Privacy Policy
Last updated: June 2026
Attrivo Intelligence Private Limited ("Attrivo", "we", "us", or "our"), a company incorporated in India with its registered office in Bengaluru, Karnataka, operates a mobile and web attribution, analytics, customer journey, audience segmentation, and engagement platform (the "Platform"), made available through our dashboard, website, software development kits ("SDKs"), and server-to-server APIs.
This Policy explains how Attrivo handles personal data. Because Attrivo's business has two very different data relationships, this Policy is organised around that distinction:
- End User Data — technical and behavioural data we process on behalf of the businesses that integrate the Attrivo SDK or APIs into their own apps and websites ("Customers"), about the people who use those apps and websites ("End Users").
- Direct Data — data we collect ourselves from people who visit attrivo.in, sign up for an account, request a demo, or otherwise deal with Attrivo directly ("Direct Contacts").
1. A Plain-Language Summary
- We are a Data Processor for the technical and behavioural data we handle on behalf of our Customers, and a Data Fiduciary for the data we collect directly about our own website visitors, prospects, and account holders, each as those terms are used under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
- We do not sell personal data, to anyone, for any purpose.
- Attribution inherently involves passing conversion signals to the advertising networks and media partners a Customer has chosen to work with — we explain exactly how that works in Section 3, rather than leaving it out.
- Personal data is stored and processed in India by default. Where a transfer outside India is necessary — for example, because attribution data must reach an overseas advertising partner's servers — we describe the safeguards that apply in Section 7.
- You can reach our Grievance Officer by writing to info@attrivo.in.
2. End User Data — What We Process on Behalf of Our Customers
When a Customer integrates the Attrivo SDK or server-to-server API into its app or website, Attrivo processes certain data about that Customer's End Users solely to deliver attribution, analytics, journey mapping, segmentation, and engagement features that the Customer has configured. Depending on the Customer's configuration, this may include:
- Device and advertising identifiers — such as the Google Advertising ID (GAID) on Android and the Identifier for Advertisers (IDFA) on iOS, where available and permitted by the device's operating system and the End User's platform-level consent choice.
- Network and technical identifiers — IP address, device model, operating system version, app version, and similar technical parameters, some of which may be used to construct a probabilistic device fingerprint for attribution matching where deterministic identifiers are unavailable or restricted (for example, following an App Tracking Transparency opt-out on iOS).
- App and web event data — installs, re-installs, sessions, screen or page views, button taps, purchases, and other in-app or on-site events the Customer has instrumented.
- Approximate location — derived from IP address or device signals, generally no more precise than city level unless the Customer has separately configured and disclosed precise location collection to its own End Users.
- Engagement data — push notification tokens, message delivery, open, and click events, generated where Attrivo sends push notifications directly on a Customer's behalf; and attribution link click and referral data, generated where a Customer uses Attrivo-generated tracking links within its own SMS, WhatsApp, email, or other messaging tools that Attrivo does not itself operate.
- Attribution and marketing touchpoint data — click IDs, referral parameters, and campaign identifiers received through tracking links or install referrers, used to connect an install or event back to the marketing activity that produced it.
Attrivo sends push notifications directly to End User devices where a Customer has configured this feature, using the device's push token and the operating system's native push infrastructure (such as Apple Push Notification service or Firebase Cloud Messaging). Attrivo does not send SMS, WhatsApp, or other telecom-based messages on a Customer's behalf. Where a Customer uses an Attrivo-generated tracking or deep link within its own SMS, WhatsApp, email, or other messaging campaigns, the Customer's own messaging tools and vendors are responsible for that message's delivery, and for compliance with all applicable telecom, consent, and anti-spam regulations governing that channel — Attrivo's role is limited to generating the link and measuring subsequent engagement with it.
Attrivo only sends push notifications to a device where the End User has granted the relevant operating system's notification permission. Attrivo does not attempt to detect, infer, or circumvent an End User's device-level notification permission status, and stops sending push notifications to a device once that permission is withdrawn.
2.1 Attrivo's Role: Data Processor, not Data Fiduciary, for End User Data
Attrivo processes End User Data strictly as a Data Processor, acting only on the documented instructions of the relevant Customer, who is the Data Fiduciary in relation to its own End Users under the DPDP Act. The Customer determines the lawful basis for collecting End User Data, is responsible for providing appropriate notice to and, where required, obtaining consent from its End Users, and is responsible for configuring the Attrivo SDK and dashboard consistently with its own legal obligations. Attrivo does not determine the Customer's consent language, notice content, or lawful basis, and does not independently market to, profile, or otherwise use End User Data for Attrivo's own purposes.
