TRUST & TRANSPARENCY
Privacy notice.
How this Pivt Digital website and ad delivery service handle information. Updated September 24, 2026.
This website
The public Pivt Digital pages do not run analytics or advertising tags. Signed-in pages use essential session and security cookies to maintain the login and protect forms, and load the Bootstrap stylesheet from the jsDelivr CDN, which receives ordinary web request data such as IP address. Standard web server logs may contain an IP address, requested URL, and browser information for security and service operation.
Accounts
Publisher customers, their team members, and the advertisers they invite sign in with an email address and password. We store the email address, an optional name, a salted password hash, the account's role and organization, and an activity log of changes made in the portal (for example creating a campaign or inviting a user). Users can protect their account with two-factor authentication using an authenticator app; we then store an encrypted authenticator secret and hashed one-time recovery codes. Invitation links expire and can be used once. After repeated failed sign-ins an account is temporarily locked. An organization owner can remove a user at any time, and the activity log is deleted after 365 days.
Advertisers are given their own, separate kind of sign-in. We store the same details for an advertiser login (email, optional name, salted password hash, the publisher and advertiser it belongs to, last sign-in time), in a table that is separate from publisher and team accounts. An advertiser login can see only its own advertiser's results and invoices, and nothing a publisher or team member can see. Advertiser logins do not currently offer two-factor authentication.
Sign-up, plan and payment
Customers (publishers) can create an account on their own. We collect the company or site name, your name and email, a password (stored only as a salted hash), and the country (United States or Canada) and state or province you tell us you are in. The service is offered to businesses in the United States and Canada only; we check this from what you declare and from the billing address you give when you add a card, and we do not look up your location from your IP address. If you use a promo code we record which one, so the discount or longer trial can be applied. We keep a record of the statements you accept (who, when, which version and a fingerprint of the wording) for as long as the account exists.
The plan is free for a trial period and then costs a monthly fee. Payment is handled by Stripe, which shows its own secure page, collects your card and billing address, and processes the payment under its own privacy notice. Pivt never sees or stores your card number; it receives and stores only Stripe's customer and subscription identifiers, the plan status and dates, and confirmation of payment. We email you about your account and your trial ending (for example seven days and one day before), and may email you if a payment fails. Administrators can give an account free-for-life access, and can approve an email address in advance so a sign-up with it is free; those approvals are stored with a note and the date. If you stop using the service your plan data is kept until your account is removed.
Contact form
If you write to us through the contact form we store your name, email address, the topic and your message so that we can reply, and email them to our team. They are deleted automatically after 365 days. Please do not put card details, passwords or sensitive personal information in a message. To limit abuse the form counts attempts per address in a short-lived cache using a one-way hash; no IP address is stored.
Ad delivery and measurement
Publisher pages may use the Pivt Digital widget to request an ad for a specific zone. The request includes the site origin and zone key. The application does not store a record per visitor or per impression. Instead it adds to daily counters for each zone and creative: how many ads were served, how many were viewed (visible on screen for at least a second), and how many were clicked. Each delivered ad carries a signed token so a view or click can be counted once; a short-lived entry in a cache prevents repeats. The browser's user agent is checked only to filter out bots and is not stored. By default the application does not set a visitor cookie, use browser storage, or store visitor IP addresses (see visitor measurement below for the one optional exception). Hosting and network providers may still process IP addresses in their ordinary server logs.
Clicks on direct, affiliate and CJ ads normally pass through a Pivt address that records one click and then sends the visitor to the advertiser or partner, whose own notice applies from that point. For programs that forbid redirects (such as Amazon Associates) a publisher uses a direct link instead: the visitor goes straight to the destination and the widget sends a small background signal that counts the click, without any identifier. Clicks on Google AdSense ads are not visible to Pivt.
Daily counters are kept for 365 days (12 months) and then deleted automatically each day.
Visitor measurement (optional)
A publisher can turn on unique-visitor counts and frequency caps for its site. This works only for visitors whom the publisher's own consent platform reports as consenting. For those visitors the widget stores a random identifier in the browser's local storage on the publisher's own site (never shared across publishers) and sends it in the body of the ad request, not in a web address. The identifier is not saved in our database: it is used to count each consenting visitor once per day and to limit how often a capped campaign is shown, and only keyed one-way hashes of it are held in a short-lived cache that expires within days. Withdrawing consent makes the widget delete the identifier. Without consent, none of this happens.
Shared site analytics
If a publisher connects its Google Analytics 4 property and turns sharing on, Pivt stores daily aggregate totals from that property (sessions, users, page views, and counts by country and device type) for 365 days. The publisher chooses which advertisers see which totals. Advertisers see only aggregate figures, never visitor-level data, and small values are hidden. The publisher can disconnect at any time, which deletes the stored analytics data.
Billing records
Publishers can create invoices for their advertisers from the counted views and clicks. An invoice stores the names, addresses, email and amounts the publisher enters and the totals taken from the counters. Invoices are accounting records and are not deleted by the 365-day cleanup; the publisher controls them and is responsible for its own retention. Pivt does not hold or move money between publishers and their advertisers.
If a publisher connects its own Stripe or PayPal account, an advertiser who chooses to pay an invoice online is sent to that provider's page, where the provider handles card or PayPal details under its own notice. Pivt never sees card numbers: it receives only a confirmation (status, amount and reference), and stores the publisher's provider keys encrypted. We also keep a record of the consent statements each person accepts when creating an account, switching on analytics sharing or connecting a payment account (who, when, which version and a fingerprint of the exact wording) for as long as the account exists.
Google AdSense and CJ Affiliate
AdSense and CJ placements are disabled for each publisher site until an operator enables them. The widget does not load Google’s ad script or show a CJ affiliate link unless the host site reports the matching consent choice. Google and CJ may process personal data and use cookies or similar technologies according to their own notices when their services are used. CJ and affiliate links can lead to affiliate tracking and the publisher may earn a commission; these ads carry a visible disclosure.
Review Google’s privacy policy and CJ’s privacy information for their practices.
Your rights and requests
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal data and to withdraw consent. Use the consent controls on the publisher site to change partner permissions. For a request about a specific publisher site, contact that site through its privacy notice.
Service operator: Pivt Digital. For privacy requests, email contact@pivtdigital.com.
Publisher sites
Each publisher site must provide its own privacy notice and consent interface covering its purposes, vendors, legal bases, retention, international transfers, and contact details. Pivt Digital’s public notice does not replace the publisher’s notice. For AdSense traffic in the EEA, UK, or Switzerland, the publisher must use an appropriate Google certified TCF consent management platform.
This notice describes the current application behavior. It needs review against the final hosting, contracts, configured vendors, and operating practices before a public launch.