1. Introduction
Translation Cloud LLC ("Didva," "we," "us," or "our") operates the click fraud prevention platform available at didva.com and via our API (collectively, the "Service"). This Privacy Policy describes how we collect, process, store, and protect personal data when you use our Service, visit our website, or communicate with us.
By using Didva, you agree to the collection and use of information as described in this policy. If you are using Didva on behalf of a company or other legal entity, you represent that you have authority to bind that entity to this policy.
The short version: Didva is a B2B fraud detection service. We process click-level data from your advertising campaigns β including IP addresses, device fingerprints, and behavioral signals β for the sole purpose of identifying and blocking fraudulent traffic. We do not sell your data, and we do not use your campaign data for any purpose other than delivering the Service to you.
2. Information We Collect
We collect information in three ways: data you provide directly, data we receive from integrated ad platforms, and data we collect automatically as part of fraud detection.
Account and Contact Information
When you create an account or contact us, we collect:
- Name, work email address, and company name
- Password (stored as a salted bcrypt hash β never in plaintext)
- Monthly advertising budget range (for service tier purposes)
- Billing name, address, and the last four digits of your payment instrument (full card data is held exclusively by Stripe and never transmitted to our servers)
- Support and communication records
Ad Campaign Data (via Platform Integrations)
When you connect Google Ads, Meta Ads, or Microsoft Advertising via OAuth, we access:
- Campaign and ad group identifiers, names, and spend data
- IP exclusion lists (to apply blocking rules on your behalf)
- Click-level logs as made available by the respective platform
- Conversion event data when you enable conversion tracking integration
We request only the minimum OAuth scopes necessary to operate the Service. You can review and revoke these permissions at any time through your Google, Meta, or Microsoft account settings.
Click Event Data (Core Fraud Detection Data)
This is the primary data Didva processes. For each click event routed through Didva's detection layer, we collect and analyze:
- IP address β used for bot IP database lookups, datacenter detection, and geolocation analysis
- Device fingerprint signals β user-agent string, screen resolution, browser timezone, language settings, installed fonts (where accessible), and canvas/WebGL fingerprint
- Behavioral signals β click timestamp, click velocity, session duration, mouse movement patterns, and scroll behavior when your tracking script is deployed
- Referrer and UTM parameters β to detect source-level fraud patterns
- Ad click identifiers β Google Click ID (GCLID), Meta Click ID (FBCLID), and equivalents
Usage and Technical Data
When you use the Didva dashboard, we automatically collect:
- Log data: pages visited, features used, time and date of access, and error events
- Device and browser information for the Didva dashboard interface itself
- IP address for security and abuse prevention
Browser Extension (Chrome)
The Didva Chrome extension displays your own account's fraud-protection figures inside the Google Ads interface. It is read-only: it cannot change anything in your ad account, and it does not touch campaigns, budgets, or bids.
While a page on ads.google.com is open, the extension reads two values from that page and sends them to app.didva.com so it can look up the right site's figures:
- The Google Ads customer ID β taken from the page address where present, and otherwise from the customer ID the Ads interface itself displays on the page
- The campaign ID β read from the page address when you open a specific campaign, so the panel can show that campaign's figures
The extension also reads the names shown in the table you are looking at β campaign names on the campaigns list, and ad-group names once you open a campaign β so it can put your Didva figures on the right row. Those tables identify a row by its name and nothing else, while our own records identify it by its ID and nothing else. The names are compared with your own account's list inside your browser: they are never sent to us, never stored, and never logged.
Nothing else on the page is read, and nothing beyond the two IDs above leaves your browser. The extension contacts no host other than app.didva.com, contains no analytics or tracking code, and sets no cookies.
Stored locally in your browser, and never sent anywhere: the access token issued when you connect, which didva site you matched to an ad account, whether the panel is collapsed, and a short-lived cache of the figures already shown to you. Uninstalling the extension removes all of it.
The token is read-only and revocable. Revoke it at any time from Connected devices in your Didva profile, or with Disconnect in the extension's popup; either takes effect immediately.
WordPress Plugin
The Didva plugin for WordPress connects a site you own to your Didva account and installs our tracking script for you, so protection starts without you pasting code into your theme.