2.2 Aggregated, Anonymised Benchmarking Data
Attrivo may derive aggregated, anonymised statistics from End User Data across multiple Customers — for example, category-level benchmarks such as average install-to-purchase conversion rates for a given app category or region — and may make such aggregated statistics available as industry benchmark reports or similar insights products. Data used in this way is aggregated and processed such that it does not identify, and cannot reasonably be used to re-identify, any individual End User, Customer, or specific app. Customers may write to info@attrivo.in to understand how their data may contribute to such aggregated benchmarks, or to request exclusion from them where technically feasible.
2.3 What Attrivo Does Not Do
Attrivo does not act as an advertising network or a data broker. Attrivo does not buy, sell, rent, or license End User Data to third parties, does not use End User Data to sell targeted or behavioural advertising, and does not build behavioural advertising profiles of End Users for Attrivo's own purposes. Attrivo's use of End User Data is limited to providing the attribution, analytics, journey, segmentation, engagement, and fraud-prevention features that a Customer has configured, and to the aggregated benchmarking use described in Section 2.2.
2.4 Privacy by Default in the SDK
The Attrivo SDK is designed to collect and transmit data only after it has been explicitly initialised by the Customer's app, and only the data fields relevant to the features the Customer has enabled. Customers control which data categories, consent signals, and partner-sharing settings are active for their integration, consistent with the configuration options described throughout this Policy.
3. How Attribution Data Reaches Advertising Partners
Unlike a typical SaaS analytics tool, attribution measurement necessarily involves communicating a subset of conversion data — for example, that a particular click or impression from a specific advertising network led to an install or purchase — back to the advertising networks, media sources, and other marketing partners ("Media Partners") that a Customer has connected within its Attrivo dashboard. This is a core, expected part of how campaign measurement and optimisation work, and we describe it here rather than leaving it implicit.
- Attrivo sends install, event, and revenue notifications ("postbacks") to the Media Partners a Customer has configured, so that those partners can measure and optimise the Customer's advertising campaigns.
- Customers can configure, on a per-partner basis, whether postbacks are sent, and whether postbacks for End Users who have not consented to data sharing are sent at all, sent without personal identifiers, or withheld entirely, subject to each Media Partner's own technical capabilities.
- Where an SDK-level consent or tracking-preference signal is available (for example, an End User's App Tracking Transparency choice, or a consent flag the Customer's app passes to the Attrivo SDK), Attrivo honours that signal in determining what is included in postbacks to Media Partners, consistent with the Customer's configuration.
- Self-attributing advertising networks may have narrower options for postback restriction than other Media Partners; where that is the case, the only available choice is typically whether to send a postback at all, not what fields it contains.
- Some Media Partners impose their own restrictions on how long user-level attribution data tied to their campaigns may be retained or exported, after which the relevant install or event is reported as organic or unattributed rather than removed from reporting altogether; where applicable, these restrictions are documented in our Customer-facing integration guides.
4. Agencies and Resellers
Where a Customer is a marketing agency, reseller, or other party acting on behalf of an underlying advertiser or app owner, that Customer represents and warrants to Attrivo that it is authorised to act on behalf of, and bind, the underlying advertiser or app owner to the applicable Customer agreement and this Policy, and that it has obtained all permissions necessary to instruct Attrivo to collect, view, and process the relevant End User Data on that party's behalf. Attrivo is not responsible for verifying the arrangement between an agency Customer and the party it represents.
5. Platform Frameworks We Operate Within
Attribution measurement operates inside frameworks set by mobile operating system vendors, which materially affect what data is available and how it may be used. Attrivo's Platform is built to operate within these frameworks, including:
- Apple's App Tracking Transparency (ATT) framework and SKAdNetwork / AdAttributionKit, which govern the availability of the IDFA and the mechanics of privacy-preserving, aggregated install attribution on iOS when an End User has not granted tracking permission.
- Android's evolving advertising identifier framework, including Google Play's data safety disclosure requirements and any Privacy Sandbox on Android attribution reporting mechanisms a Customer or Media Partner elects to use in place of, or alongside, device identifiers.
- Where deterministic identifiers are unavailable, restricted, or opted out of, Attrivo may use probabilistic matching — correlating signals such as IP address, device and app parameters, and click or impression timing within a short matching window — to attribute an install or event to a marketing source. Probabilistic matching is inherently less precise than deterministic matching and is used only where deterministic methods are unavailable.
