โ† Back to Privacy Notice

Privacy Notice โ€” coming into effect 21 September 2026

Last updated September 4, 2026

This is our updated Privacy Notice. It takes effect on 21 September 2026. Until then, the current Privacy Notice applies. We are showing it to you now so you have time to read it and decide how you feel about it before anything changes.

Published 4 September 2026. Takes effect 21 September 2026.

The version of this Notice currently in force continues to apply until 21 September 2026, and remains available until it is replaced.

Welcome to Measure Protocol's Privacy Notice. Measure Protocol respects your privacy and is committed to protecting your Personal Data. This Privacy Notice will inform you as to how we look after your Personal Data and tell you about your privacy rights and how the law protects you.

This privacy notice sets out:

  1. Introduction
  2. Things that we will not do
  3. Important information and who we are
  4. Changes to the privacy notice and your duty to inform us of changes
  5. Third-party links
  6. The data we collect about you
  7. How we use your personal data
  8. Disclosures of your personal data
  9. Advertising and ad-targeting use of data
  10. International transfers
  11. Data security
  12. How long we will retain your personal data
  13. Children and young people
  14. Your legal rights
  15. Specific notice for California residents

1. Introduction

1.1 For the purpose of this Privacy Notice "you" or "your" means an individual who is the subject of Personal Data we process as a controller, including the end users of: (i) Measure Protocol App (the "App"); (ii) the Measure browser extension (the "Browser Extension"); and (iii) the data collection services available through our Website (the "Web Services"). "we" or "us", "our" means Measure Protocol Limited ("Measure"), a company registered in England and Wales with company number 11220400, with registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom.

1.2 Measure provides a marketplace with groundbreaking solutions for person-based data where individuals are paid, or rewarded, for participating in data tasks. For instance, using the App, end users (the "Users") are pre-selected or matched, based on: (i) demographic data or other data they have previously provided to us, in whatever form; or (ii) other data provided by our third party partners (e.g., that allows us to match our Users with users of the third party platforms). This enables us to invite Users to participate in surveys, panels or other data tasks organised by us or by researchers ("Measure Partners") for brands, TV channels or broadcasters, and advertisers ("Measure Customers"). Users are also able to participate in data tasks available through our Web Services and our Browser Extension.

1.3 This Privacy Notice together with the MSR End User Terms of Use available at https://www.measureprotocol.com/app-terms (the "Terms") and any other documents referred to in it sets out the basis on which we process any Personal Data we collect from you, or that you provide to us, will be processed by us. This Privacy Notice also sets out how you can instruct us if you prefer to limit the use of that Personal Data and the procedures that we have in place to safeguard your privacy. Please read the following carefully to understand our views and practices regarding your Personal Data and how we will treat it.

1.4 Depending on the data task you participate in:

  • 1.4.1 you may be asked to fill in questionnaires and participate in surveys; or
  • 1.4.2 you may agree to participate in device metering tasks where we may collect data automatically from your devices, and it may not be obvious to you when this is happening ("Passive Tracking"). We will only install measurement software or collect data from your devices for data measuring purposes when you have agreed to participate in the relevant data task.
  • 1.4.3 you may agree to submit to us screenshots, videos or exported files, etc., showing for instance, your recent purchasing history on a website or app, or your recently watched videos on a specific platform or similar usage data ("Retro" or "Retro Services").
  • 1.4.4 you may agree to use our Browser Extension to share data from your accounts on third-party services, including your purchase history, your viewing or activity history, your search history, your browsing history, and your conversations with generative-AI assistants. Collection through the Browser Extension begins only after we inform you of this and you have given consent for the specific task or service that requires consent, and you can withdraw at any time.

2. Things That We Will Not Do

2.1 At no time will we collect from you: (i) data such as bank cards or bank account numbers; (ii) the contents of any communications between you and third parties (emails, texts, WhatsApp or social media posts); or (iii) the contents of any files on your device unless you share them with us explicitly or as part of a task. Our system will obscure or delete any information that is not relevant for the relevant data task. The Browser Extension lets you share specific sources (for example, AI-assistant conversations) only where you have given consent for that task; otherwise we do not collect the contents of your communications.

2.2 Except where you have given separate, explicit opt-in consent for the data marketplace and advertising use described in Section 9, we will not use any data we collect from you for direct marketing or advertising purposes (i.e., to advertise, or to sell third party products to you), and we do not allow Measure Partners or Measure Customers to do so. We never use special category data (as described in Section 7.13) for direct marketing or advertising purposes.

3. Important Information and Who We Are

3.1 This Privacy Notice describes how we process your Personal Data as a controller under the data protection laws that apply to you:

  • United Kingdom (primary): the UK GDPR and the Data Protection Act 2018, regulated by the Information Commissioner's Office (ICO).
  • United States โ€” California: the California Consumer Privacy Act as amended by the CPRA (see Section 15).
  • India: the Digital Personal Data Protection Act 2023 (the "DPDP Act"), for individuals in India. Where the DPDP Act applies, we process your Personal Data on the basis of your consent or another lawful basis recognised under that Act, and you may exercise the rights it provides by contacting us at privacy@measureprotocol.com.
  • European Economic Area: if and when we process the Personal Data of individuals located in the EEA, the EU GDPR (Regulation (EU) 2016/679) will also apply to that processing.

Together, these are the "Applicable Data Protection Legislation". If you have any questions about this Privacy Notice, including any requests to exercise your legal rights (see section 14 below), please contact us using the details set out below:

  • Full name of legal entity: Measure Protocol Limited, company number 11220400.
  • Data Protection Officer: Paul Neto. You can contact our DPO on any matter relating to this Privacy Notice or to how we handle your Personal Data, using the email address below.
  • Website address: https://www.measureprotocol.com (our "Website").
  • Email address: privacy@measureprotocol.com.