When you press Connect, the plugin sends your site's domain and the WordPress admin address you return to, so the site can be created in your account and you can be sent back. In exchange it receives an access token and a site key, stored in your own WordPress database.
On pages your visitors load, the plugin adds our hosted tracking script. What that script collects from a visit is described above in this section, and the cookie it stores on the visitor's device is described under Cookies & Tracking — it is the same data and the same cookie as on any site running Didva, and it applies to your public pages only, never to the WordPress administration screens. On a WooCommerce order-received page, or a thank-you page you select yourself, the plugin also adds our conversion script, which reports that a conversion happened and, for WooCommerce, the order number.
From your WordPress administration screens the plugin asks app.didva.com for your own site's figures — blocked addresses, fraud clicks, estimated savings — to display them, and once a day it fetches your own homepage to check the tracking script is still present. It contacts no host other than app.didva.com, adds no analytics of its own, and sets no cookies from the plugin itself.
Stored in your WordPress database: the access token, the site key, the domain, the date you connected, and the thank-you page you selected. Disconnect asks us to revoke the token and removes all of it; deleting the plugin does the same. You can also revoke the token from Connected devices in your Didva profile at any time. Your collected data stays in your Didva account until you delete the site there.
3. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Fraud detection and blocking β identifying and acting on fraudulent click patterns in real time | Click event data, IP addresses, device fingerprints, behavioral signals | Contract performance |
| Fraud reporting β generating reports with refund evidence for ad platforms | Click event data, ad identifiers, campaign data | Contract performance |
| Account management β creating and maintaining your account, billing, authentication | Account info, payment data | Contract performance |
| Service improvement β improving detection accuracy and reducing false positives using aggregated, de-identified pattern analysis | Anonymized click patterns (never linked to individuals or advertisers) | Legitimate interest |
| Security β detecting abuse, unauthorized access, and protecting the platform | Log data, IP addresses, account activity | Legitimate interest |
| Customer communications β sending service notifications, security alerts, and (with your opt-in) product updates | Email address, name | Contract performance / consent |
| Legal compliance β responding to valid legal requests or enforcing our Terms of Service | Any data relevant to the legal obligation | Legal obligation |
We do not sell your personal data. We do not use your campaign data to train models that benefit other customers without first anonymizing and aggregating the data such that it cannot be traced to you or any individual.
4. Sharing & Disclosure
We share your data only in the following limited circumstances:
Ad Platforms (at your direction)
When you instruct Didva to block fraudulent IPs or devices, we apply those exclusions to your connected ad accounts via the platform's API. This is an action you direct us to take on your behalf β not a data sale or independent disclosure.
Sub-processors and Service Providers
We work with the following categories of sub-processors who may handle personal data on our behalf under contractual data processing agreements:
- Stripe, Inc. β payment processing (PCI DSS Level 1 certified). Stripe processes your payment card data directly; Didva never receives or stores raw card numbers.
- Amazon Web Services β cloud infrastructure and data hosting in us-east-1 (Virginia, USA) with optional EU region support
- Datadog, Inc. β application performance monitoring and error logging (log data only; no personal campaign data)
- SendGrid (Twilio Inc.) β transactional email delivery
A current list of sub-processors is available at didva.com/sub-processors and is updated with 30 days' advance notice before any new sub-processor is added.
Legal Requirements
We may disclose your information if required to do so by law, court order, or binding governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Didva, our customers, or the public. Where legally permitted, we will notify you before complying.
Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred as part of that transaction. We will notify you via email and a prominent notice on our website prior to any such transfer, and you will have the opportunity to delete your account before the transfer takes effect.
Aggregated, De-identified Data
We may share aggregated, anonymized statistics (e.g., "17% of ad clicks across our platform originate from known bot networks") that cannot reasonably be used to identify you or your campaigns.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service, subject to the following specific periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account and billing records | 90 days after account termination, then deleted | Allow account reactivation; dispute resolution |
| Click event data (identifiable) | 12 months from the date of collection | Ad platform refund claims typically require up to 12 months of evidence |
| Click event data (anonymized) | Up to 36 months after anonymization | Aggregate fraud pattern analysis and model training |
| IP reputation records | Rolling 24 months | Persistent fraud actor tracking |
| Audit logs | 24 months | Security incident investigation |
| Financial transaction records | 7 years | Tax and accounting obligations |
You may request early deletion of your data at any time by contacting [email protected] or using the account deletion feature in your dashboard settings. Deletion requests are processed within 30 days. Note that some data may be retained for longer periods where required by law or to resolve active disputes.
