Legal & Compliance

Privacy Policy

Last Updated: August 15, 2024

Bliz ("we," "our," or "us") provides first-party server-side marketing attribution and data infrastructure. This Privacy Policy outlines how we collect, use, process, and protect data. Because of the nature of our infrastructure, we distinguish between Customer Data (information about the businesses that use our platform) and End-User Data (information about the individuals who interact with our Customers' links and websites).

1. Our Role as a Data Processor

Bliz operates as a Data Processor (or Service Provider) under GDPR and CCPA. Our Customers (the brands and agencies using Bliz) are the Data Controllers. We deploy our tracking infrastructure on our Customers' own subdomains (e.g., go.brand.com). All End-User Data captured via our edge routing and tracking scripts is owned by the Customer and processed strictly according to their instructions (e.g., routing data to Meta Conversions API or Google Ads).

2. Information We Collect

A. End-User Data (Processed on behalf of our Customers)

When an end-user clicks a Bliz attribution link or visits a Customer's website where the Bliz 1st-party script is installed, our edge servers collect:

  • Device Physics & Network Data: IP address (hashed/anonymized depending on Customer settings), User-Agent, Operating System, Screen Resolution, Device Pixel Ratio, and Timezone. This is used for probabilistic session matching.
  • Attribution Identifiers: Click IDs (e.g., fbclid, gclid) and UTM parameters.
  • On-Site Behavior: Page views, button clicks, and form submission events.
  • Conversion Data: Transaction IDs and purchase values (Revenue Events).
  • Hashed PII: If a user submits an email or phone number during a conversion, the Bliz script utilizes SHA-256 hashing at the browser level before transmitting the data to our servers for API syndication (e.g., Meta CAPI). We do not store raw End-User PII in our logging databases.

B. Customer Data (Your Account)

If you are a marketer or agency utilizing the Bliz platform, we collect:

  • Account credentials, names, and work email addresses.
  • Billing and payment information (processed securely via Stripe).
  • API keys and authentication tokens for third-party platforms (stored securely to enable Conversions API routing).

3. Cookies & First-Party Edge Tracking

Bliz does not use third-party tracking cookies. We provide infrastructure that allows our Customers to set first-party, server-set cookies on their own domains.

Technical Implementation

During the initial edge redirect, the Bliz server issues a Set-Cookie header (e.g., _fpc_brand_sid).

This cookie contains a JWE-encrypted session identifier used exclusively to map an ad click to a subsequent conversion on the Customer's website. It cannot be read by other websites (it is strictly SameSite=Lax/Strict) and is not used to track users across the independent web.

4. Data Sharing & Third-Party APIs

We do not sell End-User Data or Customer Data.

End-User Data is routed dynamically based entirely on the Customer's configuration. If a Customer connects their Meta, Google, or TikTok accounts to Bliz, our backend automatically securely forwards conversion events (via Server-to-Server CAPI) to those platforms. Bliz simply acts as the secure pipeline and attribution ledger.

5. Data Retention & Security

Security: All data is encrypted in transit using TLS 1.2+. Session identifiers are JWE-encrypted. Sensitive API credentials provided by Customers are encrypted at rest.

Retention: End-User conversion ledgers and analytics are retained based on the Customer's active subscription tier (e.g., 90 days, 180 days, or 1 year) to allow for accurate ROAS reporting. Upon subscription termination or deletion of a project, all associated End-User Data is hard-deleted from our databases.

6. Your Rights (GDPR & CCPA)

Because Bliz processes End-User Data on behalf of our Customers, end-users seeking to exercise their rights (e.g., access, deletion, or opt-out) should contact the Customer (the brand) directly. Bliz provides our Customers with the tooling necessary to fulfill these requests and delete specific session ledgers upon demand.

If you are a Customer (Bliz account holder), you may access, modify, or delete your Account Data at any time via the Bliz Dashboard or by contacting support.

Contact Us

If you have any questions about this Privacy Policy or our infrastructure security practices, please contact our compliance team:

info@bliz.cc