6. Children's Data
The Platform is intended for use by businesses, and Attrivo does not knowingly collect Direct Data from individuals under 18 years of age. Where a Customer's own app or website is directed at, or knowingly used by, children, the Customer remains responsible under applicable law — including the child-specific consent requirements of the DPDP Act and equivalent laws elsewhere — for obtaining verifiable parental or guardian consent before enabling tracking, and for configuring the Attrivo SDK accordingly. Where the Attrivo SDK offers a configuration to disable collection of device and advertising identifiers and to restrict third-party sharing for a Customer's child-directed or mixed-audience app, Customers operating such apps are responsible for enabling and correctly configuring it.
7. Data Residency and Cross-Border Transfers
Attrivo stores and processes End User Data and Direct Data in data centres located in India by default. Personal data may be transferred outside India only in the following circumstances:
- Where sending an attribution postback or similar signal to a Media Partner necessarily involves transmitting a limited data field (such as a hashed device identifier, click ID, or event name) to that partner's servers, which may be located outside India, as configured by the Customer under Section 3;
- Where a Customer has specifically requested a non-default storage or processing region for its account;
- Where a subprocessor providing infrastructure or support functions to Attrivo operates outside India, subject to the contractual safeguards described in Section 14; or
- Where a transfer is strictly necessary to comply with a legal obligation.
Under the DPDP Act, cross-border transfer of personal data is permitted except to countries that the Government of India may from time to time restrict by notification. We take reasonable contractual and technical steps — including data processing agreements incorporating appropriate transfer safeguards — to ensure that any recipient of personal data outside India affords it a standard of protection consistent with this Policy and applicable law.
8. Direct Data — Information We Collect Directly
When you create an Attrivo account, request a demo, fill out a form on attrivo.in, subscribe to communications, or otherwise contact us directly, we collect the information you provide, such as your name, work email, company name, role, phone number, and the content of your message. If you complete a purchase, our payment processor collects billing details on our behalf; Attrivo does not itself store full payment card numbers.
We also collect limited technical data about your visit to our website — browser type, approximate location derived from IP address, pages viewed, and referring URL — through server logs and first-party analytics, to understand site usage and improve the Platform. We do not use this data to build advertising profiles of website visitors, and we do not share it with advertising networks.
9. Purposes of Processing
- Operating, maintaining, and improving the Platform's attribution, analytics, journey, segmentation, and engagement modules.
- Authenticating accounts, processing billing, and providing customer support.
- Responding to demo requests, support tickets, and other communications initiated by a Customer or Direct Contact.
- Sending service-related notices, including changes to this Policy or our Terms of Service.
- Detecting, investigating, and preventing fraud, abuse, and security incidents, including invalid-traffic and ad-fraud detection delivered as part of the Platform (see Section 10).
- Complying with applicable law and responding to lawful requests from courts, regulators, or other public authorities.
10. Fraud and Invalid Traffic Detection
As part of the Platform, Attrivo analyses device, network, and behavioural signals — such as click timing patterns, IP reputation, and anomalous install or event volumes — to flag suspicious or fraudulent installs and events on behalf of Customers. Where a Customer participates in industry fraud-signal-sharing arrangements with its Media Partners, limited fraud-relevant signals (such as a flag indicating a click or install was identified as invalid, without unnecessary additional personal data) may be included in postbacks to the relevant Media Partner, consistent with Section 3.
11. Restricted Data Categories
Customers must not configure the Attrivo SDK or APIs to collect or transmit sensitive personal data such as government identification numbers, precise health information, financial account credentials, or precise real-time geolocation beyond what is described in this Policy, through event names, event properties, user attributes, or any other field. Attrivo may filter, reject, or delete data that appears to fall into these categories if identified.
12. Legal Basis for Processing (DPDP Act)
For Direct Data where Attrivo acts as a Data Fiduciary, we process personal data based on your consent under Section 6 of the DPDP Act, or, where applicable, in reliance on the specific legitimate uses recognised under Section 7 of the DPDP Act — for example, where you have voluntarily provided your personal data for the purpose of a demo request, support interaction, or business enquiry, or as reasonably necessary for employment-related processing, or to comply with a legal obligation. Where processing relies on consent, you may withdraw that consent at any time by writing to info@attrivo.in, without affecting the lawfulness of processing carried out before withdrawal.
For End User Data, the lawful basis is determined by the relevant Customer in its capacity as Data Fiduciary; Attrivo processes such data only pursuant to the Customer's documented instructions and the data processing terms agreed with that Customer.
13. Who We Share Information With
Attrivo does not sell personal data. We share information only in the following circumstances:
- With Media Partners configured by a Customer, as described in Section 3.
