Skip to content
Code samples below use example values.

Suggested privacy-policy wording ​

If your site runs Prism, your privacy policy needs to describe it. This page gives plain-English paragraphs you can adapt. Delete anything that doesn't apply to your site and fill in the [bracketed] parts.

Not legal advice

This is template language, not legal advice. Review it with your counsel before publishing, especially if you serve visitors in the EU, UK, California or other regulated jurisdictions. For the broader controller obligations, see Required disclosures.

Measurement and advertising ​

How we measure our website and advertising. We use Adsidian Prism, a first-party measurement service that runs on our own domain ([track.yourdomain.com]), to understand how visitors use this site and which of our advertisements lead to enquiries or purchases. When you visit, Prism records the pages you view and actions you take, such as submitting a form or completing a purchase, together with technical information such as your browser type, the referring page, the advertising campaign that brought you here, and your IP address. By default your IP address is shortened before it is stored.

Information from forms and purchases ​

Information you give us. When you submit a form or complete a purchase, we may record your email address, phone number, first and last name, city, state, ZIP or postal code, and date of birth, where you provide them. These details are converted into an irreversible code (a SHA-256 hash) in your browser before they are sent to our measurement service, so the original values are not transmitted by the measurement script. [We do not use measurement tracking on forms that ask for sensitive information.]

If any of your forms collect sensitive details, exclude them from capture with data-prism-ignore (see Privacy & consent) and keep the bracketed sentence only if it is true.

Cookies ​

Cookies. Our measurement service sets the following first-party cookies:

  • A visitor identifier (adsidian_id), used to recognize the same browser across visits. It lasts up to one year. On Shopify stores a similar identifier (_prism_aid) is set by our measurement pixel.
  • Ad click identifiers (cookies beginning _prism_, for example _prism_gclid or _prism_fbclid), which remember which advertisement you clicked so we can credit it. They last up to 90 days and are only written when the identifier appears in the address you arrived from.
  • A Meta browser identifier (_fbp), used to match visits to Meta advertising. It lasts up to 90 days and is only set if you have not declined advertising cookies.

Sharing with advertising platforms ​

Sharing with advertising platforms. Where you have not opted out, we share conversion events, such as a form submission or purchase, and the hashed identifiers described above with the advertising platforms we use [Meta, Google, LinkedIn, Reddit, ChatGPT/OpenAI Ads], so they can measure and improve our advertising. These platforms handle that data under their own privacy policies. Some laws treat this as "sharing" or "sale" for targeted advertising; you can opt out using [our cookie settings / our "Do Not Sell or Share My Personal Information" link].

List only the platforms you have enabled in Prism.

Opt-out signals. If your browser sends a Global Privacy Control signal (Sec-GPC: 1), or you decline advertising or marketing cookies in our consent banner, we do not share your browsing activity with advertising platforms. If an order can be linked to that same browsing session, we withhold the order from them too. A purchase that cannot be linked to a browser that opted out may still be shared with the advertising platforms we use. We may still keep a first-party record of your visit for our own analytics.

This is how Prism behaves: a Global Privacy Control signal or a consent denial means browser events are stored first-party and never forwarded, and orders linked to that browsing session are withheld as well. Orders reported by your store's servers that can't be linked to an opted-out session may still be forwarded to the platforms you enable. Linking is by Prism's stored visitor identity, not by matching email addresses. See Consent integration.

Retention and your rights ​

How long we keep it. We keep measurement records for up to [13 months] and then delete them automatically. You can ask us to access or delete the information we hold about you by contacting [your contact details]. We will ask our measurement provider to remove or anonymize the matching records. Information already delivered to an advertising platform is held by that platform; use its own privacy controls to manage it.

Prism's default retention is 395 days (about 13 months) and is configurable per client, so change the figure if your agency set a different window. Deletion requests are handled by anonymizing the matching records.

Service providers ​

Our providers. Adsidian processes this data on our behalf as our service provider, using the subprocessors listed at docs.adsidian.ai/privacy/subprocessors.

Next ​

Adsidian Prism — first-party server-side tracking.