Holdout Labs Inc.
Privacy notice
How Holdout Labs collects, uses, stores, and deletes information, including data from connected advertising platforms.
Effective September 4, 2026
Who we are
Holdout Labs is operated by Holdout Labs Inc. This notice applies to the Holdout Labs website, application, and connected data services.
Connected advertising data
With a client's authorization, a workspace administrator may connect a Google Ads or Meta Ads account to Holdout Labs. Holdout Labs uses the connected account data for reporting and analytics that support event-marketing measurement and decision review.
The current connector is read-only. It does not create, edit, publish, delete, or manage advertising campaigns, ad sets, ads, budgets, or audiences in Google Ads or Meta Ads.
Information we collect
We collect account and authentication information needed to operate a workspace, information submitted by a client, and technical records used to secure and support the service. When a client authorizes an advertising-platform connection, we receive the authorization tokens and account identifiers needed to maintain that connection.
Connected Google Ads and Meta Ads data can include advertising-account details; campaign, ad-group or ad-set, ad, and creative metadata; destination URLs and tracking templates; spend, impression, reach, click, interaction, video, and conversion reporting; and geographic, device, network, channel, and conversion-action breakdowns made available by the provider. A client may also provide first-party ticket-sales, event, and campaign context.
Application analytics and your choice
The Holdout Labs application may use product analytics for page views and feature interactions. When configured on an allowlisted application origin, Google Analytics 4 or Google Tag Manager can receive sanitized page metadata, authentication status, user role, and non-PII internal user, organization, workspace, account, and plan identifiers. The event filter drops email-address and phone-number patterns and fields likely to contain names, contact details, free text, secrets, or credentials.
A user can record an allow-or-decline analytics preference for analytics storage through the privacy banner and change it later in Privacy preferences. The application stores that choice in the browser's local storage and applies it through Consent Mode. Advertising storage, advertising user-data, and advertising-personalization settings remain disabled. Depending on deployment configuration, declining analytics storage may still permit limited cookieless measurement signals.
The isolated legal.holdoutlabs.com reviewer site does not load product analytics, execute application JavaScript, or write analytics-preference storage.
How we use information
We use this information to authenticate users; operate, secure, and support the service; show campaign performance; reconcile reporting; produce attribution and incrementality analysis; and prepare decision recommendations for a client's manual review. A recommendation in Holdout Labs is not an instruction sent to an advertising platform.
How we disclose information
We make a client's information available to authorized members of that client's workspace. We may also disclose information to service providers that host, secure, monitor, or support Holdout Labs on our behalf. When an analysis or recommendation feature is enabled, those service providers can include an artificial-intelligence processing provider acting on our instructions. We may also disclose information when required to comply with law, protect rights and safety, or complete a corporate transaction. We do not sell Google Ads or Meta Ads data, and we do not use connected advertising-platform data to target ads on behalf of Holdout Labs or for unrelated third parties.
Holdout Labs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Storage, security, and retention
Connected-account credentials, including stored provider credentials, are kept server-side and encrypted; they are not stored in browser storage. Holdout Labs also uses authenticated, workspace-scoped access controls and TLS-protected service connections. No method of storage or transmission is completely secure, but we limit access to people and systems that need it to operate the service.
We retain identifiable connected-source records only for the active service relationship and the retention period stated in the controlling agreement, unless a verified deletion request or applicable law requires earlier deletion. Disconnecting a provider stops future reads through that connection but does not by itself request deletion of information already imported.
Through our operational deletion process, we delete identifiable connected-source data and customer-linked records derived from it that we control from active systems within 30 days after verifying an authorized deletion request. We may retain limited records only where applicable law requires retention. Residual disaster-recovery copies are restricted from ordinary use and removed through their scheduled backup lifecycle; if restored, the deletion request remains applicable.
Your choices
The person who authorizes a provider connection chooses the account made available to Holdout Labs. An authorized workspace administrator can disconnect the connection. Disconnecting removes the stored provider credentials from Holdout Labs and stops future access through the connection. Access can also be revoked through the applicable Google or Meta account. Previously imported reporting data is handled separately under the retention schedule and verified-request process described above. Instructions for requesting deletion are available on the data deletion page.
Updates to this notice
We may update this notice as the service or applicable requirements change. We will post the updated notice here and revise its effective date. Material changes may also be communicated through the service or another appropriate channel.