Skip to main content

User Data & Privacy

What user data is used, and which parts are optional?

For basic ad serving, we practically don't need any personal data at all. The only thing required is confirmation that an ad was served (to meet basic KPIs like impression counts).

Optional data (collected only with user consent and only if you implement the relevant trackers):

  • First-party cookies, session identifiers, mobile device identifiers.
  • IP address, referrer URL.
  • Behavioural data: browsed products and categories, search interactions, cart activity.
  • Purchase history and signals from logged-in users.

You decide which trackers to enable and what data you share. If you want to use targeting, it's worth adding at least an add-to-cart tracker (without needing to pass the full transaction value) — it's a strong signal for campaign performance.

Can the system run without cart data, purchase history, or checkout events?

Absolutely. That data unlocks additional targeting options, but it's entirely optional. The system works fine without it.

Trackers that collect and share data require cookie consent from the user — the same way any other analytics or advertising tool works in e-commerce. If a user doesn't consent, trackers aren't triggered and no data is passed to us.

What happens without consent? Ads still appear, but they're not personalised. If a campaign requires targeting and the user doesn't match any segment (because we have no data on them), that specific campaign won't show — but a non-targeted one might.

This works the same way as any other ad-supported platform: no cookie consent doesn't mean no ads — it just affects which ads are shown.

Short answer: we can't recognise that user. Incognito mode creates a browser session with a randomly generated ID. All cookies from that session — whether consented to or not — are wiped when the session closes. Even if a user gave consent and we tracked their behaviour during a session, we won't be able to connect that data to them on their next visit (which will have a new, random ID).

Is user data anonymised or aggregated?

In line with GDPR guidelines, data is pseudonymised and only aggregated in that form into segments (user profiles). We don't process personally identifiable information.

How long do you retain user data?

No longer than 60 days from the user's last interaction with an ad.

Is data shared outside the platform?

Data is used exclusively within the MageAds platform. The only exception is a Google Ad Exchange integration — but only if you opt into it (it's entirely optional). In that case, some data is passed to Google, which requires appropriate user consent in your cookie policy.

Do we have control over what data is shared with you?

Full control. You decide which trackers to implement, which directly determines what data we receive. You can disable any tracker at any time. The trade-off is a narrower targeting scope, but ads keep running.

Consent is only required when trackers that collect data are activated. Ads without trackers can run without any additional consent beyond what you already collect. You simply add the relevant elements to your existing cookie banner — only for the trackers you've connected.


Need help? Contact support at info@mageads.com