Compliance for Audiences

What you are responsible for before sharing an audience with an advertising platform - BAAs, hashing, audience naming, consent, and exactly what leaves Ours Privacy.

Use this page before you send an audience to an advertising platform. It covers what Ours Privacy does on your behalf, what it deliberately does not do, and what remains your decision.

This page describes product behavior and the terms you accept in the product. It is not legal advice, and your own counsel is the right party to tell you whether a particular audience may be shared.


The four things to know

These are the points you confirm in the product before an audience can sync, restated here so you can read them without a dialog in the way.

Advertising platforms are not HIPAA business associates. Vibe, Meta, and Google do not sign business associate agreements, and their terms prohibit uploading protected health information or consumer health data. A platform that will not sign a BAA is, under HHS guidance on tracking technologies, a party that may only receive de-identified data.

Hashing an identifier does not make it anonymous. Whether it is an email address, a name, or a phone number, the platform matches the hash back to a person, and that matching is the entire purpose of the upload. Treating SHA-256 as a safeguard is a specific and expensive mistake: the FTC has charged companies on the basis that hashed identifier uploads were disclosures of the underlying identity.

The audience's Export Name travels with it. That is the only name the platform sees; your internal name never leaves Ours Privacy. Meta prohibits audience names that reflect or imply health information, and the Export Name is displayed verbatim in the platform's interface, so it must not describe a condition, treatment, or medication. Choosing a name that satisfies that is yours to do — see Naming an audience you are about to share below.

You are responsible for having a lawful basis. That includes any consent your visitors must give before you share them with a platform. Building an audience does not automatically consider a visitor's consent status: an audience of "viewed a page in the last 30 days" matches everyone who did, whatever they told your banner, and a sync sends exactly the audience you defined. If consent matters for this audience, require it in the audience itself.


The data-sharing acknowledgement

Before an audience can sync anywhere, someone on your account accepts data-sharing terms covering the four points above, and confirms that they have the authority and a lawful basis to share the audience with the selected platforms and that the audience does not contain protected health information or consumer health data.

The acceptance is recorded on the audience with who accepted it, when, and which version of the terms they saw. The Sync to Destinations card shows the date it was accepted.

Two behaviors worth knowing. The version is stored rather than a plain yes, so an acceptance of one version of the terms is never later presented as acceptance of a different one. And removing the last destination from an audience clears the acknowledgement, so re-enabling a sync later means reading and accepting the terms again rather than inheriting a decision somebody made months ago.


Ours Privacy does not filter an audience on consent. A sync sends the audience as you defined it, and so does a CSV. If consent should bear on who is shared, add it to the audience as a condition.

Two conditions cover the common cases, both on the Visitor Properties card:

  • Opt-out posture — Rejected Consent Categories does not contain advertising. Excludes recorded rejections. A visitor with no consent record is not a rejection and still matches.
  • Opt-in posture — Accepted Consent Categories contains advertising. Matches only visitors who actively accepted, which is a much smaller audience if most of your traffic predates your banner.

Because the condition lives in the audience, the preview counts it: what you see before you sync is what the sync sends. See Visitor conditions.


Naming an audience you are about to share

The Export Name is rendered verbatim in the advertising platform's own interface. That makes the name a piece of information the platform receives, separate from the member list.

Consider an audience called diabetes-followup-q3. Every identifier in it is hashed, and no condition or criteria are sent. The platform still learns that the people in that list were grouped by a diabetes-related concern, because the name says so and the membership says who. Hashing protects the identifiers; the name is not an identifier.

The platforms require this of you directly. Meta's Business Tools Terms state that the names you choose and criteria you establish for custom audiences must not reflect, imply, or be based on health information. Google's Customer Match policy prohibits lists that contain or imply sensitive information including health conditions. The FTC has charged companies over exactly this: the GoodRx complaint identified custom audiences named after specific medications and conditions.

Choosing the name is yours. Put the description in Name, which never leaves Ours Privacy, and press Generate for the Export Name. An audience named Post-Discharge Follow-Up, No Appointment Booked internally with an Export Name of copper-lantern-cove gives you both: your team knows what the audience is, and the platform learns nothing.

Rewording a descriptive name is not the fix — it usually produces a slightly less obvious descriptive name, which is the same disclosure with extra steps. Move the meaning to the internal field instead. See Export names.


What actually leaves Ours Privacy

For a sync, two things: the audience's Export Name, and one hashed email address per member. The address is hashed with SHA-256 in the form the receiving platform specifies. Nothing else goes: not names, not phone numbers, not addresses, not your conditions, not your internal audience name, not counts.

For a CSV export, what you chose. The all-fields format contains raw visitor values and is for internal use. The Google and Meta formats contain up to six and ten columns respectively, hashed to each platform's specification. You control where that file goes, which makes a downloaded CSV the higher-risk artifact of the two. See Exporting a CSV.

Your internal name, your conditions, and every visitor attribute outside the chosen export never leave.


Evidence for a compliance review

If you are the person who has to show an auditor what happened, three things are worth knowing about where the record lives.

The acknowledgement is the receipt for the decision. Who accepted the data-sharing terms, when, and which version they saw is recorded on the audience itself and shown in the Sync to Destinations card. That is the artifact that answers "who authorized sharing this audience."

The audience definition is the record of who was included. Because an audience is a set of conditions rather than a saved list, the conditions are the documentation of the population. Keeping the internal Name descriptive is what makes that legible six months later.

Wider organizational activity has its own tools. For periodic access and configuration review across your account, see Audit Log. For what is being forwarded to which third parties across the platform, see Compliance Report and Consent Analytics.


Audience size and re-identification

Platform minimums exist partly for privacy reasons: a very small audience makes the people in it easier to single out. Meta's guidance for a customer list is at least 1,000 people, and Google recommends at least 5,000 members for a Customer Match list to have a reasonable chance of serving.

A tiny audience is worth a second look for a reason beyond targeting effectiveness. An audience of eleven people sent to a platform under any name is a much more specific statement about those eleven people than a list of fifty thousand.


Practices worth adopting

Name the audience for your team, not for the platform. Descriptive internal name, meaningless Export Name, every time. See Export names.

Put consent in the audience. Nothing applies it for you. If consent bears on whether someone may be shared, it belongs in the conditions, where you can see it and the preview counts it.

Decide who may accept the terms. The acknowledgement is a statement about your organization's authority and lawful basis. Accepting the terms and selecting destinations are governed by permissions, so the people who can do it should be the people who can make that statement. Ask your account administrator about access.

Review synced audiences on a schedule. A daily sync keeps running until somebody stops it. An audience built for a campaign that ended six months ago is still being sent.

Treat downloaded CSVs as the loose end. A file on somebody's laptop has left every control the platform gives you. A recent export can be downloaded again from the audience, so re-downloading when you need it is usually better than keeping a copy.


Next Steps

Need help? Contact support@oursprivacy.com.

How is this guide?

On this page