Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains how TrafficSigma ("TrafficSigma", "we", "us", or "our") collects, uses, discloses, and safeguards personal data when you visit our website, register for an account, or use our self-serve advertising network and related services (collectively, the "Services"). It also describes the rights you have over your personal data and how you can exercise them.
We are committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection (revFADP), and applicable United States federal and state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and other comparable US state privacy laws as they take effect.
1. Who we are
TrafficSigma operates a global self-serve performance advertising network that connects advertisers with publisher-supplied traffic across formats such as push notifications, in-page push, pop, native, domain redirect, and messenger-based placements.
For the purposes of the GDPR, UK GDPR, and revFADP, TrafficSigma acts as the controller of the personal data described in this Policy, except where we act as a processor on behalf of our advertiser and publisher clients (for example, when handling campaign and audience data on their instructions). Where we act as a processor, our client is the controller and their own privacy notice governs that processing.
You can contact us about privacy matters at any time at [email protected].
2. Personal data we collect
We collect the following categories of personal data:
- Account and identity data: name, business name, email address, phone number, username, password (stored in hashed form), and account role (advertiser or publisher).
- Billing and financial data: billing address, tax or VAT identifiers, transaction history, deposit and balance records, and limited payment metadata. Full card numbers are handled by our PCI-DSS compliant payment processors and are not stored on our systems.
- Advertiser campaign data: campaign settings, creatives, targeting parameters, bids, budgets, and aggregated performance statistics such as impressions, clicks, and conversions.
- Publisher data: traffic source details, site or app identifiers, payout details, and earnings statistics.
- Technical and usage data: IP address, device and browser type, operating system, language, referring URLs, pages viewed, and interactions with the platform, collected via server logs and cookies or similar technologies.
- Communications data: the content of support tickets, emails, and other messages you send to us.
We do not intentionally collect special categories of personal data (such as health, biometric, or precise geolocation data) about our account holders, and we ask that you do not submit such data to us unless strictly necessary and lawful.
3. Purposes of processing and legal bases
Under the GDPR, UK GDPR, and revFADP we rely on the following legal bases (Article 6 GDPR) for our processing:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account and providing the Services | Performance of a contract (Art. 6(1)(b)) |
| Processing payments, deposits, and refunds | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Fraud prevention, traffic quality, anti-bot filtering, and platform security | Legitimate interests (Art. 6(1)(f)) |
| Campaign moderation and compliance with advertising laws | Legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) |
| Product analytics and service improvement | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications and newsletters | Consent (Art. 6(1)(a)), withdrawable at any time |
| Meeting tax, accounting, and other legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we balance those interests against your rights and freedoms and only proceed where our interests are not overridden. You may object to such processing as described in Section 8.
4. Cookies and consent
We use strictly necessary cookies to operate the platform (for example, to keep you signed in, to secure sessions, and to remember your consent choice), as well as analytics and marketing cookies where you consent to them. On your first visit we present a consent banner that lets you accept all, reject all (both a single click, given equal prominence), or manage granular preferences by category (Strictly necessary, Analytics, and Marketing). Non-essential cookies default to off and are not set until you opt in. Strictly necessary cookies do not require consent and cannot be switched off.
Full details of the cookies we set, their categories, and their durations are in our Cookie Policy.
You can change or withdraw your cookie consent at any time through the "Your Privacy Choices" control in our website footer, which reopens the consent preferences, and you can also manage cookies through your browser settings. We honor the Global Privacy Control (GPC) signal: where a browser transmits GPC and you have not made an explicit choice, we automatically opt you out of non-essential cookies and treat it as a valid opt-out of the sale or sharing of personal data and of targeted advertising where required by law.
5. Advertising data processing
TrafficSigma is a business-to-business advertising platform. In connection with the delivery and measurement of advertising campaigns, we and our clients process data such as advertiser account data, publisher data, campaign configuration, and aggregated campaign statistics. When we serve ads or measure results on behalf of an advertiser or publisher, we act as a processor and follow that client's documented instructions.
We do not sell personal data for money, and we do not share personal data for cross-context behavioral advertising in a manner that would require an opt-out under US state law outside of the honored GPC and opt-out mechanisms described here. Where advertising involves end-user data supplied by publishers, our clients are responsible for obtaining any consents required from those end users under applicable law.
6. Sharing and disclosure
We may share personal data with:
- Service providers and processors who help us run the Services, such as hosting, payment processing, analytics, fraud detection, and customer support providers, all bound by data processing agreements.
- Advertiser and publisher clients to the extent necessary to deliver, measure, and reconcile campaigns.
- Professional advisers, auditors, and authorities where required to comply with law, enforce our terms, or protect our rights, users, and the public.
- Successors in the context of a merger, acquisition, or asset sale, subject to this Policy.
7. International data transfers
We operate globally, and personal data may be transferred to and processed in countries outside your own, including the United States. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, we implement appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and, where applicable, reliance on the EU-US and Swiss-US Data Privacy Framework (DPF). You may request a copy of the relevant safeguards by contacting us.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy. Account and campaign data are retained for the life of your account and for a reasonable period afterwards to handle disputes and legal claims. Billing and transaction records are retained for the periods required by tax and accounting laws (typically up to ten years). Server logs and technical data are retained for a limited period for security and fraud-prevention purposes. When data is no longer needed, we delete or anonymize it securely.
9. Your rights
Subject to applicable law, you have the following rights over your personal data under the GDPR, UK GDPR, and revFADP:
- Access to the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") in the circumstances allowed by law.
- Restriction of processing in certain circumstances.
- Data portability for data you provided to us, in a structured, machine-readable format.
- Objection to processing based on legitimate interests or for direct marketing.
- Withdrawal of consent at any time, without affecting prior lawful processing.
- Right to lodge a complaint with your competent supervisory authority, such as your national EU data protection authority, the UK Information Commissioner's Office (ICO), or the Swiss Federal Data Protection and Information Commissioner (FDPIC).
US state privacy rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another US state with a comprehensive privacy law, you may have the right to:
- Know and access the personal data we have collected about you.
- Correct inaccurate personal data.
- Delete personal data, subject to legal exceptions.
- Obtain a portable copy of your personal data.
- Opt out of the sale or sharing of personal data and of targeted advertising. We honor the Global Privacy Control (GPC) signal as a valid opt-out request.
- Not be discriminated against for exercising your privacy rights.
To exercise any of these rights, email us at [email protected]. We will verify your identity and respond within the timeframes required by applicable law. You may use an authorized agent to submit a request on your behalf where the law permits.
10. Children's privacy
The Services are intended for businesses and professional users. They are not directed to children, and we do not knowingly collect personal data from anyone under 16 years of age. If we learn that we have collected such data, we will delete it promptly.
11. Security measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration. These include encryption in transit, access controls and least-privilege permissions, hashed password storage, network and application security monitoring, and regular review of our security practices. No method of transmission or storage is completely secure, but we work continuously to protect your data.
12. Data protection contact
For any questions about this Policy, to exercise your rights, or to reach our data protection contact, please email [email protected]. Where required, we can also act as, or appoint, a representative for data subjects in the EU, UK, and Switzerland.
13. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email or through the platform. Your continued use of the Services after an update constitutes acceptance of the revised Policy.