Legal Affairs, in the manner and time that statute requires (generally as expeditiously as practicable, and no later than 30 days after we determine a breach occurred, unless law enforcement delay applies).
16Children
The Service is for adults running advertising businesses. It is not directed at children under 13 (COPPA) or to anyone under 18. We do not knowingly collect personal information from children. If you believe we have, email privacy@advertisersystem.com and we will delete it.
17Automated processing
Fraud and billing systems apply automated rules (rate limits, interval checks, mass-click thresholds, token validation, and similar). Those rules can cause an event not to be billed or an account to be flagged for operator review. They are not consumer credit decisions. You can ask us to explain a billing or enforcement action that affects your account.
18Changes to this policy
We will post updates here with a new effective date. Material changes that affect your rights will also be noted in the dashboard or by email where practical.
19Contact
AdvertiserSystem
advertisersystem.com
State of Florida, United States
privacy@advertisersystem.com
How to reach us
Privacy and data-rights requests: privacy@advertisersystem.com. Account holders can also open an in-product support ticket after you sign in. Do not send passwords or full card numbers to that inbox.