- With subprocessors who provide cloud hosting, infrastructure, customer support tooling, or payment processing on our behalf, each bound by confidentiality and data protection obligations (see Section 14).
- With a Customer's own authorised team members, since End User Data is fundamentally collected for that Customer's use of the Platform.
- In connection with a merger, acquisition, or asset sale, subject to the acquiring party's commitment to honour this Policy.
- Where disclosure is required by law, court order, or a valid request from a competent authority.
14. Subprocessors and Data Processing Terms
Attrivo maintains a data processing addendum, incorporated by reference into our Customer agreements, which sets out the terms on which Attrivo processes End User Data as a processor, including the categories of subprocessors we engage, our obligations on subprocessor confidentiality and security, audit and information rights, and breach notification timelines. A current list of subprocessors is available on request at info@attrivo.in.
Categories of subprocessors include cloud infrastructure providers and push notification delivery services (such as Apple Push Notification service and Firebase Cloud Messaging), engaged to deliver push notifications configured by Customers.
15. Data Retention
We retain End User Data for as long as the relevant Customer's account remains active and for a limited period afterward to allow for export, unless a shorter period is requested by the Customer or a longer period is required by law. Where our SDK or dashboard supports Customer-configurable retention or consent-expiry windows, Customers are responsible for setting these consistently with their own legal obligations. We retain Direct Data only for as long as necessary for the purposes described in this Policy or as required by law. When data is no longer needed, we delete it or render it irreversibly anonymous.
Upon a verified deletion request from an End User — whether routed to us through the relevant Customer or received directly at info@attrivo.in — we will delete or irreversibly anonymise the relevant End User Data within a reasonable period, except where retention is required by law.
16. Cookies and Similar Technologies
Our website uses a limited set of first-party cookies necessary for the site and dashboard to function, together with optional analytics cookies that help us understand aggregate usage. You can control cookies through your browser settings; disabling non-essential cookies will not affect your ability to use core parts of the website, though some convenience features may not work as intended.
17. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption of data in transit, role-based access controls, audit logging, network segmentation, and regular review of our security practices. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
In the event of a personal data breach, Attrivo will notify affected Customers without undue delay and, where Attrivo acts as a Data Fiduciary in respect of the affected data, will notify the Data Protection Board of India and affected individuals as required under the DPDP Act and its rules.
18. Your Rights and Choices
Depending on your relationship to Attrivo, you may have the right to access, correct, update, or erase your personal data, to seek grievance redressal, and — where you hold an Attrivo account as a Data Principal — to nominate another individual to exercise your rights in the event of death or incapacity, in each case as available under the DPDP Act or other applicable law.
- If you are an End User of a Customer's app or website, the most effective way to exercise these rights is usually through that Customer directly, since it controls the relevant account and determines the lawful basis for processing. We will also honour verified requests sent to info@attrivo.in and will coordinate with the relevant Customer where needed.
- If you hold an Attrivo account directly, or are a Direct Contact, you can update most information from your dashboard or account settings, or write to us for anything else.
Where our SDK supports it, Customers can configure consent, opt-out, or tracking-preference controls so that an End User's data is processed differently, or not processed by Attrivo, once that End User has declined tracking. Customers are responsible for configuring and honouring these controls consistently with their own legal obligations to their End Users.
19. Grievance Officer
In accordance with the DPDP Act, Attrivo has appointed a Grievance Officer to address questions, complaints, and requests relating to this Policy and our processing of personal data as a Data Fiduciary.
Grievance Officer: info@attrivo.in
Registered office: Bengaluru, Karnataka, India
We will acknowledge and respond to grievances within the timelines prescribed under applicable law.
20. Children's Privacy (Direct Data)
The Platform is intended for use by businesses and is not directed at individuals under the age of 18. We do not knowingly collect Direct Data from children. If you believe a child's data has been provided to us in violation of this section, please contact us at info@attrivo.in so we can address it.
21. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, the Platform, or applicable law. We will post the revised Policy on this page with an updated date, and for material changes we will provide reasonable advance notice, such as by email or an in-product notice, before the change takes effect.
22. Governing Law and Jurisdiction
This Policy and any dispute arising from it are governed by the laws of India, and the courts located in Bengaluru, Karnataka shall have exclusive jurisdiction, without prejudice to any mandatory data protection rights available to you under the law of your own country of residence.
23. Contact Us
For any question about this Policy, to exercise your rights, or to reach our Grievance Officer, write to us at:
Attrivo Intelligence Private Limited
Email: info@attrivo.in
Website: www.attrivo.in
Registered office: Bengaluru, Karnataka, India