3.2 Postal address: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom.

3.3 You have the right to make a complaint at any time to the relevant supervisory authority for data protection issues, such as the Information Commissioner's Office of the United Kingdom (https://ico.org.uk/). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

4. Changes to the Privacy Notice and Your Duty to Inform Us of Changes

4.1 We keep this Privacy Notice under review and may update it from time to time. Where we make a material change โ€” for example, if we begin collecting a new type of data, use your data for a new purpose, or share it with a new type of recipient โ€” we will tell you at least 14 days before the change takes effect, and we will tell you what has changed. We give that notice using the means most likely to reach you, which may include email, a notice in the App, and a notice on our Website. This Notice shows both the date it was published and the date it takes effect, and the version currently in force stays available until the new one replaces it. A change that is not material, such as a correction or a clarification, takes effect when we publish it.

4.2 It is important that the Personal Data we hold about you is accurate and current. Please keep us informed if your Personal Data changes during your relationship with us.

5.1 The Website may include links to third-party websites and applications. Clicking on those links or enabling those connections may allow those third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy notices or data use policies.

6. The Data We Collect About You

6.1 Personal Data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity of the individual has been removed (anonymous data).

6.2 This is information that you give us by instructing us to provide you with the services, accepting our online Terms of Use, registering an account on our Website and/or using our App or services.

6.3 You are responsible for ensuring that you are authorised to share all such information with us for the purposes described in Section 7 of this Privacy Notice and that you only provide such data to us in accordance with Applicable Data Protection Legislation.

6.4 Measure will indicate on our forms those data fields which are required for our services to function using the symbol: "*". If you do not fill in the required fields specified above, you will not be able to sign up and receive some services offered by Measure.

6.5 We may collect different kinds of Personal Data about you such as:

  • your basic registration data (name, email, location, country, IP address, time zone, date joined / became active) ("Registration Data");
  • Records of transactions (IDs and basic transactional information of surveys, data tasks or other research projects you have taken and when) ("Transactional Data");
  • Records of gift cards or other rewards given to you for participating in data tasks such as surveys or other research projects ("Rewards Data");
  • the survey ratings the survey Partners or us give you based on the quality and completeness of your survey answers โ€” or the ratings our Partners or us give you for your participation in other data tasks ("Ratings Data"). We use Ratings Data to maintain data quality and eligibility; this does not involve automated decision-making producing legal or similarly significant effects, and you may contact us to review or contest a rating;
  • A list of profile demographic questions answered through the App ("Demo Data");
  • Records of your consents or opt-ins for our own compliance and legal purposes ("Opt-in Data");
  • The survey and/or task data you fill in or provide when you participate in a survey or data task run and controlled by us ("Survey Data"), including social media IDs that you may choose to provide; and
  • If you have:
    • contacted our customer service or compliance departments; or
    • Provided feedback about our products. ("Customer Support Data").

User Data includes information about how you interact with our Website and App and your account information, such as your user name and password. This includes information we collect about you and your device. Each time you visit our Website or use our App or services we may automatically collect the following information:

  • App Data: Identifiers for our App and account analytics such as Measure Unique ID, Device Tokens and AppsFlyer Identifiers;
  • Unique Application Numbers: When you install or uninstall our App or when our App searches for automatic updates, we may receive information about your installation, such as, a unique application number and the type of operating system;
  • Device Data: including the type of device you use, a device identifier, your mobile operating system, and time zone setting;
  • Log Data: such as the details of your use of our App or your visits to our Website including, but not limited to traffic data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise;

Passive Data: (Applicable to Android users only) Passive Tracking is a Measure product that upon User's consent, allows the collection and metering of the User's device level usage, internet browsing habits, online activities, app and feature usage, location, and system information ("Passive Data"). The Passive Data collected will depend on the data tasks, the Users agree to participate in. Each data task will inform the User about the scope of the data that will be collected from the User's device through the App and the term, which would typically comprise:

  • Online browsing: This includes the sites Users visit and apps they use, including news sites/apps or social networks, and their interactions with them.
  • Online activities: This includes the search terms Users enter and the results of such searches, information about the videos Users view, the products users shop for online, information Users enter into forms (excluding payment card details, bank account numbers, full government ID numbers, passwords, security answers, and multi-factor authentication tokens), the materials Users download or upload, the advertisements Users see, information about cookies on websites Users visit, information and content on sites or apps that Users visit or Use and with which Users interact and may include personal, financial and health information (subject to the process described below in the section entitled "Special category data").
  • System information: This includes information about the device and browser that Users are running on, how the MSR app is operating, and which other applications are installed or running.
  • Mobile Usage Information: which refers to information about a User's use of their mobile. This can include the following types of information:
    • Information about your internet browsing habits: how much time they spend browsing the internet on their mobile device or computer, the sites they visit or apps they use, and the terms of any search they carry out.
    • Information about your usage of other apps and features: (such as the camera, though we do not collect any photos) on User's mobile device, including the identity of the apps and features, when they downloaded them, how often they use them and for how long.
    • Information about the type of mobile device Users own: when and for how long they charge it, its battery status, whether it is switched on, off or in a stand-by or 'Airplane' mode.
    • Information about which mobile network Users use, which wi-fi networks they connect to, and at what times.
    • Information about the volume of data: downloaded to Users' mobile device, the times that they download that data and the method of connection they use (wi-fi or mobile network).
    • Information we can deduce from combining the above information: e.g., what apps users were using just before they searched for particular information using their mobile device's internet browser, or how often they call, email or text a particular contact.
    • Operating system capabilities: to view the contents of a user's applications, such as Accessibility services. Where a data task requires the use of Accessibility services or similarly sensitive device permissions, we provide a clear, separate description of what will be accessed and why.

Retro Data: Retro is a service where Users are rewarded for submitting to us screenshots, videos, exported files, etc., showing for instance, their recent purchasing history on a website or app, or their recently watched videos on a specific platform or similar usage data as specified in the relevant data task ("Retro Data"). Retro data is collected via a specific task or survey if you choose to participate. As set out in Section 2.1, our system obscures or deletes information (including payment card details and financial credentials, bank account numbers, full government ID numbers, passwords, security answers, and multi-factor authentication tokens) that is not relevant to the data task, including in Retro submissions.

