MadData About Products Publishers Media Buyers Contact Login

Draft — under review

Privacy Policy

1. Who we are

eRate is a digital advertising technology company operating an ad-serving and campaign-management platform (together, "the Service") and this website. The Service is operated by eRate online measurement solutions ltd (Israel), reachable at support@erate.co.il. In this policy, "we", "us", and "our" refer to eRate online measurement solutions ltd; "you" and "your" refer to the person whose data is processed.

This policy covers three situations, and different sections apply to each:

  • Website visitors — people browsing this website (Section 2.1).
  • Platform users — advertisers, agencies, and publishers who log in to our campaign-management dashboard (Sections 2.2–2.4).
  • End users — people who encounter ads delivered by our technology on our partners' websites and mobile applications (Section 2.5).

The platform is provided on a business-to-business basis. Accounts are created for customer organisations; we do not offer self-service public registration to consumers.

2. What information we collect

2.1 Website visitors

If you use the contact form on this website we collect the details you submit: name, email address, phone number, and your message. Our web server also retains short-lived access logs (IP address, request path, user agent, response code) for operational and security purposes. This website does not use analytics or advertising cookies.

2.2 Platform account information

When an account is created for you on our dashboard, we store:

  • Your name and email address.
  • A salted hash of your password (never the password itself).
  • The secret used by your authenticator app for two-factor authentication, stored encrypted.
  • The role and permissions assigned to you within your organisation.

2.3 Google account information (only if you connect Google)

If you connect a Google account to use for sign-in as your second factor, we store:

  • The Google account's stable identifier (the OpenID Connect sub claim).
  • The email address Google reports for that account.
  • The timestamp of the connection.

We do not receive or store your Google password, and we do not request access to your Gmail, Drive, Calendar, or any other Google services beyond the basic profile (email and name) that the OAuth openid email profile scopes provide. You can disconnect your Google account at any time from your account's security settings, subject to keeping at least one second factor enabled.

2.4 Activity, audit, and session data

For security and accountability we record actions taken in the dashboard: who logged in, who created or modified a campaign, who uploaded a creative, and similar events, with the user identifier, the action, the affected record, and a timestamp. When you use the dashboard we store an encrypted session cookie in your browser to keep you logged in, along with a CSRF protection token.

2.5 Ad-serving data (end users)

When our technology delivers an ad on a partner website or application, we process:

  • Pseudonymous identifiers, used to recognise a browser or device across ad requests: a first-party cookie (retained up to 12 months) and a browser local-storage identifier. Where neither is available, the ad is still delivered but the device is not recognised across requests. We do not use device fingerprinting.
  • Event data: ad impressions, viewability events, clicks, and (where an advertiser measures them) conversion events, each with a timestamp and the campaign and placement involved.
  • Technical data: IP address, user agent, device type, operating system, and browser.

These identifiers do not include your name, email address, phone number, or any directly identifying information, and we make no attempt to link them to your real-world identity.

3. How we use information

We use the data described above to:

  • Deliver ads and control how often the same person sees a given campaign (frequency capping).
  • Measure campaign performance and estimate unique-user reach for our customers.
  • Build pseudonymous audience segments so a campaign can be shown, or not shown, to devices that previously interacted with related campaigns (retargeting and exclusion).
  • Detect and filter invalid traffic, bots, and fraud.
  • Authenticate platform users, keep sessions secure, and maintain audit trails.
  • Respond to inquiries submitted through this website.
  • Diagnose problems, prevent abuse, and improve the Service.

We do not sell personal data. Our customers receive aggregated campaign statistics only — never the underlying identifiers or per-person data.

4. Third parties we share information with

We share data only with the following processors, and only to the extent necessary for the Service to function:

Processor Purpose Data shared
Google LLC OAuth sign-in for platform users (only if you connect a Google account) Your sign-in request and the OAuth tokens needed to verify it
DigitalOcean LLC Application and database hosting (Frankfurt region, EU) Data processed by the Service runs on DigitalOcean infrastructure
Cloudflare, Inc. Content delivery network for ad creative files Standard CDN request data (IP address, user agent) of devices loading creatives
Resend, Inc. Email delivery (contact-form messages, account emails) Recipient email address, name, and email body

We do not share data with data brokers, and we do not use third-party analytics providers.

