Built for privacy by design.
SegmentHub processes first-party behavioural data on your behalf. This page sets out how that data is handled, what controls you get, and where your data can live.
GDPR and CCPA tooling
Consent management, data anonymization and handling of "right to be forgotten" requests are part of the platform rather than something you build around it.
Identifiers are hashed before they leave
Audiences pushed to advertising networks carry normalized SHA-256 hashes, never raw email addresses. Profiles without an identifier a destination can match are excluded from the upload rather than padded in.
On-premise and private cloud
Where regulation or policy requires data to stay inside your own infrastructure, SegmentHub can be installed there instead of running on our managed cloud. Available on the Enterprise plan.
Destination credentials stay write-only
API tokens and secrets for connected ad networks are entered once and never displayed again in the panel. They can be replaced or deleted at any time, which immediately stops the synchronization that used them.
What we process, and why
| Data | Purpose | Leaves your account as |
|---|---|---|
| Behavioural events | Page, product, search and purchase activity used to build segments | Does not leave; used to compute membership |
| Profile identifiers | Resolving activity across devices to one person | SHA-256 hashes, only to destinations you connect |
| Segment membership | Targeting and personalization | As audience lists in the ad networks you enable |
| Destination credentials | Authenticating audience synchronization | Never displayed or exported |
Auditability
Every audience synchronization is recorded: when it ran, the source audience size, how many records were eligible, how many were added, removed or rejected, how long it took, and the error returned if it failed. If a network stops accepting an audience you can see exactly when that started and what it objected to, rather than discovering it through a campaign that quietly underperforms.
Our privacy policy covers what we collect on this website and how to reach us about it; the terms of service govern use of the platform, and cookie settings control what this site itself stores.
Going through a security review?
Procurement and information-security teams usually need specifics: data residency, retention periods, sub-processors, encryption, access control, incident response and a data processing agreement. We answer those directly, against your questionnaire, rather than in marketing copy — and the Enterprise plan includes support through the review itself.
Request security documentationOr email [email protected] directly.