Browser Extension Data: The Browser Extension is a Measure product that, with your consent for each task or service, lets you share data from your own accounts on supported third-party platforms (for example, your order history on Amazon, or your conversations with a generative-AI assistant such as Amazon Rufus or Perplexity). We access only what is already visible in your account for the task or service you have chosen. Before any access takes place, you are shown a notice that identifies Measure Protocol Limited as the data controller and explains what will be collected, the purposes for which it is used, and any partners with whom it will be shared. Some of these uses โ€” carrying out and verifying the task you have requested, keeping our service secure, and meeting our legal obligations โ€” do not rely on your consent. We ask for your consent to use this data for market research, profiling or direct marketing, and that consent also covers our reading and storing it on your device for that purpose. You can decline, pause, stop, or withdraw at any time, without affecting your MSR membership. Depending on the task or service, Browser Extension Data may include:

  • Account and activity history: your purchase or order history, your viewing or watch history, and your activity on a supported platform, as shown in your own account.
  • Full-history sources shared in their entirety: your search history, your browsing history, and your conversations with generative-AI assistants (for example, Amazon Rufus, Perplexity, or ChatGPT). Because these sources are shared in full and contain free text that you have written, they may contain special category data, most often information about health. We handle this as described in Section 7.13 (Special category data), and we never use it for advertising or marketing. Read more: how we scrub and anonymise free text and journeys.
  • Technical data: browser type, extension version, and the timestamp of collection.

Some Browser Extension tasks are one-off (you accept a task, share the data, and that is the end of it). Others are ongoing, where data is collected continuously in the background until you stop sharing; for these, we tell you clearly that collection is continuous, show a persistent indicator while it is on, give you a "Stop Sharing" control, and ask you to renew your consent at least every six months.

Matching Identifiers: we may collect or share with Measure Customers or Partners the following types of identifiers, to enable data matching, audience identification, and research enhancement (e.g., to find Users that meet the requirements for specific data jobs and ask them to participate in them):

  • Hashed identifiers: cryptographically hashed versions of your email address, phone number, or other contact information.
  • Device identifiers: mobile advertising IDs (MAID/IDFA/GAID), device fingerprints, and browser identifiers.
  • Platform identifiers: TV provider IDs, streaming service IDs, retailer account identifiers, and similar platform-specific identifiers you provide to us. We access only what is visible in your account with your permission and in line with the relevant platform's terms.
  • Panel identifiers: your unique Measure user ID and any pseudonymous identifiers we create for matching purposes.
  • Household identifiers: postal/ZIP code, IP address, and other data points that may be used to identify household-level matches. Household-level matching is used for research and panel eligibility; it is not used to address targeted advertising to you unless you have opted in under Section 9.

These identifiers enable us to match your profile with external datasets, identify research opportunities, and enhance our research capabilities as described in Section 7 below.

Cross-partner Audience & Attribution: through data matching activities, and subsequent data tasks (that you are eligible for and decide to join), we may receive from, or share with, Measure Customers or Partners various categories of personal data from our Partners to link with your profile. These categories include, but are not limited to, the following:

  • Media consumption data: TV viewing habits, streaming activity, content watched, advertisement exposures, viewing duration and timestamps
  • Advertising exposure data: digital and traditional ad impressions, campaign exposures, and advertising engagement metrics.
  • Transaction and purchase data: purchase history, products viewed, shopping behaviors, and retail interactions.
  • Digital activity data: website visits, app usage, search activity, and content interactions.
  • Demographic and profile data: age, gender, location, household composition, interests, and lifestyle indicators.

Where these categories are linked to data collected through the Browser Extension or Passive Tracking, this occurs only where you have given consent for that channel; for all other data types, we rely on our legitimate interests as described in Section 7.8.

7. How We Use Your Personal Data

7.1 We will only use your Personal Data when the law allows us to. Most commonly, we will use your Personal Data in the following circumstances:

  • With your consent;
  • Where we need to perform the contract we are about to enter into or have entered into with the company you represent or work for;
  • Where it is necessary for our legitimate interests or those of a third party and your interests and fundamental rights do not override those interests; or
  • Where we need to comply with a legal obligation.

7.2 We use the Demo Data, Survey Data and Retro Data you provide to: (i) generate market research reports in aggregate form, and/or user-level insights (where the data per User is analysed and used more granularly); and (ii) pre-select you for surveys and data tasks and then ask you to participate in them. As part of our research we may create user segments and profiles (for example, grouping users by behaviour or interests) for analysis and to select and match you for relevant data tasks. This research profiling is not used for advertising or ad-targeting (which is covered separately in Section 9), and it does not produce legal or similarly significant effects on you. Where user-level insights, including free text and behavioural sequences, are shared outside Measure, they are first scrubbed of identifiers and references so that recipients cannot re-identify you (see Section 7.13). Read more: how we use your research data.

7.3 Data Matching & Data Task Selection: For data tasks with specific profile, user matching or audience requirements, we may use your Registration Data, Retro Data, Matching Identifiers and Cross Partner Audience & Attribution Data and limited Demo Data only to select you for the data task, and/or match you against similar identifiers provided by Measure Customers or Partners. If you subsequently participate in the data task, Measure Partners or Measure Customers may use this data to generate reports and insights. For instance, as part of our market research services, we engage in data matching and enhancement activities to generate comprehensive research insights. This includes both sharing your Matching Identifiers with Measure Customers or Research Partners (as defined below) and sharing or receiving Cross Partner Audience & Attribution Data to link with your profile. These activities may occur, in the context of a data task (as part of specific research studies you join, other data tasks or audience panels), or as general research operations to identify opportunities and enhance our research capabilities.

We may share your Matching Identifiers and Cross Partner Audience & Attribution Data with Research Partners (as defined below), data providers, measurement companies, and other third parties for the following purposes:

  • Audience matching: To identify whether you appear in partner datasets (such as ad exposure logs, purchase databases, or media consumption panels).
  • Research opportunity identification: To determine your eligibility for specific research studies or data enhancement projects.
  • Campaign measurement: To measure advertising effectiveness by matching your profile against ad exposure data.
  • Panel enrichment: To supplement our research Panel with additional data sources for more comprehensive insights.

