Legal

Privacy

What we collect when we serve an advertisement, who receives it, how long we keep it, and what you can ask us to do about it.

Last updated August 27, 2026

PLUSONE ("we", "us") operates plusoneads.com, the ad serving domain for n+1 audience extension. When an advertisement carries this domain, we served it, ran the auction that selected it, and measured it on behalf of a publisher or an advertiser. This policy explains what that involves from a data perspective.

Two groups of people are covered here. Readers encounter advertising served through this domain on publisher websites and apps. Customers are the publishers, demand partners, and advertisers who hold accounts with us. Most of this policy concerns readers.

1. Consent comes before identity

Before an advertisement uses any persistent identifier, our tag reads the consent signals available on the page. We support the IAB Transparency and Consent Framework (TCF v2) and the IAB Global Privacy Platform (GPP). We independently honor Global Privacy Control and Do Not Track, both from the browser and from the request headers, and we honor the Limit Ad Tracking signal on mobile.

Every request resolves to three separate permissions, which are whether we may set a cookie, whether we may use an advertising identifier, and whether we may use precise location. If we cannot positively establish permission, all three default to denied. Our servers independently re-check the raw privacy signals and may only tighten the browser's decision, never loosen it. A request originating in the EEA or the UK is restricted unless a complete and readable TCF signal is present.

Consent governs identity, not whether an advertisement appears. A reader who has declined, or whose consent we cannot read, may still see an advertisement. When permission is absent we do not merely withhold cookies. Any tracking cookies already present are actively expired on the response, the reader's IP address is truncated before it reaches any demand partner, and city, latitude, and longitude are omitted.

2. Cookies and identifiers

Our cookies are set on our own domain rather than the publisher's, so from the publisher page they are third-party cookies. All are marked Secure and HttpOnly. We set none of them when permission is absent.

We do not use browser local storage or session storage, and we do not fingerprint devices. We do not run canvas, audio, or font enumeration, and we use no third-party analytics software in our advertising units.

3. What an advertising request contains

When a publisher page asks us for an advertisement, the request carries the page address or app identifier, the placement, device type, operating system and browser information, approximate location, the applicable consent signals, and, only where permission exists, the sync identifier. Approximate location means country and region. City and precise coordinates are used only where permission for precise location was established.

Advertising requests are sent to demand partners so they can bid. Those requests contain the same fields, and they contain the sync identifier only where permission exists. Where permission is absent, the IP address in those requests is truncated and precise location is removed. Demand partners are contractually bound to use the request only to decide whether and how much to bid.

4. What we keep

5. Who else processes this data

We use Google Cloud for storage, analytics, and application hosting, OVHcloud for the servers that run the auction, and Cloudflare in front of our services. Demand partners receive advertising requests as described in section 3. Where an advertiser uses our AI creative generator, the brief they supply is sent to OpenAI to produce the creative. No reader data is involved in that step.

6. What customers receive

Publishers see reporting on the advertising served on their own properties. Advertisers and demand partners see reporting on their own campaigns, deals, and endpoints. Demand partners can inspect samples of the requests sent to their own endpoints and the responses they returned. Customer data is isolated per account, and no customer can retrieve another customer's records.

We do not sell reader data. No name, email address, telephone number, or account credential is collected from readers in the first place.

7. Your choices

You can decline through the consent prompt on the publisher's website, and we will honor it. You can enable Global Privacy Control in your browser, and we honor that signal independently of any publisher prompt. You can also clear or block our cookies in your browser settings, which stops user sync and frequency capping.

To opt out of identity and tracking across our platform, or to ask about the data associated with your browser, write to [email protected]. We handle these requests manually today rather than through a self-service portal. Because we hold no account, name, or email address for readers, we can generally only act on a request when you can supply the identifier from your browser, and a reader who has cleared cookies cannot be located in our records at all.

8. Children

Our platform is intended for advertising on general-audience publications and applications and is not directed to children. We do not knowingly collect information from children, and we honor the child-directed flag when it is supplied to us in an advertising request.

9. International transfers

We are based in the United States and our service providers process data in the United States and the European Union. If you are reading this from elsewhere, your information may be transferred there.

10. Changes and contact

If we change this policy we will update the date at the top of this page. For any privacy question, or to exercise a right described above, write to [email protected]. For anything else, [email protected].