Built for privacy by design.
SegmentHub processes first-party behavioural data on your behalf. This page sets out how that data is handled, what controls you get, and where your data can live.
GDPR and CCPA tooling
Purpose-scoped consent, subject access exports and right-to-erasure handling are part of the platform rather than something you build around it — and an erasure returns a signed receipt naming every store it reached. See Consent & Privacy.
Identifiers are hashed before they leave
Audiences pushed to advertising networks carry normalized SHA-256 hashes, never raw email addresses. Profiles without an identifier a destination can match are excluded from the upload rather than padded in.
On-premise and private cloud
Where regulation or policy requires data to stay inside your own infrastructure, SegmentHub can be installed there instead of running on our managed cloud. Available on the Enterprise plan.
Destination credentials stay write-only
API tokens and secrets for connected ad networks are entered once and never displayed again in the panel. They can be replaced or deleted at any time, which immediately stops the synchronization that used them.
What we process, and why
| Data | Purpose | Leaves your account as |
|---|---|---|
| Behavioural events | Page, product, search and purchase activity used to build segments | Does not leave; used to compute membership |
| Profile identifiers | Resolving activity across devices to one person | SHA-256 hashes, only to destinations you connect |
| Segment membership | Targeting and personalization | As audience lists in the ad networks you enable |
| Messaging addresses | Delivering email, SMS, WhatsApp and push you have consent for | To your own relay, gateway or push service — never ours |
| Consent decisions | Recording and enforcing what each person agreed to, per purpose | Retrievable on request with their evidence; kept in a durable ledger |
| Exported datasets | Loading your own data into your own warehouse | Only to the storage bucket you nominate, under your credentials |
| Destination credentials | Authenticating audience synchronization and message delivery | Never displayed or exported |
Subject rights, end to end
The usual gap in a data platform is not refusing a request — it is not being able to say what happened to every copy. SegmentHub owns each of its own stores, so one request reaches all of them and produces an artefact you can hand to a reviewer.
Consent per purpose
Analytics, advertising, personalization, email, SMS and push are decided separately and recorded with their source, timestamp, the wording shown and the notice version. "Never asked" is stored as a distinct state from "declined".
Enforcement at collection
A consent gate can run when an event arrives, not just before a message goes out. Choose per account between recording only, pseudonymising events that lack the purpose, or dropping them outright. IAB TCF v2.2 strings are read directly.
Access requests
One authenticated call returns everything held about a data subject: the visitor record, the linked customer profile, every consent decision with its evidence, and their suppression status.
Erasure with a signed receipt
Queued, audited and fanned out across every profile-store shard, both search indices and the shared caches. The receipt names each store, holds no personal data itself, and is re-verified every time the privacy report is opened.
Two things are deliberately kept. An opt-out entry survives erasure in anonymised form, because deleting it would silently re-enable messaging that person the moment they appeared again. The audit trail survives too, because it is the evidence of what the platform did — including the erasure. A per-account data region is recorded alongside the on-premise option above for the residency conversation. Full detail on the Consent & Privacy page.
Auditability
Every audience synchronization is recorded: when it ran, the source audience size, how many records were eligible, how many were added, removed or rejected, how long it took, and the error returned if it failed. If a network stops accepting an audience you can see exactly when that started and what it objected to, rather than discovering it through a campaign that quietly underperforms.
You do not have to go looking. An expired destination token, an unusual rejection rate, a relay or gateway that has started refusing sends, and a drop in event volume against the same hour on the same weekday each raise an alert to email and a webhook — one per broken thing, closed automatically with a recovery notice. See Alerts & Health.
Our privacy policy covers what we collect on this website and how to reach us about it; the terms of service govern use of the platform, and cookie settings control what this site itself stores.
Enterprise operations
Controls for teams that need accountability, repeatable configuration and limited access—not a shared administrator login.
Immutable activity history
Account mutations are written to a centralized audit record, while the activity report makes changes reviewable by actor, time and affected resource.
Granular team permissions
Separate view and manage rights for audiences, campaigns, reports, media, members, settings, webhooks, API tokens and publishing.
Scoped API access
Create managed API tokens for application workflows instead of distributing member credentials or granting broader panel access.
Portable configuration
Export account configuration, preview an import and apply reviewed changes so setup can be reproduced across controlled environments.
Going through a security review?
Procurement and information-security teams usually need specifics: data residency, retention periods, sub-processors, encryption, access control, incident response and a data processing agreement. We answer those directly, against your questionnaire, rather than in marketing copy — and the Enterprise plan includes support through the review itself.
Request security documentationOr email [email protected] directly.