When we share Matching Identifiers for matching purposes, we typically (i.e., unless we tell you otherwise) share only hashed or pseudonymised (not anonymised) versions to protect your privacy. Partners or Measure Customers receiving these identifiers are contractually prohibited from using them for direct marketing, profiling or any purpose other than the specified matching activity. Where matching uses Passive Data or Browser Extension Data, the lawful basis is your consent for that channel; where matching uses Survey Data, Retro Data, Registration Data or Matching Identifiers alone, the lawful basis is our legitimate interests.

We may share with, or receive from Measure Customer or our Research Partners, Cross Partner Audience & Attribution Data which we may use to link with other data we have from you in relation to specific data tasks. "Research Partners" are organisations we collaborate with for data matching and enhancement, such as: (i) media measurement organisations, TV channels and broadcasters; (ii) advertising technology and measurement companies; (iii) streaming and digital content providers; (iv) retailers and e-commerce platforms; (v) data providers and aggregators; and (vi) other market research organisations.

7.4 We use the Survey Data provided by our Users (by filling in questionnaires) to allow the applicable Measure Partners and/or Measure Customers to analyse the survey responses for market research purposes. We may also use the Survey Data ourselves to generate market research reports in aggregate form and/or user-level insights. Where user-level Survey Data is shared outside Measure, it is first scrubbed of identifiers and references so that recipients cannot re-identify you (see Section 7.13).

7.5 We use the Passive Data we collect from you to: (i) generate market research reports in aggregate form, and/or user-level insights; (ii) pre-select you for surveys or data tasks and then ask you to participate in these surveys or data tasks; and (iii) when you consent to it, allow specific Measure Partners and Measure Clients to access your pseudonymised Passive Data to generate market research reports in aggregate form, and/or user-level insights. Where user-level Passive Data is shared outside Measure, it is first scrubbed of identifiers and references so that recipients cannot re-identify you (see Section 7.13).

7.6 For Retro, we automatically extract pertinent data from the screenshots, videos and exported files you submit and use it to generate market research reports in aggregate form, and/or user-level insights. Where user-level Retro Data is shared outside Measure, it is first scrubbed of identifiers and references so that recipients cannot re-identify you (see Section 7.13).

7.7 We use the Browser Extension Data you choose to share to generate market research insights, including understanding purchase behaviour, media consumption, and how people use search, browsing, and generative-AI services. We analyse this data for scientific and statistical research, and we share it externally only as aggregate findings, as research outputs (such as models or taxonomies), or as individual-level data (including free text and behavioural sequences, known as journeys) that has first been scrubbed of identifiers and references. Scrubbing is the failsafe that anonymises this data to the recipient: once identifiers and references are removed, a recipient who receives the scrubbed output cannot re-identify you. Where special category data is present, we handle it as described in Section 7.13. The collection of Browser Extension Data, and its use for this market research processing, relies on your consent (Article 6(1)(a) UK GDPR) rather than legitimate interests, as set out in the table at Section 7.8.

7.8 Lawful basis and the table below

We have set out below, in a table format, a description of all the ways we plan to use your Personal Data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. Note that we may process your Personal Data for more than one lawful ground depending on the specific purpose. For the collection of behavioural data through Passive Tracking and the Browser Extension, which involves storing information on, or accessing information from, your device, we rely on your consent (Article 6(1)(a) UK GDPR), together with consent under the Privacy and Electronic Communications Regulations (PECR). We do not rely on legitimate interests for that collection.

Purpose/ActivityType of dataLawful basis for processing including basis of legitimate interest
To register you as a new customer and set you up to be able to participate in surveys and other data tasks(a) Registration Data (b) Demo Data(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to know our customer, to provide our services and be able to keep records of our interactions with them)
To collect behavioural data through Passive Tracking and the Browser Extension (device access and storage only โ€” including search, browsing, and generative-AI conversation data). *The market-research and other uses of this data are separate purposes, set out in the rows below and in Sections 7.2โ€“7.7.*(a) Passive Data (b) Browser Extension DataWe access and use this information for the following essential purposes: to prepare and carry out the task you have requested (including temporarily assembling and transmitting the file for that task) and to verify its completion so we can pay your reward (performing our contract with you); to maintain the security of our service (our legitimate interest in protecting the service and its users); and to meet our legal obligations (compliance with law). For non-essential uses: Consent (under PECR for storing or accessing information on your device).
To process and deliver our survey and data measurement services to our Users and provide them with rewards, including: (a) Managing the data tasks (b) Selecting and/or matching you, for specific data tasks (c) delivering rewards (d) keeping records of the services we provide(a) Registration Data (b) Demo Data (c) Rewards Data (d) Transactional Data (e) Ratings Data (f) Survey Data (g) Customer Support Data (h) Passive Data (i) Retro Data (j) Browser Extension Data (k) Matching Identifiers (l) Cross-partner Audience & Attribution(a) Performance of a contract with you (b) Necessary for our legitimate interests (to provide the services to you and to keep records of our services) (c) Necessary to comply with a legal obligation (d) Consent, for the underlying collection of Passive Data and Browser Extension Data
To carry out market research on the data you have shared, including research that uses free-text content(a) Demo Data (b) Rewards Data (c) Transactional Data (d) Ratings Data (e) Survey Data (f) Retro Data (g) Matching Identifiers (h) Cross-partner Audience & Attribution(a) Necessary for our legitimate interests (to conduct market research and provide our services), supported by performance of a contract
To carry out market research on the data you have shared through Passive Tracking or the Browser Extension, including research that uses free-text content(a) Passive Data (b) Browser Extension Data(a) Consent (Article 6(1)(a) UK GDPR), to use this information for market research purposes. (b) For special category content that we keep, your separate explicit consent (Article 9(2)(a) UK GDPR), with the safeguards in Section 7.13. (c) For detecting and removing special category content you have not consented to, our legitimate interests in compliance and data minimisation (Article 6(1)(f) UK GDPR).
To manage our relationship with you(a) Registration Data (b) Customer Support Data(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests
To administer and protect our business and the Website and the App(a) Registration Data (b) User Data (c) Opt-in Data (d) Customer Support Data(a) Necessary for our legitimate interests (for running our business, network security, to prevent fraud) (b) Necessary to comply with a legal obligation
To use data analytics to improve our Website, the App, our products and services, our marketing, and our customer relationships and experiences(a) Registration Data (b) Transactional Data (c) User Data (d) Customer Support DataNecessary for our legitimate interests (to keep our Website and the App updated and relevant, to develop our business, and to inform our marketing strategy)
To share identifiers with Partners for data matching, audience or panel identification, and research opportunity discovery; to receive and process matched data from Partners(a) Demo Data (b) Survey Data (c) Passive Data (d) Retro Data (e) Matching Identifiers (f) Cross Partner Audience & Attribution Data(a) Necessary for our legitimate interests (to conduct market research, identify research opportunities, and provide comprehensive insights) (b) Performance of a contract with you
To use the data you have shared for advertising and ad-targeting through data marketplaces (Section 9)(a) Demo Data (b) Survey Data (c) Browser Extension Data (d) Retro Data (e) Passive Data (f) Matching Identifiers (g) derived segments and inferences (special category data is excluded)Consent (Article 6(1)(a) UK GDPR), to use this information for advertising and ad-targeting through data marketplaces, only where you have given separate opt-in consent under Section 9

