Legal
Privacy Policy
What personal data PubTrust processes, in which role, why, where and for how long — and the rights you have over it.
Who we are, and our two roles
PubTrust is a ClearTrust product. The contracting ClearTrust entity and its registered address will be named here in the reviewed version. We process personal data in two distinct roles:
- As a processor for the publishers, ad networks and publisher groups that install the PubTrust tag (our customers). For data the tag collects about visitors to a customer's websites, the customer is the controller and we act only on its documented instructions, under our Data Processing Agreement.
- As a controller for our customers' account and billing data, for correspondence with us, and for visitors to pubtrust.cc.
Data processed through the PubTrust tag
When a page carrying the tag loads, the tag reports ad slots it has judged: the page URL and referrer, the Site, details of any violating creative (the rule that matched, advertiser domain, creative ID, bidder, slot and landing URL), exact counts for the page view, and a small sample of clean impressions. The edge adds coarse geography, network, browser family, operating-system family and device class. The docs list every field.
IP addresses are truncated at the edge by default — IPv4 to /24, IPv6 to /48 — before anything is stored. A customer organisation can opt in to full IP retention only with an explicit acknowledgement, and full addresses are then deleted after at most 30 days. The tag sets and reads no cookies and uses no local storage, fingerprinting or cross-site identifier.
Purposes
- Detecting, blocking and reporting advertisements that violate the customer's ad-quality policy or attack the page.
- Producing the customer's reports, including the estimated revenue impact of blocking.
- Counting page views, on which the customer is billed.
- Securing, operating and debugging the service.
The customer, as controller, determines the lawful basis — typically its legitimate interest in protecting its website and its readers from malicious and non-compliant advertising. We process this data only to provide the service to that customer.
Data we control
- Account data — name, work email, organisation, role, sign-in and security events, and the audit log of actions taken in the dashboard. Basis: performance of our contract with your organisation, and our legitimate interest in securing the service.
- Billing data — billing contact, plan, usage and invoices. Card details are collected and held by Stripe. Basis: contract, and legal obligations for tax records.
- Correspondence — messages you send us and our replies, and service email such as usage alerts and report digests. A message sent through our contact form is stored with the details you enter, a truncated IP address (IPv4 /24, IPv6 /48) and your browser's user agent, which we keep to prevent abuse of the form. Basis: legitimate interests in answering you and protecting the form, or steps prior to a contract.
- This website — pubtrust.cc sets no analytics or advertising cookies. Our hosting providers keep standard request logs for security. The dashboard uses a strictly necessary session cookie once you sign in.
How long we keep data
| Data | Retention |
|---|---|
| Violation records | 90 days |
| Clean-impression detail sample | 30 days |
| Aggregated rollups (no IP addresses) | Indefinitely, for trends and billing |
| Full IP addresses (opt-in only) | At most 30 days |
| Account data | For the life of the account; the deletion period after closure will be set in the reviewed version |
| Audit log | For its statutory retention period, then destroyed |
| Billing records | As long as tax law requires |
Where data is processed
Beacons are received at Cloudflare's global edge, where IP addresses are truncated, and forwarded in HMAC-signed batches over HTTPS to our application platform on Railway, where they are stored. An EU data region is available for the application platform and database; ask before onboarding. Where personal data is transferred outside the EEA or the UK, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses with the UK Addendum, as set out in the DPA.
Sub-processors
| Sub-processor | Purpose | Data |
|---|---|---|
| Cloudflare | Edge network: delivery of the tag and policy bundles, receipt of beacons, IP truncation, queueing | Beacon data in transit, including the connecting IP address before truncation; Site configuration |
| Railway | Application hosting, Postgres database and Redis | Stored event data (truncated IP addresses by default), account data, audit log |
| Stripe | Subscriptions, payments and usage metering | Billing contacts, plan, one aggregated usage figure per organisation per day; card details are held by Stripe and never reach PubTrust |
| plinth (plinth.tools) | Transactional email: account emails, usage alerts, report digests | Recipient names and email addresses, email content |
The maintained list is on the sub-processors page. We notify customers before adding or replacing a sub-processor.
Your rights
Under the GDPR and the UK GDPR you can ask for access to, correction of, erasure of or a copy of your personal data, object to or restrict its processing, and complain to your data protection supervisory authority. Write to privacy@pubtrust.cc.
If you are a visitor to one of our customers' websites, that customer is the controller of tag data about you: contact them, or write to us and we will pass your request on and help them answer it. Because IP addresses are truncated by default and the tag uses no identifier, tag data usually cannot be linked to a specific person.
Security
Beacons are validated against each Site's registered domains; batches between the edge and our platform are HMAC-signed and sent over HTTPS; the audit log is append-only and hash-chained; and staff access to a customer account requires a typed reason, is time-limited and read-only by default, and appears in the customer's own audit log. See Security & Privacy. Report vulnerabilities to security@pubtrust.cc.
Changes to this policy
We will publish changes at this address and tell customers about material changes by email before they take effect.