Global Privacy Notice
How AttributionPath™ handles personal data across websites, attribution services, APIs and white-label deployments.
Effective 24 August 2026. This Privacy Notice explains how AttributionPath™ handles personal data when you visit our websites, create or administer a business account, request support, run an attribution test, use AttributionPath™ software, or interact with a deployment operated for an advertiser, publisher, agency, commerce platform, white-label partner or API customer.
1. Scope and regional structure
AttributionPath™ is a global attribution and measurement platform made available through regional service designations. The region relevant to a customer relationship may depend on the customer's location, contracting route and service configuration. Current public designations are AttributionPath™ United Kingdom, AttributionPath™ North America and AttributionPath™ Europe. Regional privacy requirements apply where their legal scope and thresholds are met.
2. Our role depends on the processing
For account administration, billing, security, website enquiries and our own service operations, AttributionPath™ may act as a controller or business. When AttributionPath™ processes campaign, visitor, event or conversion data on documented instructions from a business customer, it generally acts as a processor or service provider. A customer remains responsible for determining its own purposes, lawful bases, notices, consent requirements and attribution rules. White-label and API arrangements may create different role allocations and are addressed in the applicable agreement and DPA.
3. Data we may process
Depending on configuration, data may include business contact and account information; installation and configuration information; device, browser and network information; IP address and derived coarse location; page, referral, campaign and advertising identifiers; timestamps; click, impression and conversion events; order or transaction references; pseudonymous identifiers; consent signals; fraud, quality and security signals; support communications; and technical logs. Customers should not intentionally transmit special-category or highly sensitive personal data unless expressly agreed and lawfully permitted.
4. Why data is processed
We process data to provide attribution and path-to-conversion reporting; identify duplicate or competing claims; apply customer-defined measurement rules; operate pixels, tags, APIs, proxies and integrations; secure and troubleshoot the service; prevent abuse; maintain audit and operational records; provide support; administer accounts and subscriptions; meet legal obligations; and improve reliability and performance in ways compatible with the original purpose.
5. Legal bases
Where GDPR-style laws apply and AttributionPath™ acts as controller, processing may rely on performance of a contract, legitimate interests, consent where required, and compliance with legal obligations. Where AttributionPath™ acts as processor, the customer determines the applicable lawful basis and instructs the processing. Nothing in this notice substitutes for the customer's own privacy notice or consent obligations.
6. Cookies, pixels and similar technologies
Attribution and measurement can involve first-party storage, cookies, pixels, tags, server-to-server events, APIs and comparable technologies. Whether consent is required depends on the technology, purpose, jurisdiction and customer implementation. Customers are responsible for implementing consent or opt-out mechanisms required for their deployment. AttributionPath™ will honour supported consent signals and documented customer configuration where technically applicable.
7. Sharing and subprocessors
Personal data may be disclosed to authorised subprocessors and service providers that support hosting, infrastructure, security, communications, customer support and other necessary operations, subject to appropriate contractual and security obligations. Data may also be disclosed where required by law, to protect legal rights or security, or in connection with a lawful corporate transaction. AttributionPath™ does not permit a processor deployment to use customer personal data for unrelated independent advertising purposes merely because it is processed through the platform.
8. International transfers
Global infrastructure may involve transfers or remote access across borders. Where restricted-transfer rules apply, appropriate mechanisms may include adequacy decisions or regulations, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, or another legally recognised safeguard. Transfer risk assessments or supplementary measures are used where required.
9. Retention
Data is retained only for as long as reasonably necessary for the applicable service, contractual, security, audit and legal purposes. Customer-controlled service data follows the retention configuration or agreement. Backup and security copies may persist for limited additional periods before deletion or overwrite. Legal holds may extend retention where required.
10. Security
We use administrative, technical and organisational safeguards appropriate to the nature and risk of processing. Measures may include access controls, authentication, encryption in transit, logging, environment separation, vulnerability management, backups and incident-response procedures. No internet service can guarantee absolute security.
11. Individual rights
Depending on applicable law, individuals may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, appeal, limitation of certain uses or disclosures, and complaint to a regulator. Where AttributionPath™ acts solely as processor or service provider, requests relating to customer-controlled data should normally be directed to the relevant customer; we assist customers as required by contract and law.
12. California and other US state rights
Where applicable US state privacy laws provide rights to know/access, delete, correct, opt out of sale, sharing or targeted advertising, limit certain uses of sensitive personal information, obtain portability or appeal a decision, those rights will be respected according to the law that applies. A service-provider or processor deployment is contractually restricted to the permitted business purposes and customer instructions. See our Global Privacy & Regional Rights page for jurisdiction-specific information.
13. Children
AttributionPath™ is a business service and is not directed to children. Customers must not knowingly configure the service to collect children's personal data in breach of applicable law.
14. Automated measurement
AttributionPath™ may automatically classify events, identify patterns, detect duplicate claims or apply customer-defined attribution rules. The service is designed for advertising measurement and reporting. Customers remain responsible for any consequential business decision they make using outputs and for determining whether additional legal requirements apply to automated decisions in their jurisdiction.
15. Complaints and privacy contact
Privacy questions and rights requests may be sent to privacy@attributionpath.com. We may need to verify identity and jurisdiction before acting on a request. Where another organisation controls the relevant data, we may direct the request to that organisation.
16. Changes
We may update this notice to reflect changes in law, technology, service functionality or regional operations. The effective date above identifies the current published version. Material changes will be communicated where required by law.