Privacy Policy
Last updated: August 7, 2026
1. Who we are
Last Best Digital LLC, doing business as CriterionIQ ("CriterionIQ," "we," "our," or "us"), is a cross-channel marketing intelligence, execution, and signal platform. This Privacy Policy explains how we collect, use, store, and share information when you visit criterioniq.com or use our platform (collectively, the "Service"). If you're a business customer, our processing of personal data on your behalf as part of the Service is governed by our Data Processing Agreement, which forms part of your agreement with us.
2. Information we collect
We collect information in the following ways:
- Account information. When you sign up or request an audit, we collect your name, work email address, company website, and any notes you choose to share.
- Connected platform data. With your explicit permission, we connect to your marketing accounts, including Meta (Facebook Pages, Instagram business accounts, and ad accounts), TikTok, Google, LinkedIn, and other advertising and social platforms you connect, via their official APIs to retrieve the data needed to provide the Service. From Meta this includes Facebook Page and Instagram content and insights (such as posts, media, engagement, reach, and impressions), ad account reporting, and the list of assets you authorize us to access. We request read access for reporting, and management access only where you enable a feature (such as audience or conversion activation) that requires it. This data is used only to provide the Service to you and only within the scope permitted by each platform's developer terms.
- Lead and engagement data from connected platforms. Where you enable it, and on your behalf as your processor, we receive lead information that people submit through your lead generation forms, events, and campaigns on connected platforms (for example LinkedIn Lead Gen Forms, and equivalent tools on Meta and TikTok), which may include a person's name, email address, phone number, job title, company, and their responses to your form's questions and consent options. We also receive platform-scoped identifiers and engagement signals (such as a stable per-platform user identifier and interactions like reactions, comments, or event registrations on your owned assets). We use this data only to deliver those leads to the destinations you choose, to match them to your own first-party customer records for your reporting, and to honor the consent each person gave on your form. We do not sell this data or combine it across our customers.
- Public ad library data. Some features use Meta's publicly accessible Ad Library to surface ad creative examples. This data is publicly available and not tied to your connected accounts.
- Tracking and signal data. If you use our Signal IQ or Conversion API Gateway features, we process conversion events, pixel data, and identity signals on your behalf as a data processor. Personal identifiers in these events are hashed before they are sent to any advertising platform. Because we run the gateway ourselves rather than routing your data through a third-party conversion API vendor, we generally act as your processor rather than a party that owns or resells this signal. See Section 6 for the full detail.
- Usage data. We automatically collect log data, browser type, IP address, pages visited, and feature interactions to operate and improve the Service.
- Cookies. We use essential cookies for authentication and session management, and controlled analytics and advertising cookies, including cookies that support our own marketing and retargeting, to understand how the platform is used. See our Cookie Policy for the full list of cookies, providers, and how to control them.
3. How we use your information
- To provide, operate, and improve the Service
- To generate performance briefs, audits, and intelligence reports on your behalf
- To send transactional emails (audit delivery, account notices)
- To respond to support requests
- To detect and prevent fraud, abuse, or security incidents
- To comply with legal obligations
We do not sell your data. We do not use your ad account data or any data obtained through third-party platform APIs to train AI models. Platform API data is used solely to provide the Service to you within the scope permitted by each platform's developer policies.
4. How we share your information
We share data only in the following circumstances:
- Service providers. We use third-party vendors (cloud infrastructure, database providers, email delivery) who process data solely on our behalf under contractual data protection obligations.
- AI processing. Some features use AI models to generate analysis and recommendations. Raw data obtained through third-party platform APIs (Meta, TikTok, Google, etc.) is never transmitted to external AI providers. AI models receive only internally computed aggregations and anonymized summaries derived from your data, and only to the extent necessary to provide the Service to you. See our AI Policy for which AI provider we use, what it does and doesn't do with that data, and how long outputs are retained.
- Legal requirements. We may disclose information when required by law, court order, or to protect the rights and safety of CriterionIQ, our users, or the public.
- Business transfers. If CriterionIQ is acquired or merges with another entity, your data may transfer as part of that transaction, subject to equivalent privacy protections.
5. Third-party platform API data
When you connect a third-party advertising platform (Meta, TikTok, Google, LinkedIn, and others), we access your account data through that platform's official API under your authorization. Our use and transfer of information received from the Meta APIs, including data from Facebook and Instagram, adheres to the Meta Platform Terms and Developer Policies, including any limited-use requirements. Our use of data received from the LinkedIn Marketing APIs, including LinkedIn Lead Sync, complies with the LinkedIn API Terms of Use and Marketing Developer Platform policies; we access only the data belonging to the account you authorize, use it solely to provide the Service to you, and do not use it to independently profile LinkedIn members. We are committed to the following:
- Platform API data is used only for the specific purpose of providing the Service to you and only within the scope permitted by the applicable platform's developer policies.