By "essential purposes" in the table above, we mean uses that are strictly necessary to prepare, carry out and verify the specific task or service you have requested, to pay your reward, to keep our service secure, and to meet our legal obligations. This mirrors the narrow "strictly necessary" exemption recognised under PECR Regulation 6 for storage of, or access to, information on your device. We do not rely on "essential purposes" for market research, profiling, advertising or any other use of Passive Data or Browser Extension Data; those uses require your consent, as set out elsewhere in this table and in Sections 7.13 and 9.

7.9 Aggregated and/or Anonymised Data

We may share Aggregated Data about our Users, and information collected from providing those services, for example by publishing market reports or providing our business partners with information on trends. Read more: what "aggregated" means. We may also share user-level data, including free text and journeys, once it has been scrubbed of identifiers and references so that recipients cannot re-identify you, as described in Section 7.13.

7.10 Marketing and Promotional Offers

We may use your personal data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing). You will receive marketing communications from us if you have requested information from us or purchased our services and you have not opted out of receiving that marketing. We will get your express opt-in consent before we share your Personal Data with any third party for marketing purposes.

7.11 Opting Out

You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time. Where you opt out of receiving these marketing messages, this will not apply to Personal Data provided to us because of a product or service purchase, product/service experience or other transactions.

7.12 Change of Purpose

We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your Personal Data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Where we wish to use your data for the data marketplace and advertising purpose described in Section 9, we treat this as a new purpose and ask for your separate, explicit opt-in consent. Where data was collected under consent (for example, through the Browser Extension or Passive Tracking), we will not switch to a different lawful basis for further processing of that data without obtaining your fresh consent.

7.13 Special category data

Some of the activities you choose to share with us, including your search history, your browsing history, and your conversations with generative-AI assistants, are shared with us in full. These can contain special category data, most often about health (for example, searches or questions about medications, symptoms, or treatments), and occasionally information that could reveal political opinions, religious beliefs, or sexual orientation.

We do not specifically ask you to share this information, and our research does not depend on any one person's sensitive information. Where it is present in what you share:

  • We ask for your separate, explicit consent before we keep it. Where you give that consent, we process this information under Article 9(2)(a) of the UK GDPR (explicit consent), and only for research. This consent is in addition to the consent you give for the task itself, and you can withdraw it at any time in Settings without affecting your participation.
  • If you do not consent, we do not keep it. Sensitive information detected in what you share is removed. We run automated checks for this, and because the content is free text we cannot guarantee that every instance is found โ€” which is why we ask you not to include it unless you have consented.
  • We hold your data under pseudonymisation. Your behavioural data is keyed to a code, and the information that identifies you is held separately and protected.
  • We apply data minimisation, access controls, and retention limits, and we do not use this information to make decisions about you as an individual.
  • Before any individual-level data (including free text and journeys) is shared outside Measure, we scrub it of identifiers and references. Scrubbing is the failsafe that anonymises the data to the recipient: once identifiers and references are removed, the content carries no bridge to you, so a recipient who receives the scrubbed output cannot re-identify you. On this basis a scrubbed statement (including one that mentions health) is anonymised to that recipient, even though it remains personal data to Measure, which holds the key.
  • For journeys (time-ordered behavioural sequences), we scrub identifiers and references, and the journeys contain no location data. Because a time-ordered sequence carries more re-identification risk than a single attribute does, we do not rely on scrubbing alone: we share journeys only with research recipients, who use the detailed data to develop broad patterns, and not with advertising technology firms or data brokers. We keep that restriction under review against a documented re-identification assessment.
  • We do not use this information for advertising or marketing.

7.14 Cookies and similar technologies

We use cookies and similar technologies โ€” including identifiers, and software that stores information on, or reads information from, your device. They do different things in two different places, so we describe each separately.

7.14.1 In our App, Browser Extension and Web Services. Here they distinguish you from other users, operate our products, and carry out the data collection you have agreed to. Where the law requires it we rely on your consent to store or access information on your device, and you can manage or withdraw that consent. This is the collection described in Sections 6 and 7, and it happens only for the tasks and channels you have enabled.

7.14.2 On our marketing website (measureprotocol.com). This is a different context with a different audience: most visitors are not panelists, and nothing here is part of a research task. On the marketing website we use:

  • Essential cookies, which store your cookie-consent preference;
  • Analytics cookies โ€” for example Google Analytics, when enabled โ€” to understand how the site is used; and
  • Marketing and identification technologies โ€” for example RB2B, when enabled โ€” described at 7.15.