6. Security
Protecting your campaign data is fundamental to what Didva does. We implement the following technical and organizational measures:
- Encryption in transit: All data transmitted to and from Didva is encrypted using TLS 1.2 or higher. Our APIs enforce HTTPS with HSTS headers.
- Encryption at rest: All stored data β including click event logs, account information, and backups β is encrypted using AES-256.
- Access controls: Internal access to customer data is role-based and limited to personnel who require it to perform their job functions. All access is logged and reviewed quarterly.
- Authentication: We support multi-factor authentication (MFA) for all Didva accounts and require it for employees accessing production systems.
- SOC 2 alignment: Our security controls are designed and tested against the SOC 2 Type II framework. Our most recent audit report is available under NDA to enterprise customers.
- Vulnerability management: We conduct regular penetration tests by independent third-party security firms and operate a responsible disclosure program at didva.com/security.
In the event of a data breach that is likely to affect your rights and freedoms, we will notify you and, where required, the relevant supervisory authority within 72 hours of becoming aware of the breach.
7. Cookies & Tracking
We use cookies and similar technologies on the Didva marketing website and dashboard. Our Didva.js fraud detection script, when deployed on your website, also sets cookies in your visitors' browsers for fraud scoring purposes.
Didva Website & Dashboard Cookies
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
didva_session |
Strictly necessary | Maintains your authenticated session in the Didva dashboard | Session / 30 days (if "remember me" selected) |
didva_csrf |
Strictly necessary | Cross-site request forgery protection | Session |
didva_prefs |
Functional | Stores UI preferences (timezone, date format, dashboard layout) | 1 year |
didva_analytics |
Analytics (opt-out available) | Aggregated product usage analytics to improve the dashboard | 90 days |
Analytics β Google Analytics 4
On the Didva marketing website (didva.com) we use Google Analytics 4 (GA4) to understand how visitors find and use our pages so we can improve them. GA4 sets its own cookies (for example _ga and _ga_<id>) and may collect:
- Pages viewed, time on page and navigation paths
- Approximate, city-level location derived from a truncated (anonymized) IP address
- Device, browser, operating system and screen size
- Referring source (for example a search engine, ad or link)
- Interaction events such as sign-up clicks, pricing clicks and free-audit form submissions
We run GA4 with Google Consent Mode v2: analytics cookies are not set and no analytics data is collected until you accept via the cookie banner shown on your first visit. You can decline, or change your choice later by clearing the consent setting in your browser. IP anonymization is enabled.
Google acts as a data processor for this data and may process it on servers outside your country (see “International Data Transfers” below). For more information see Google’s Privacy Policy and how Google Analytics uses data. To opt out across all sites you can install the Google Analytics Opt-out Browser Add-on.
Didva.js Detection Script Cookies (on your website)
When you deploy the Didva tracking script on your advertising landing pages, it stores the advertising click that brought each visitor, so a conversion later in the visit can be matched back to that click. The cookie it sets is cg_click. It:
- Is set under your domain (not didva.com), making it a first-party cookie, at the registrable domain so it survives a move from your apex to a checkout subdomain
- Contains the click identifier the ad platform put in the landing-page address, which advertising channel it came from, and when the click happened — no name, address or other identifying detail about the person
- Expires 90 days after the click
- Is mirrored into the browser's local storage (
cg_click_id,cg_click_channel,cg_click_ts, and the earliercg_gclidkeys) so attribution still works where cookies are blocked - Is subject to your website's cookie consent mechanism — you are responsible for including it in your consent flows
Finding the right domain to set that cookie on cannot be done from the hostname alone, so the script briefly writes a throwaway __cg_d cookie while it asks the browser which domain it will accept. Each attempt lasts ten seconds at most and is removed as soon as it succeeds. Device and behavioural signals described in Information We Collect are sent with the request and are not stored on the visitor's device.
