Privacy Policy

Last updated: May 1, 2026

1. Introduction

Attribi ("we", "us", "our") is a multi-touch attribution platform that helps digital marketers understand the full customer journey across advertising channels. This Privacy Policy explains what information we collect from users of attribi.com (the "Service"), how we use it, and the choices you have.

2. Information We Collect

2.1 Account Information

When you create an Attribi account, we collect your name, email address, and authentication credentials. If you sign in with Google, we receive your name, email address, Google account ID, and profile picture.

2.2 Visitor Tracking Data

Attribi's JavaScript tracker (installed by you on your own websites) collects anonymous visitor touchpoint data: page URLs, UTM parameters, ad click IDs (gclid, fbclid, li_fat_id, ttclid, msclkid), referrer, user-agent, IP address, timestamp, and a first-party visitor identifier stored in the visitor's browser cookie and localStorage. This data is attributed to your tenant and used to build conversion journeys.

2.3 Lead Data You Submit

When a visitor on your website submits a form, your tracker may send us the lead's name, email, phone number, and form payload. This data is processed on your behalf solely to provide attribution and integration services.

2.4 Third-Party Integration Data

When you connect ad platforms (Google Ads, Meta, LinkedIn, TikTok, Microsoft Ads) or CRMs (HubSpot, Salesforce, Zoho, Pipedrive, Freshsales), we store OAuth access tokens, refresh tokens, account IDs, and configuration metadata required to read spend data, upload offline conversions, and sync lead records.

2.5 Meta Lead Ads Data

If you connect a Facebook Page to Attribi for Lead Ads ingestion, we use the pages_show_list, pages_manage_ads, and leads_retrievalpermissions to (a) list the Pages you admin so you can choose which to connect, (b) enumerate the active Lead Forms on the Pages you select, and (c) fetch new Lead Form submissions every 10 minutes via Meta's Marketing API. We do not use these permissions to read Page posts, photos, videos, events, follower lists, profile pictures, or any other Page content beyond the Lead Form metadata and submissions described here.

For each lead submission we receive from Meta, we store: the form field responses you collected (typically email, phone, name, plus any custom questions), the originating ad, ad set, and campaign IDs, the Meta lead ID, and the submission timestamp. This data is stored encrypted at rest, scoped to your Attribi account via row-level security, and is accessible only to your team members.

We use Meta Lead Ads data exclusively to (a) display leads in your Attribi dashboard, (b) forward leads to CRMs you have connected to your Attribi account at your direction, and (c) upload qualified-stage and closed-won-stage offline conversion signals back to Meta keyed on the original Meta lead ID, so that Meta's optimization model can learn which Lead Ads drove real downstream revenue for you. We do not sell, share, or use Meta lead data for any purpose other than the customer-directed uses described here.

3. How We Use Information

  • Provide multi-touch attribution reports and ROAS calculation
  • Upload closed-won conversions back to connected ad platforms (offline conversion tracking)
  • Push lead and attribution data into your connected CRMs
  • Authenticate you and protect your account
  • Send essential service notifications (security alerts, billing, product updates)
  • Improve and debug the Service

We do not sell your data. We do not use customer data to train machine learning models. We do not share your data with advertisers beyond the specific ad platform integrations you explicitly connect.

4. Google API Services User Data Policy

Attribi's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google OAuth scopes (Google Ads, Google Sheets) is used only to provide the user-facing features of the Service and is never transferred to third parties except as necessary to provide those features, or when required by law. We use the Google Picker API with the narrow drive.file scope so that Attribi only ever accesses the specific spreadsheet you explicitly select — never your wider Google Drive.

5. Data Storage and Security

All data is stored in Supabase (hosted on AWS) with encryption at rest and in transit. Row-level security policies enforce tenant isolation. OAuth tokens are stored encrypted in a restricted-access database. Access to production systems is limited to authorized personnel and protected by multi-factor authentication.

6. Data Retention and Deletion

We retain touchpoint and lead data for as long as your account is active. You can export your data at any time via the Settings page or by contacting us.

You may request deletion of your Attribi account and all associated data — including any Meta Lead Ads data we have ingested on your behalf — at any time by emailing privacy@attribi.com. We will delete all your tenant data within 30 days of the request and confirm completion via email.

You may also disconnect any connected platform (including Meta) from Attribi at any time via the Connections page. Disconnecting stops further data ingestion immediately. Previously ingested data remains in your Attribi account until you delete it or close your account.

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data; withdraw consent; or lodge a complaint with a supervisory authority. To exercise these rights, email privacy@attribi.com.

8. Cookies and Tracking

The Attribi dashboard uses essential cookies for authentication and session management. The Attribi tracker (deployed on customer websites) sets a first-party cookie on your customers' websites to identify returning visitors; this cookie contains only a random identifier and no personal data.

9. International Transfers

Attribi is operated from India. If you access the Service from outside India, your data will be transferred to and processed in regions where our cloud providers operate.

10. Children's Privacy

Attribi is not intended for users under 16. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via email or in-app notice at least 30 days before they take effect.

12. Contact

Questions about this Privacy Policy? Contact us at privacy@attribi.com.