Non-essential cookies and similar technologies load only after you accept them through the cookie banner on the website. For detailed information on the cookies and similar technologies we use, see our cookie policy.

7.15 Website visitor identification and marketing

When you visit or log in to our marketing website, cookies and similar technologies may be used by our online data partners or vendors to associate that activity with other personal information they or others already hold about you, including by association with your email address. We, or service providers acting on our behalf, may then send communications and marketing to those email addresses.

This applies to our marketing website only. It is not part of the App, the Browser Extension or any research task, and it is not connected to your panel participation or to any data you have shared with us as a panelist.

You can opt out in either of two ways:

  • Opt out of receiving this advertising at https://app.retention.com/optout
  • Opt out of the collection of your personal data at https://www.rb2b.com/rb2b-gdpr-opt-out

These technologies load only after you accept non-essential cookies through the banner on our website, and you can withdraw that acceptance at any time.

8. Disclosures of Your Personal Data

8.1 We may share your Personal Data with the parties listed below, as described in the table in Section 7.8 above:

  • Measure Partners and Measure Customers connected to the research projects you agree to participate in;
  • Service providers and cloud storage providers who provide us with IT and system administration services or any other services we require to operate our business such as data mining / metering services, data analysis, processing of rewards or incentives, or for market research product development purposes;
  • Professional advisers including researchers, lawyers, bankers, auditors, and insurers;
  • HM Revenue & Customs (United Kingdom), regulators, and other authorities;
  • Our successors in title, our prospective sellers or buyers of our business, or our affiliates in connection with a merger or reorganisation of our business or assets.
  • We may check some of the information that you provide against third party databases to confirm that it is accurate, for example: (i) validating that your post code is accurate; (ii) with your consent, validating your Profile Data against LinkedIn (and using this to enrich Profile Data); (iii) with your consent, validating the data captured through any or all approaches mentioned against the social media IDs you may provide (and using this to enrich Profile Data).
  • Research Partners, data providers, measurement companies, and other third parties as specified in Section 7 above.
  • Where you have given separate opt-in consent, the data marketplace platforms described in Section 9.

8.2 We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Data for their own purposes, and permit them to process your Personal Data only for specified purposes and in accordance with our instructions.

9. Optional Sharing That Identifies You

9.1 What this section covers. Everything else in this Notice describes how we use your data for market research. This section describes something different: sharing your data in a form that lets someone else recognise you as an individual. There are two kinds, and both are optional, both need your separate opt-in, and neither happens unless you choose it.

  • Part A โ€” advertising through data marketplaces. Your data is made available to advertising buyers through marketplace platforms, so they can match and link it to their own records in order to recognise and target you. Covered at 9.2โ€“9.9.
  • Part B โ€” sharing directly with a company we name. A defined set of your details is shared once, with a single company we name to you at the time we ask, for a specific purpose we tell you. This is not advertising. Covered at 9.12โ€“9.18.

If you do not opt in to either, your data is used only as described elsewhere in this Notice. Opting in to one does not opt you in to the other, and you can withdraw either without affecting the other or your research participation.

Two things are true of both: special category data is never included (see 9.5), and neither is available to users under 16 (see 9.10). Section 9.11 explains what happens if we make a material change to either.

Read more: your optional sharing choices, and how they fit together.

Part A โ€” Advertising through data marketplaces

9.2 Separate, explicit consent. Advertising use is a new and distinct purpose from market research. Because of that, we ask for a separate, explicit opt-in consent, which you can give or withdraw at any time from your account settings. Your data flows to a marketplace only for the platforms you have specifically enabled. For Browser Extension and Passive Tracking, you can only give advertising consent if you already have active market research consent for that data โ€” advertising consent builds on that consent and cannot exist without it. You can withdraw your advertising/marketplace consent alone, at any time, without affecting your market research participation.

9.3 The delivery channel. Where you opt in, your data is delivered to advertising buyers through data marketplace platforms, which are the channel for this purpose rather than its definition. The platforms we use are Narrative, Snowflake, and Databricks. You can enable or disable each independently.

9.4 The data that may be used. With your consent, the following may be used for advertising: your Demo Data; your Survey Data and research tasks; Retro Data or Passive Data; behavioural information from your accounts shared through the Browser Extension; advertising identifiers; and profiles, segments and inferences we create from this data. This covers both data we have already collected and data we collect in the future.

9.5 Special category data is excluded. We do not make special category data (such as health, or data revealing political opinions, religious beliefs, or sexual orientation) available for advertising or to any marketplace, and we do not make available any segment or inference derived from special category data. Only pre-approved, non-special data categories are made available, and we apply automated controls to keep special category content out.

9.6 The purposes the data may be used for. Audience matching, data augmentation, campaign measurement, and advertising, profiling and ad-targeting.

9.7 Who receives your data. Your data flows to the marketplace platforms named above, which mediate and manage the relationships with the businesses that license data through them. Because the marketplaces manage those onward relationships, we may not know or control each end buyer, so we describe the marketplaces and the categories of recipients and purposes here rather than naming individual buyers. When you give or review your consent, we show you each marketplace by name and you choose which ones to enable. Your data flows only to the platforms you have specifically enabled. Today those are the three named in 9.3; we add a new marketplace to that list only as it goes live, and enabling it is a fresh choice you make โ€” it is never added to an existing consent. You can review your choices, and change or withdraw them, at any time from your account settings. We impose contractual restrictions on how the data may be used. Buyers may use your data only for the advertising and ad-targeting you have consented to. They are prohibited from: (i) using it for any other purpose; (ii) deriving additional direct identifiers from it, or reversing the identifiers we provide to recover contact details they did not already hold; (iii) building or selling a standalone identified profile of you for any non-advertising purpose; (iv) using it to make decisions producing legal or similarly significant effects (such as credit, insurance, or employment); and (v) retaining or using it after you withdraw consent. Special category data is never made available (see 9.5).

