This page covers data ownership, consumer privacy, and data retention. This information adds context to but does not replace Katalys published policies on katalys.com.
Data Ownership
Katalys collects data 1) for internal purposes from users visiting Katalys products, 2) for external purposes from users visiting advertiser- or partner-controlled domains.
Internal Collection
Clients logging into Katalys products on Katalys-owned domains are subject to Katalys Privacy Policy, as documented here. These policies are for employee-facing tooling only. Data collected is owned by and managed by Katalys in accordance with company policy so that Katalys can service clients.
External Collection
Data collected from client-owned domains and stored within Katalys is controlled by siloing information into a Tracking ID. Advertisers must have a Tracking ID to record data into their account, whereas partners only selectively require Tracking IDs.
-
For advertisers, data captured by an advertiser’s Katalys Tracking Script is stored within a Tracking ID stored on Katalys-controlled infrastructure but owned by the advertiser.
-
Partners get selective visibility into this data through aggregated means only for traffic directly attributed to the partner. Fields include Click Count, Session Depth, and Session Count.
-
Partners get selective visibility into order data only for orders being paid to the partner and only for the purpose of confirming that payouts match contracts. Fields include Order ID, Order Time, Action Type, Product Name, and Product Category.
-
No other order details (such as email hash or PII) are shared.
-
-
For partners only sending direct clicks, data is stored within a Tracking ID owned by the advertiser. A direct click is an off-domain action to the partner, and an on-domain session-entrance for the advertiser; therefore, it must be visible to the advertiser.
-
For partners implementing the Katalys Tracking Script on their owned domains to capture on-domain UTM values or perform advanced campaign tracking, data is stored within a Tracking ID stored on Katalys-controlled infrastructure but owned by the partner.
-
Advertisers do not get visibility into partner’s data.
-
Advertisers get visibility into clicks sent to the advertiser. Fields visible include Sub1/2/3/4/5.
-
UTM values are private to the partner and not visible to the advertiser.
-
Read more about how Tracking IDs work and process data →
Consumer Privacy
In compliance with privacy legislation passed by the EU (GDPR), the State of California (CCPA), and other jurisdictions, technology providers must 1) disclose what data is collected, 2) how it is used, 3) allow users certain controls over their data.
-
For internal products and owned domains, Katalys publishes its own Privacy Policy here →
-
For data collected externally from clients, continuing reading below.
What Is Collected
When the Katalys Tracking Script is deployed onto an advertiser’s or partner’s website, it operates similarly to other analytics trackers. It collects:
-
URL
-
Referrer
-
User Agent
-
IP Address
-
Session identifiers (random GUID values, stored in a browser cookie)
-
Email address (when provided by an advertiser – hashed and anonymized)
No additional PII is expressly collected by Katalys.
This information is required to be collected. Katalys is providing attribution modeling that services contracts. Without this data, Katalys cannot provide its modeling and cannot offer payouts to partners. Katalys also offers some analytics functions, such as session-count; this does not mean that the cookies are analytics cookies. The identifiers are required to provide the modeling core to the service.
Who Processes Data
Katalys operates its own data processing infrastructure using cloud hosted providers such as AWS. Information is encrypted in-flight and at rest; hosting providers cannot access any client data. Katalys does not sell consumer data or transmit consumer data to any third party without the consent and configuration by the client.
How Data is Used
Katalys uses data to provide attribution modeling. Analysis of these models enable advertisers and partners to selectively share data, and when a contract is active, to enable payouts on our marketplace.
Data stored within a Tracking ID is not correlated with another Tracking ID. This means that data collected by an advertiser is not used by or accessible to another advertiser.
The Katalys platform has features which enable any client to offboard their data using an API and using Postbacks. Katalys provides integrations with large advertising networks, such as Google, Meta, and TikTok. Katalys does not by default send data into any third-party system; these features are managed by the client. Each client is responsible for disclosing to their users how they use Katalys tooling.
Katalys technology does not change the visual experience for users. If a client – advertiser or partner – is deploying Katalys technology, then it is the client’s responsibility to disclose Katalys as a Data Processor and how the client will use the data they are storing within Katalys.
Consumer Controls
Opt out of collection: Consumers cannot opt out of data collection. Katalys must collect data to service its clients. The Katalys system calculates “conversions”, which are billable events triggered when a user completes online or offline actions, such as placing an ecommerce order or signing up for a newsletter. When an action is detected, the attributed source must be contractually reported. Since Katalys cannot know which users will complete actions before they complete them, Katalys must collect all information to calculate billable events.
Opt out of marketing: Katalys is not an SSP and does not operate its own targeting system. As such, Katalys does not provide a marketing opt-out feature.
Data deletion: Consumers may not request a deletion of their data to Katalys directly. Data reported about a user or transaction is owned by the client. Data deletion requests from Katalys clients can be handled via support ticket, and only if the ticket contains enough identifying information to filter to appropriate records.
Data exports: Consumers may not request data exports to Katalys directly. Data reported about a user or transaction is owned by the client. Katalys provides advanced reporting to its clients so long as the client has tagged the information correctly. Be advised that Katalys heavily anonymizes its own databases, which can limit the ability for data to be exported.
Retention Periods
Data stored within Katalys infrastructure includes PII and non-PII fields. Columns marked as PII are cleaned, obfuscated, or deleted over time.
-
Account-level fields:
These are data fields manually populated by a Katalys client. This data has a minimum retention of 3 years. This allows any Katalys client to see year-over-year reporting on fields where the client has defined an explicit value. Example fields are Katalys Traffic Source, Sub1/2/3/4/5, UTM Campaign, UTM Content, UTM Medium, UTM Source, UTM Term.-
Note: Event data can be marked as payable, such as when a consumer clicks-then-purchases. When an event is payable, fields such as Katalys Traffic Source and Order ID will be retained by the Accounting Team for long term auditing and reporting. Retention is governed by Katalys accounting practices.
-
-
Raw PII fields:
Event logs containing raw Email, User-Agent or IP addresses are kept for a minimum of 100 days, and no more than 6 months.-
Note: Emails are always hashed before storage. Certain email hashes affiliated with orders are stored for a minimum of 5 years. This is required to service platform features such as “New To File” triggers, commonly used by advertisers to increase payouts for partners who drive net-new customers.
-
-
Pseudo-anonymous fields:
Fields storing truly-random GUIDs, such as Session ID, are stored for a minimum of 3 years. Once raw and hashed data is expunged, pseudo-anonymous fields can no longer be correlated to individual users. Retention of these fields follows Account-level fields, but the fields are not retained for billing purposes.