Appearance
Required disclosures for your privacy notice
When you deploy Prism on your website, you are the controller (GDPR) / business (CCPA) for the data it collects, and your privacy notice must disclose that processing. Adsidian processes the data as your service provider under the Data Processing Agreement.
This page is template language you can adapt. It is not legal advice — have your counsel review your notice for your jurisdictions.
What Prism collects (disclose all of it)
- Page views and conversion events (server-side, first-party)
- A first-party visitor identifier cookie (
adsidian_id, up to 1 year) and ad click-ID cookies (90 days) - IP address and browser user-agent (IP can be truncated — ask your agency to enable IP anonymization)
- Where you pass them on lead/purchase events: SHA-256 hashed email, phone, name, city/state/zip, and date of birth (hashed in the visitor's browser; raw values are never transmitted)
Where it goes (disclose the sharing)
Events may be delivered, subject to the visitor's consent, to the advertising platforms you use — Meta (Conversions API) and Google Ads — to measure and optimize your advertising. Under CCPA/CPRA this delivery may constitute "sharing" for cross-context behavioral advertising; your notice should offer a "Do Not Sell or Share My Personal Information" mechanism, which you can honor via consent integration (a denial suppresses ad platform delivery automatically).
Template language
Analytics and advertising measurement. We use Adsidian Prism, a first-party measurement service, to record page views and conversions on this site. Prism sets a first-party identifier cookie (up to 1 year) and click-attribution cookies (90 days), and records your IP address and browser type. When you submit a form or make a purchase, your email, phone number, and similar contact details are irreversibly hashed in your browser before transmission. Subject to your consent choices, hashed identifiers and conversion events are shared with the advertising platforms we use (Meta, Google) to measure and improve our advertising. Raw event data is retained for up to 13 months. To opt out of this sharing, use our cookie settings [link] or the "Do Not Sell or Share" link [link]. To exercise access or deletion rights over this data, contact us at [your contact]; requests are fulfilled with our provider's assistance.
Adjust the retention figure if your agency configured a different window, and add Prism to your notice's processor/subprocessor list (Adsidian — subprocessors).
Data subject requests
When a visitor asks you for access or deletion, forward the request to your agency or [email protected] with the visitor's email address (or their adsidian_id cookie value). Deletion and export are fulfilled within the GDPR/CCPA statutory windows. Remember that Meta and Google retain what was already delivered to them — your notice should point users to those platforms' own controls for that data.
Special categories — do not send
Never pass health conditions, financial account details, government IDs, or data about children through Prism event properties. See the acceptable-use terms in the Adsidian Terms of Service.