9.8 Lawful basis. Because special category data is excluded, we rely on your consent (Article 6(1)(a) UK GDPR), together with consent under PECR where information is stored on or accessed from your device. We do not rely on legitimate interests for this purpose.

9.9 How to withdraw your consent. Your consent is as easy to withdraw as to give. You can turn off a specific marketplace or withdraw all marketplace consent, from your account settings or by contacting our DPO. When you withdraw, we immediately stop including your data in any new marketplace export and signal the affected marketplace to stop using your data and delete it under our agreements, which require the marketplace and any onward recipients to do the same. Under our agreements, marketplaces and onward recipients are required to delete your data within 30 days of a withdrawal or deletion request. Recall of data already lawfully shared may not be instantaneous, though we require prompt deletion under our agreements. If you want full deletion, you can also exercise your right of erasure under Article 17 UK GDPR. If you withdraw your market research consent instead, this automatically withdraws your advertising consent too, since advertising consent depends on it. However, where we rely on a lawful basis other than consent โ€” for example, our legitimate interests for Survey Data or Retro Data โ€” we can continue that market research processing regardless of your advertising consent choices. You can withdraw advertising consent while keeping your market research consent in place; withdrawing advertising consent does not affect your research participation. We keep records of your consent decisions, including timestamp and scope, for accountability.

9.10 Children. Neither kind of sharing in this section โ€” marketplace or direct โ€” is available to users under 16. See Section 13.

9.11 Material changes. If we make a material change to how either kind of sharing operates โ€” for example, adding a new marketplace, or a new purpose โ€” we will notify you as described in Section 4 and, where the law requires it, ask for fresh consent before any data flows under the new arrangement. For the direct sharing in Part B, every separate instance is a fresh request: a new company, or a new purpose, is always a new consent and never an addition to one you have already given.

Part B โ€” Sharing directly with a company we name

9.12 What this is. Sometimes a company asks us to confirm which of the details we hold about you are genuinely yours, and to share the confirmed set with them. This is different from Part A in every respect that matters to you: it is one company, not a marketplace; we name that company to you before you decide; it is a defined set of details, shared once, rather than an ongoing feed; and the purpose is not advertising.

We only ever ask you about this as a specific, paid task. You can decline, and declining does not affect your account, your rewards, or any other task available to you.

9.13 What we would share. The exact set is listed on screen before you consent, and it is only ever the details we have confirmed with you. It may include your confirmed email addresses and phone numbers, your usernames and handles for the services concerned, your account IDs, your device's advertising identifier, and โ€” for each of those โ€” where we found it and how strongly it has been confirmed.

Usernames and handles are included, and we want to be plain about what that means. They are direct identifiers: a recipient can use one to recognise you, and to connect what they already know about you across the services where you use the same handle. That is the purpose of this kind of task, not a side effect of it. It is why we ask for your separate consent, name the recipient before you decide, show you every detail we hold and where it came from, and limit by contract what the recipient may do with it (Section 9.16).

9.14 Where these details come from. This matters, so we want to be plain about it. When you connect an account to Measure, the data export from that account often contains an email address, a phone number or a username. We collect those into a single picture of the details associated with you. Depending on which accounts you have connected, that can include services such as Amazon, Instagram, YouTube, Facebook, Pinterest, ChatGPT, X, Reddit, Snapchat, Lemon8 and TikTok. We also hold your device's advertising identifier, which the Measure app collects directly.

Before we share anything, we show you the details we hold and tell you which of your connected accounts each one came from. You can add anything missing, and you can tell us if something is not yours โ€” in which case we leave it out.

9.15 How we confirm the details are yours. Because the point of this sharing is accuracy, we confirm the details before sending them. That involves two steps, both explained on screen before you agree:

  • A short selfie, processed by us and by our identity-verification provider, to confirm that a real, live person is present. This is biometric information, and we ask for your explicit consent to it. It is used only for that check: no facial template is kept, and we never use it to match you against anyone else.
  • A one-time code sent to each email address and phone number, which you enter back to confirm you control it. We use those details only to send the code.

If you would rather not do either, you do not take part, and nothing is shared.

9.16 What the company may and may not do. We name the company and state its purpose before you consent, and we limit what it may do by contract. It may use the data only for the purpose we have told you about. It is prohibited from using it for any other purpose, from passing it on to anyone else, and from using it to make decisions about you that produce legal or similarly significant effects. We do not sell your data. Where the stated purpose is confirming or matching the company's own records, that does not include using the data to target advertising at you or to buy media against you.

9.17 Lawful basis. We rely on your explicit consent (Article 6(1)(a) UK GDPR), and on your explicit consent under Article 9(2)(a) for the biometric processing in 9.15, together with consent under PECR where information is stored on or accessed from your device. The company we name is identified to you, the set of details is listed, and the purpose is stated โ€” all before you decide. We do not rely on legitimate interests for this.

9.18 How to withdraw. You can withdraw at any time from your account settings, where you will also find a standing record of what was shared, with whom, and when. When you withdraw we stop sharing immediately and tell the company to delete its copy, which it is required by our agreement to do within a defined period.

One limitation we would rather state than imply: where a set of details has already been sent, withdrawal obtains deletion because the company is obliged to delete it โ€” not because we can reach in and remove it. That is the honest position, and it is one reason we keep what we send to the minimum. If you want full deletion of what we hold, you can also exercise your right of erasure under Article 17 UK GDPR (see Section 14).

10. International Transfers of Personal Data from the EEA or UK

10.1 Measure serves customers globally. Accordingly, your Personal Data may be shared with other entities outside of the European Economic Area ("EEA") or the UK, when this is necessary for the purposes mentioned in this Notice. These countries include the countries in which we have operations. It also includes the countries in which some of our service providers are located.

