Privacy Policy
Audaptiv Pty Ltd ABN: 71 693 745 747 121 Castlereagh Street, Floor 12, Sydney NSW 2000, Australia
Effective Date: 23 February 2026 Last Updated: 19 March 2026
1. Introduction
Audaptiv Pty Ltd ("Audaptiv", "we", "us", "our") operates a programmatic audio advertising platform that serves audio advertisements on behalf of advertising agencies and their clients. This Privacy Policy explains how we collect, use, and disclose information in connection with our services.
We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA).
2. Information We Collect
2.1 End-User (Listener) Data
When an audio advertisement is served, our platform processes the following data from the ad request. This data is provided by the advertising platform that initiates the ad request — Audaptiv does not directly interact with end users.
| Data Type | Purpose | Retention |
|---|---|---|
| IP address | Geolocation lookup only, and only when active campaigns require geographic targeting. Not stored. | Not retained |
| User agent string | Device type detection only. Not stored. | Not retained |
| Hashed listener identifier | Pseudonymous, non-reversible, per-campaign hash for aggregate reach and frequency measurement. Built from the inputs described in §2.3; not linkable across campaigns. | 25 months |
| Derived geographic data | Approximate location — derived only when campaigns require geographic targeting. | 25 months (when collected) |
| Device type | Broad category (e.g. mobile, desktop, smart speaker). | 25 months |
| Contextual data | Collected only when active campaigns require specific contextual targeting signals. | 25 months (when collected) |
| Ad delivery events | Impression, playback progress, completion, and interaction events. | 25 months |
We do not collect names, email addresses, phone numbers, browsing history, or demographic data, and we do not build behavioural or interest-based profiles. We do not set our own persistent cookies. Where a mobile advertising ID or a platform-set identifier is present in an ad request, we use it only as an input to the per-campaign hashed identifier described in §2.3 below — we never store or process it in raw form. Our platform evaluates active campaign requirements before collecting any contextual data — if no campaign requires a specific data type, it is not collected.
2.2 Client (Platform User) Data
Clients who use our platform provide:
| Data Type | Purpose |
|---|---|
| Email address | Authentication and access control |
| First and last name | Display in platform |
| Profile photo URL | Display in platform (from OAuth provider) |
| Advertiser contact email | Campaign management communications |
2.3 Listener Identification for Measurement
To measure how many distinct listeners heard a campaign and how often (reach and frequency), we create a per-campaign pseudonymous identifier for each ad request. We do not identify you personally, and we do not track you across campaigns or across apps and sites.
How the identifier is built. We take a single input value (see the priority order below), combine it with the specific campaign's identifier and a secret value held only by us, and apply a one-way SHA-256 hash. The result is a short, irreversible code. Because each campaign's identifier is mixed in, the same person produces a different code in every campaign — the codes cannot be linked back to a person and cannot be matched across campaigns. Within a single campaign the code stays the same for that campaign's duration, which is what lets us count unique listeners and frequency accurately.
What input is used, in priority order. We use the first available of:
- An identifier the advertising platform itself supplies for the request (e.g. its own listener id);
- The advertising platform's first-party cookie value (Triton only);
- A mobile advertising ID (Apple IDFA, Google GAID, or an AdsWizz IFA), where the device makes one available;
- As a last resort, a fingerprint derived from the request's IP address and User-Agent.
Input only — never stored raw. Mobile advertising IDs and the platform cookie are used solely as an input to the hash above; we never store or otherwise process them in raw form. If a device signals that ad tracking is turned off (the all-zero advertising ID returned after an iOS App Tracking Transparency denial or an Android opt-out), that value is discarded and never used. The combined text string that feeds the hash is discarded immediately after the code is generated and is never stored. (Note: this is specific to the hash input. We do separately retain an IP address and User-Agent field on our event records for engineering, analytics, and abuse-prevention purposes, as described elsewhere in this policy and our agreements; that is distinct from the hash input, which is not retained.)
Irreversibility. The hash is one-way. We cannot recover the original input from the stored code, and the code on its own does not identify you.
3. How We Use Information
End-user data is used for: ad delivery, contextual targeting (when required by campaign configuration), campaign analytics and reporting, and fraud prevention.
Client data is used for: account management, platform access control, customer support, and billing.
Where GDPR applies, we rely on legitimate interest for end-user data processing (contextual ad serving and campaign measurement) and performance of contract for client data.
4. How We Share Information
We provide clients with aggregated, anonymized analytics only. We do not share raw IP addresses, user agent strings, or identifiable listener data with clients.
We use third-party service providers in the following categories:
| Category | Data Shared | Location |
|---|---|---|
| Cloud infrastructure | All platform data (encrypted) | Australia |
| Authentication | Client email, name, profile photo | Global |
| Geolocation (when required by campaigns) | End-user IP address (real-time, not stored) | International |
| Contextual data (when required by campaigns) | Geographic coordinates only (non-identifiable) | International |
We may also disclose information as required by law, to enforce our Terms of Service, to protect rights and safety, or in connection with a merger or acquisition (with prior notice).
Our platform integrates with advertising platforms that initiate ad requests. These platforms receive standard ad delivery event confirmations only.
5. Overseas Disclosure
All persistent data is stored in Australia (Sydney). Personal information may be disclosed to overseas recipients in the following circumstances:
- Geolocation providers (international) — end-user IP addresses for real-time lookup, only when campaigns require geographic targeting. IP addresses are not stored after the lookup.
- Contextual data providers (Europe/international) — geographic coordinates only (non-identifiable).
- Authentication provider (global) — client email and name for platform login. Protected by Data Processing Agreement and Standard Contractual Clauses.
Where GDPR applies, transfers are protected by Standard Contractual Clauses or adequacy decisions.
6. Data Retention
End-user tracking data is retained for 25 months from the event date and then permanently deleted. Client account data is retained for the duration of the client relationship plus 90 days. Aggregated, non-identifiable data may be retained indefinitely.
7. Your Rights
Under the Australian Privacy Act, you have the right to access personal information we hold about you, request correction of inaccurate information, and complain about a breach of the APPs.
Where GDPR applies, you additionally have the right to erasure, restriction of processing, data portability, objection to processing, and to lodge a complaint with a supervisory authority.
Where CCPA applies, California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. Audaptiv does not sell personal information.
Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to clients via email at least 30 days before taking effect.
9. Contact Us
For privacy inquiries, data access requests, or complaints:
Audaptiv Pty Ltd Attn: Cristopher Kedmenec Email: privacy@audaptiv.com Address: 121 Castlereagh Street, Floor 12, Sydney NSW 2000, Australia
If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). If GDPR applies, you may also lodge a complaint with your local data protection authority.