You can manage or disable non-essential cookies through our cookie preference center, accessible from the footer of our website.
8. Your Rights
Regardless of where you are located, you have the following rights with respect to your personal data:
π Right to Access
Request a copy of all personal data we hold about you, including your account information and any click event data associated with your campaigns.
βοΈ Right to Rectification
Request correction of inaccurate or incomplete personal data. Most account information can be updated directly in your dashboard settings.
ποΈ Right to Erasure
Request deletion of your personal data. We will fulfill deletion requests within 30 days, subject to legal retention obligations.
βΈοΈ Right to Restriction
Request that we restrict processing of your data while we resolve a dispute about its accuracy or legitimacy of processing.
π¦ Right to Portability
Receive a copy of your data in a structured, machine-readable format (JSON or CSV) to transfer to another service provider.
π« Right to Object
Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
To exercise any of these rights, email [email protected] or use the data request tools in your account settings under Privacy & Data. We will respond within 30 days (or 45 days for complex requests, with notice). We do not charge a fee for reasonable requests.
9. GDPR (EU / EEA Residents)
If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) applies to our processing of your personal data.
Data Controller: Translation Cloud LLC, 30 Lafayette Ave STE 1, #1092, Morristown, NJ 07960, United States is the data controller for account and billing data. For click event data processed on behalf of our customers, Didva acts as a data processor and our customers are the data controllers.
Legal Bases for Processing: We rely on the following legal bases as described in Section 3 (How We Use Your Data): contract performance (Article 6(1)(b)), legitimate interests (Article 6(1)(f)), legal obligations (Article 6(1)(c)), and consent (Article 6(1)(a)) where explicitly obtained.
Data Protection Officer: We have appointed a Data Protection Officer. You may contact our DPO at [email protected].
Supervisory Authority: You have the right to lodge a complaint with your local supervisory authority. If you are in the EU/EEA, you can find your authority at edpb.europa.eu/about-edpb/board/members_en.
We will not make automated decisions about you that produce significant legal effects solely based on automated processing without providing you an opportunity to request human review.
10. CCPA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, our business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of personal information we have collected, subject to exceptions for data needed to complete transactions, detect security incidents, or comply with legal obligations.
- Right to Opt Out of Sale or Sharing: Didva does not sell or share personal information for cross-context behavioral advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes other than those specified in the CPRA.
- Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To submit a verifiable consumer request, email [email protected] with the subject line "California Privacy Request." We will verify your identity before processing the request and respond within 45 days.
11. International Data Transfers
Didva is headquartered in the United States. If you are located outside the United States, your personal data will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs): We incorporate the European Commission's standard contractual clauses (2021/914/EU) into our data processing agreements with customers in the EU/EEA.
- UK International Data Transfer Addendum: For transfers from the United Kingdom, we use the ICO's International Data Transfer Addendum.
- Adequacy decisions: Where applicable, we rely on adequacy decisions issued by the European Commission.
A copy of our standard data processing agreement and applicable transfer mechanisms is available upon request at [email protected].
12. Children's Privacy
Didva is a business-to-business service designed for use by adults managing advertising campaigns. The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe we have inadvertently collected information from a minor, please contact [email protected] and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Sending an email to the address associated with your account at least 30 days before the changes take effect
- Posting a prominent notice on the Didva dashboard for the 30-day notice period
- Updating the "Last updated" date at the top of this policy
If you continue to use the Service after the effective date of a revised policy, you are deemed to have accepted the updated terms. If you do not agree to the changes, you may close your account before the new policy takes effect.
We maintain an archive of previous versions of this Privacy Policy at didva.com/privacy/archive.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us through any of the following channels:
- Privacy team: [email protected]
- Data Protection Officer: [email protected]
- Postal address: Translation Cloud LLC, Attn: Privacy, 30 Lafayette Ave STE 1, #1092, Morristown, NJ 07960, USA
We aim to respond to all privacy-related inquiries within 5 business days. For formal data subject requests, we will acknowledge receipt within 3 business days and provide a substantive response within 30 days.
Questions about your data?
Our privacy team is here to help. Reach out and we'll respond within 5 business days β no legal jargon, just straight answers.
βοΈ Contact [email protected]