Skip to content
Security & privacy

Built for privacy by design.

SegmentHub processes first-party behavioural data on your behalf. This page sets out how that data is handled, what controls you get, and where your data can live.

GDPR and CCPA tooling

Consent management, data anonymization and handling of "right to be forgotten" requests are part of the platform rather than something you build around it.

Identifiers are hashed before they leave

Audiences pushed to advertising networks carry normalized SHA-256 hashes, never raw email addresses. Profiles without an identifier a destination can match are excluded from the upload rather than padded in.

On-premise and private cloud

Where regulation or policy requires data to stay inside your own infrastructure, SegmentHub can be installed there instead of running on our managed cloud. Available on the Enterprise plan.

Destination credentials stay write-only

API tokens and secrets for connected ad networks are entered once and never displayed again in the panel. They can be replaced or deleted at any time, which immediately stops the synchronization that used them.

What we process, and why

Data Purpose Leaves your account as
Behavioural events Page, product, search and purchase activity used to build segments Does not leave; used to compute membership
Profile identifiers Resolving activity across devices to one person SHA-256 hashes, only to destinations you connect
Segment membership Targeting and personalization As audience lists in the ad networks you enable
Destination credentials Authenticating audience synchronization Never displayed or exported

Auditability

Every audience synchronization is recorded: when it ran, the source audience size, how many records were eligible, how many were added, removed or rejected, how long it took, and the error returned if it failed. If a network stops accepting an audience you can see exactly when that started and what it objected to, rather than discovering it through a campaign that quietly underperforms.

Our privacy policy covers what we collect on this website and how to reach us about it; the terms of service govern use of the platform, and cookie settings control what this site itself stores.

Going through a security review?

Procurement and information-security teams usually need specifics: data residency, retention periods, sub-processors, encryption, access control, incident response and a data processing agreement. We answer those directly, against your questionnaire, rather than in marketing copy — and the Enterprise plan includes support through the review itself.

Request security documentation

Or email [email protected] directly.