Privacy Policy
Last updated: July 2026
1. Who we are
Holdout ("we", "us", "our") operates the website and tools at tryholdout.com. We build self-serve geo incrementality testing and marketing measurement software for performance marketers.
2. What data we collect
We collect only what is necessary to provide the service:
- CSV files you upload. Files are processed in memory on our servers to run analyses. We do not store your uploaded data after the analysis is complete. Files are discarded at the end of each request.
- Email addresses. If you request a test-end reminder, we collect your email address and the date you provide to schedule the reminder. This data is stored by our email provider (Resend) for the sole purpose of sending the scheduled reminder.
- Usage analytics. We use PostHog to collect anonymised, aggregated usage data (page views, feature interactions) to understand how the product is used. We do not use PostHog to identify individuals or track across websites. IP addresses are not stored.
- Error reports. We use Sentry to collect anonymised error reports and performance data when something goes wrong. This helps us fix bugs. No personally identifiable information is intentionally captured.
3. How we use your data
- To run the analysis you request and return results to you.
- To send the test-end reminder email you explicitly requested.
- To improve the product through aggregated, anonymised usage patterns.
- To diagnose and fix technical errors.
We do not sell your data. We do not use your data for advertising.
4. Your uploaded marketing data
Your CSV files contain your business data. We treat them as confidential. Files are processed server-side in memory and are not written to permanent storage. They are not shared with third parties. When you close the session or the request completes, the data is gone.
5. Shopify integration
If you connect a Shopify store, we request read-only access to orders (read_orders scope). We use order dates and shipping postcodes only, to aggregate weekly conversion data by UK geography for geo incrementality test design and analysis.
- We do not access customer names, email addresses, or phone numbers.
- Order data is pulled on demand, processed in memory, and aggregated to postcode-district level.
- We do not store raw order records on our servers after processing.
- OAuth access tokens are encrypted at rest and deleted when you disconnect the store.
You can disconnect Shopify at any time from Settings. Disconnecting deletes the stored access token immediately.
6. Google Ads integration
If you connect a Google Ads account, we request the auth/adwords OAuth scope to read your campaigns and write negative location criteria to campaigns you select. Specifically:
- We read your campaign list to display it within the product.
- We write negative location criteria (geo exclusions) to campaigns you explicitly select, so you can run geo holdout tests.
- We do not make any other changes to your account.
- OAuth refresh tokens are encrypted at rest in our database and deleted when you disconnect.
- We do not share your Google Ads credentials or campaign data with any third party.
You can disconnect Google Ads at any time from Settings. Disconnecting deletes the stored refresh token immediately.
Holdout's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Meta integration
If you connect a Meta ad account, we request the ads_management permission to read your ad sets and write location exclusions to ad sets you select. Specifically:
- We read your ad set list to display it within the product.
- We write location exclusions (holdout regions) to ad sets you explicitly select, so you can run geo holdout tests.
- We do not make any other changes to your account. No spend, budget, audience, or creative changes are made.
- OAuth access tokens are encrypted at rest in our database and deleted when you disconnect.
- We do not share your Meta credentials or advertising data with any third party.
You can disconnect Meta at any time from Settings. Disconnecting deletes the stored access token immediately. You can also remove Holdout's access from your Meta Business Integrations settings.
8. How we protect your data
These protections apply to everything you upload or connect, including data we receive from Google APIs.
- Encryption in transit. All traffic between your browser, our servers, and connected platforms uses HTTPS (TLS). We do not accept unencrypted connections.
- Encryption at rest. Credentials for connected accounts (Google Ads, Meta, Shopify) are encrypted with authenticated symmetric encryption (Fernet) before they are stored. The encryption key is held as a server secret, separate from the database.
- Access control. Our database enforces row-level security, so your data is only readable by your own authenticated account. Backend operations use a scoped service role that exists only on our servers. Credentials are never sent to your browser.
- Minimal retention. Data pulled from connected accounts is processed in memory to produce aggregated results. We do not keep raw copies after processing. Uploaded files are discarded at the end of each request. Credentials are kept only while a connection is active.
- Deletion and revocation. Disconnecting an integration in Settings deletes the stored credential immediately. For Google, you can also revoke Holdout's access at any time from your Google Account permissions page.
- Breach notification. If a security incident affects your data, we will notify you within 72 hours, as UK GDPR requires.
9. Third-party services
- PostHog: product analytics (EU data residency). Privacy policy.
- Sentry: error tracking. Privacy policy.
- Resend: transactional email for reminders. Privacy policy.
- Crisp: in-product support chat. Messages you send to us via Crisp are stored by Crisp. Privacy policy.
- Vercel: frontend hosting. Privacy policy.
- Railway: backend hosting. Privacy policy.
- Shopify: optional store connection (OAuth). Order data is accessed via Shopify's Admin API when you connect a store. Privacy policy.
- Meta: optional ad account connection (OAuth). Ad set data is accessed via Meta's Marketing API when you connect an account. Privacy policy.
- Stripe: payment processing. Card details are entered on Stripe's checkout pages and never touch our servers. Privacy policy.
10. Cookies and local storage
We use browser localStorage to remember design parameters you have entered so they can be pre-filled in the analysis tool. This data never leaves your browser and is not sent to our servers. We do not use tracking cookies.
11. Data retention
Uploaded files: not retained (discarded after each request). Saved test designs and analysis results: aggregated regional totals only, never the raw file, kept in your account until you delete them or close your account. Email reminders: deleted from Resend after the reminder is sent. Analytics data: retained in aggregated form for product improvement. Support chat logs: retained by Crisp per their policy.
12. Your rights
Under GDPR and UK data protection law, you have the right to access, correct, or delete your personal data. If you have set a reminder and want it cancelled, or have any other request, contact us at privacy@tryholdout.com.
13. Changes to this policy
We may update this policy as the product evolves. Material changes will be noted at the top of this page with an updated date.
14. Contact
Questions about this policy: privacy@tryholdout.com.