- We do not sell, rent, or share platform API data with unauthorized third parties.
- We do not use platform API data to build, train, or improve AI or machine learning models.
- We do not use platform API data to build products or services that compete with those platforms.
- We do not combine platform API data with data from other sources in ways that violate the applicable platform's terms.
- You may revoke our access to your connected accounts at any time through the platform's own settings or by contacting us.
6. The Conversion API Gateway and Signal IQ
CriterionIQ operates its own first-party Conversion API (the "Conversion API Gateway"). Unlike platforms that route your conversion data through a third-party conversion API vendor, we run the gateway ourselves; your visitors' events flow from your own website to your own advertising destinations, with CriterionIQ generally acting as your data processor rather than a party that owns, resells, or independently monetizes your signal.
How it works
- First-party collection. Conversion events (such as page views, leads, and purchases) are collected on your own domain or a subdomain you control, not on a CriterionIQ tracking domain shared across customers.
- Server-side hashing. Before any personal identifier (email, phone number, name, address, or external ID) is sent to an advertising platform, we normalize and irreversibly hash it with SHA-256 on our servers. We do not transmit plaintext personal data to ad platforms.
- Match quality. To improve attribution accuracy, we process first-party signals such as advertising-platform cookies (for example
_fbp,_ttp,_gcl) and a durable first-party visitor identifier. Where these contain personal data, they are hashed before transmission. - Deduplication. Browser-side and server-side events are matched on a shared event ID so each conversion is counted once, not twice.
- You choose the destinations. Events are forwarded only to the advertising platforms you connect and authorize (for example Meta, Google, TikTok, LinkedIn, Pinterest, GA4). We do not add destinations of our own.
- Identity resolution. To power cross-device and household-level measurement for your own account, the Service builds first-party identity resolution, a durable pseudonymous identifier and related device/household linkages, from your own visitors' data. This is a feature of the Service, built to serve your reporting and activation; it is never sold, licensed, or shared with other customers or third parties.
Because we run the gateway ourselves, we can keep data handling tightly scoped and aligned with industry-standard practices. As a general practice, with your conversion and identity data we commit to:
- not selling, renting, or licensing your conversion or identity data, or the identity resolution we build for you, to any third party;
- not pooling or combining your identifiable conversion or identity data with another customer's data into a shared or cross-customer identity graph;
- not enriching your events with data purchased from third-party data brokers; and
- not using your identifiable conversion or identity data to train AI or machine-learning models (see Section 4 and our AI Policy; AI features only ever receive aggregated, de-identified summaries).
On a limited basis, after data has been aggregated and de-identified such that it no longer identifies your business or any individual, CriterionIQ may use it for cross-client benchmarking and to improve its own internal models. This is narrower than, and does not conflict with, the commitments above; it's described in full, including the de-identification standard, in our Data Processing Agreement.
We handle conversion and identity data in line with industry-standard practices: identifiers are hashed, retained only as long as reasonably needed to deliver and reconcile events (see Section 7), and you generally act as the data controller while we act as your processor, so you can disable the gateway or request deletion. For the full detail on our data-handling practices and obligations as your processor, see our Data Processing Agreement, or contact us at [email protected] for a signed copy.
7. Data retention
We retain account data for the duration of your active relationship with us, plus a reasonable period thereafter for legal and operational purposes. Ad platform data connected for audits is deleted or returned to read-only archive within 30 days of your request. Lead and identity data received through connected platforms is retained on your behalf while your account is active and until you delete it, and is removed within 30 days of your, or the relevant individual's, deletion request. Conversion and identity event data processed through the Conversion API Gateway (Section 6) is retained for up to 365 days from collection and then purged in the ordinary course; backup copies are retained only within our standard backup rotation and are not otherwise accessed or used. You may request deletion at any time (see Section 9).
8. Security
We encrypt data in transit (TLS) and at rest. Production customer data runs on isolated tenants. We conduct regular reviews of our access controls and security practices. No system is perfectly secure; if you discover a vulnerability, please contact us at the address below.
9. Your rights and choices
Depending on where you are located, you may have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability where technically feasible
To exercise any of these rights, email us at [email protected]. We may ask you to verify your identity before completing your request, for example, by confirming account details we already have on file. We will respond within 30 days.
For data obtained through a connected platform such as Meta (Facebook and Instagram), you can also revoke our access at any time by removing CriterionIQ from your Facebook or Instagram app settings. To have the associated data erased, follow our data deletion instructions.
10. Third-party links and integrations
The Service connects to third-party ad platforms (Meta, TikTok, Google, LinkedIn, and others). Once you leave our platform, those parties' privacy policies govern. We are not responsible for their data practices.
11. Children's privacy
The Service is intended for business users aged 18 and older. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date above and, where appropriate, by email. Continued use of the Service after changes take effect constitutes acceptance.
13. Contact
Questions about this policy? Reach us at [email protected].