5. Where data is processed and international transfers

We are an Israeli company and the Service is directed primarily at the Israeli market; data is processed under the Israeli Privacy Protection Law. Our application servers and databases are located in the European Union (DigitalOcean, Frankfurt region), and Israel benefits from a European Commission adequacy decision permitting data flows between the EEA and Israel.

Some processors named above (Google, Cloudflare, Resend) may process data in the United States. We engage them under their standard data-processing agreements, which incorporate recognised transfer safeguards (EU-U.S. Data Privacy Framework certification and/or Standard Contractual Clauses).

6. Retention

  • Ad-serving identifiers and event-level data are retained for a rolling measurement window of approximately 3 months, after which they are deleted or reduced to aggregated, non-identifying statistics. Aggregated campaign statistics (which contain no personal data) are retained as business records.
  • The first-party cookie expires no later than 12 months after it was last set.
  • Platform account data is retained while the account is active.
  • Activity logs are retained for the operational lifetime of the relevant records and a reasonable audit window thereafter.
  • Database backups are retained on a rolling basis (typically up to 30 days) for disaster recovery.

7. Opting out of ad targeting

You can opt out of our pseudonymous identification at any time using our opt-out page: https://rep.erate.co.il/?t=optout. After opting out you may still see ads served by us, but they will no longer be frequency-capped or targeted using our identifiers. Because the opt-out is itself stored in your browser, clearing cookies will reset it. You can also block or delete cookies and site data through your browser settings at any time.

8. Security

We implement reasonable technical and organisational measures to protect data, including:

  • HTTPS/TLS for all traffic.
  • Salted-hash storage of passwords (never plaintext) and encrypted storage of two-factor secrets.
  • Mandatory two-factor authentication for all platform accounts.
  • Role-based access control inside the application.
  • Network separation between the ad-serving layer and the administrative dashboard.
  • Regular system updates and database backups.

No system is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the appropriate supervisory authority as required by applicable law.

9. Your rights

Subject to applicable law (Israeli Privacy Protection Law, EU GDPR, and equivalent regimes), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data.
  • Receive a copy of your data in a portable format.
  • Withdraw consent (for example, by using the opt-out page or disconnecting your Google account).
  • Object to certain processing.
  • Lodge a complaint with a supervisory authority — in Israel, the Privacy Protection Authority (PPA); in the EU, the supervisory authority of your country of residence.

To exercise any of these rights, email support@erate.co.il. Note that for ad-serving data we hold only pseudonymous identifiers and usually cannot connect them to you without additional information from you (such as the cookie value in your browser).

10. Cookies

On this website we set no cookies beyond those strictly necessary. Within the Service:

  • Dashboard session cookie — keeps platform users authenticated; encrypted, HttpOnly, Secure; expires with the session.
  • CSRF token — required for the security of authenticated requests.
  • Advertising cookie (first-party) — set when ads are delivered on partner sites, used for frequency capping and unique-user measurement as described in Section 2.5; expires within 12 months; can be declined via the opt-out page (Section 7) or browser settings.

11. Children

The Service is not directed to children under the age of 16, we do not knowingly collect data from anyone under that age, and we do not build audience segments aimed at children. If you become aware that a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page a reasonable period before they take effect, and platform users will be notified by email. The "Last updated" date at the top reflects the most recent revision.

13. Contact

For any privacy-related question or request, contact:

eRate online measurement solutions ltd Email: support@erate.co.il

14. Governing law

This policy is governed by the laws of the State of Israel. Disputes shall be subject to the exclusive jurisdiction of the competent courts of Tel Aviv–Jaffa, except where local law grants you the right to bring a claim before the courts of your country of residence.