Legal

Privacy Policy

This policy explains what Atlas5 processes as a programmatic exchange, and how privacy signals flow through the auction.

Last updated July 17, 2026

1. Our role: a conduit, not a CMP

Atlas5 is an exchange, not a consent management platform. We don't collect consent from end users ourselves — publishers are responsible for collecting consent on their own properties and passing the resulting signals to us on every request. We read those signals, forward them to demand partners, and use them to gate user syncing. If a signal isn't sent, demand receives none, which can suppress bidding in regulated regions.

2. Information we process

From publishers, we hold account and contact information needed to run your account:

  • Company and contact details for your account (name, email, billing information).
  • Your declared domains, app bundles, and seller IDs.

From ad requests, we process what your integration sends us, which typically includes:

  • Device and browser signals (IP address, user agent, device type) needed to run the auction and detect invalid traffic.
  • Contextual signals about the placement (page URL or app bundle, ad size, category).
  • Identity signals you choose to pass, such as Extended IDs (EIDs) or a hashed user identifier.
  • Consent and privacy strings — GDPR/TCF, US Privacy (CCPA), GPP, and COPPA flags.

3. How we use it

  • To run the real-time auction and return a bid, VAST response, or no-bid.
  • To generate the funnel, revenue, and viewability metrics shown in your reporting dashboard.
  • To operate ad quality controls — creative and advertiser blocklists, category filtering.
  • To detect fraud, invalid traffic, and violations of our policies or your account's allowlist.
  • To match users for the purpose of raising bid density, subject to the consent signals you send.

4. Sharing with demand partners

Bid request data is shared with the demand partners eligible to compete for a given impression, exactly as forwarded by your integration. Winning demand partners receive the fields needed to render and measure their creative. We do not sell the data in bid requests to third parties outside the auction.

5. Cookies and user syncing

Where permitted by the consent signals on a request, Atlas5 and its demand partners may set or read a matching cookie (or use an app-level device identifier) to raise bid density. This is sometimes called "user syncing." Sync calls only fire when the relevant consent signal allows them, and are skipped entirely when it doesn't. In cookieless environments (such as Safari's ITP), matching relies more heavily on Extended IDs passed by the publisher.

6. Your privacy choices

Atlas5 does not have a direct relationship with the end users browsing publisher properties — for exercising privacy rights (such as access, deletion, or opt-out requests under GDPR, CCPA/CPRA, or similar regional laws), please start with the privacy policy of the website or app you were using, since the publisher controls the consent collected on that property. You can also contact us directly at [email protected] and we will route your request appropriately.

7. Data retention

Aggregated reporting data is retained for as long as needed to provide your dashboard history and meet our reconciliation and audit obligations. Raw bid-request-level logs are retained for a shorter operational window sufficient for fraud detection, debugging, and billing reconciliation, after which they are deleted or aggregated.

8. Security

We apply administrative, technical, and physical safeguards designed to protect the data we process, including access controls on our dashboard and encryption of data in transit. No system is perfectly secure, and we encourage you to report any suspected vulnerability to [email protected].

9. Children's privacy

Atlas5 relies on the COPPA signal (regs.coppa) sent by publishers to identify requests subject to child-directed protections, and restricts behavioral targeting and syncing on flagged requests accordingly. Publishers with child-directed properties are responsible for setting this signal correctly on every request.

10. Changes to this policy

We may update this policy as our practices or applicable law changes. Material changes will be reflected by an updated "Last updated" date at the top of this page.

11. Contact

Questions about this policy can be sent to [email protected].