10.2 Our data is hosted on cloud infrastructure provided by Amazon Web Services (AWS), located in the United States, with Measure Protocol Limited as the data exporter. That transfer is made under AWS's certification to the UK Extension to the EU-US Data Privacy Framework, and is additionally covered by the Standard Contractual Clauses and the UK International Data Transfer Agreement Addendum contained in the AWS Data Processing Addendum. Where we transfer personal data to any other recipient outside the UK or EEA, we rely on appropriate safeguards: where the receiving party is certified under the UK Extension to the EU-US Data Privacy Framework, we rely on that certification; otherwise we put in place Standard Contractual Clauses and the UK International Data Transfer Agreement Addendum, and we complete a transfer risk assessment for the receiving country before the transfer takes place.

10.3 For the data marketplace use described in Section 9, any transfer to a buyer outside the UK or EEA is protected by Standard Contractual Clauses and the UK International Data Transfer Agreement Addendum, with a transfer risk assessment completed for the receiving country before transfer.

10.4 If you want to receive more information about these safeguards, you can contact us using the details set out in this Privacy Notice.

11. Data Security

11.1 We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Data on our instructions, and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator if we are required to do so.

12. How Long Will We Use Your Personal Data For?

12.1 We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

12.2 To determine the appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

12.3 We distinguish between Individual Level Data (data that still relates to an identifiable individual) and Aggregated Data (data that has been aggregated or anonymised so that you can no longer be identified). Aggregated Data is no longer personal data and may be retained without the time limits that apply to Individual Level Data.

12.4 As a general guide:

CategoryRetention
App and Demo Data (on device)While the App is installed; deleted on uninstall
Registration, Rewards, Ratings, Customer Support6 years from end of relationship (Limitation Act 1980)
Transactional Data6 years; orphaned from behavioural data on account closure
Survey DataUp to 6 years
Retro raw filesUp to 30 days, deleted after QA
Retro extracted dataUp to 6 years
Browser Extension raw3 months (rolling)
Browser Extension โ€” Individual Level DataUp to 6 years
Passive DataInactive; if reactivated, 3 months raw and up to 6 years as Individual Level Data
Cross-Partner DataUp to 3 years, then deleted or anonymised
Verbatim free text containing special category content, where you have consentedUp to 6 years from the date you submitted it, then deleted or permanently separated from anything that identifies you. If you withdraw your consent we delete it at that point instead โ€” see Section 7.13. Where you have not consented, we do not keep it at all
Marketplace export records (logs of data made available under Section 9)Up to 6 years, being the limitation period for contract claims under section 5 of the Limitation Act 1980 (accountability)
Orphaned behavioural data (post key-deletion)Indefinite (no longer personal data)

Genuinely transient operational artifacts (for example, a raw screenshot before its fields are extracted) are reduced or deleted sooner.

12.5 Please contact us using the contact details set out in this Privacy Notice if you have any questions about data retention.

13. Children and Young People

13.1 Measure's services are only available to individuals aged 16 and over, and we do not knowingly collect data from anyone under 16. We use age verification at registration and ongoing participation criteria designed to exclude under-16s. No Browser Extension or Passive Tracking consent is sought from, and no device access is performed for, anyone under 16.

13.2 We apply additional protections to data from younger participants. Records from participants under 18 are excluded from any individual-level research dataset that contains special category content, and from any health-themed research output. Marketplace data sharing under Section 9 is not available to anyone under 16.

13.3 If you believe a child under 16 has provided us with personal data, please contact us at privacy@measureprotocol.com and we will take steps to delete it.

14.1 You may cancel your participation in surveys or other data tasks, such as Passive Tracking or Browser Extension sharing, by deinstalling the software, removing the extension, using the "Stop Sharing" control, or contacting us. If you do so, please note that we will continue to process the data we collected before your cancellation. Using the "Stop Sharing" control or removing the Browser Extension stops any further device access or collection immediately, and consent for that channel is treated as withdrawn for future processing. Where you withdraw from research collection, we stop processing and sever the behavioural data from your Registration Data so that it no longer identifies you; de-identified data may be retained as described in Section 12.

14.2 Under certain circumstances, you have rights under data protection laws in relation to your Personal Data. If you wish to exercise any of your legal rights, please contact us using the contact details set out in this Privacy Notice.

14.3 You have the right to:

  • Request access to your Personal Data. This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
  • Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your Personal Data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  • Request restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of your Personal Data in the following scenarios: (a) If you want us to establish the data's accuracy; (b) Where our use of the data is unlawful but you do not want us to erase it; (c) Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; and (d) You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request the transfer of your Personal Data to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

14.4 No Fee Usually Required

You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances. We will notify you if this is the case at the time.

14.5 Time Limit to Respond

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.

14.6 Exceptions

It may not be possible for us to delete your Personal Data if we are required to keep it by law or if we hold it in connection with a contract with you. Similarly, access to your Personal Data may be refused if making the information available would reveal Personal Data about another person or if we are legally prevented from such disclosure.

15. Specific Notice to California Users

The following paragraphs apply to California residents.

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA/CPRA"), verifiable residents of California have additional rights as outlined below.

Your rights:

  • Opt out of the sale or sharing of your personal data. California residents have the right to opt out of the sale or sharing of their personal data, including sharing for cross-context behavioural advertising. You can submit a request at https://www.measureprotocol.com/donotsellmypersonalinformation. The data marketplace use described in Section 9 is treated as a sale or share, and is subject to this opt-out.
  • Limit the use of sensitive personal information. Where we process sensitive personal information (which can include health information), you have the right to limit its use to what is necessary to provide the services. We do not use sensitive personal information for advertising, and we do not sell or share it.
  • Right to Non-Discrimination for the Exercise of a Consumer's Privacy Rights. You have the right not to receive unlawful discriminatory treatment for the exercise of your privacy rights.

Categories of Personal Information Collected, Sold, Shared, or Disclosed

Measure collects personal information from research participants using the Measure MSR app, Browser Extension, and Web Services during and after registration, including during participation in surveys or other data collection tasks and in connection with the receipt and redemption of rewards. These tasks may be for Measure's own purposes or in conjunction with partners.

Measures are taken to minimise, scrub, and aggregate data where possible to protect users' data and privacy pursuant to this policy, including scrubbing user-level data of identifiers and references before it is shared outside Measure. Categories of personal information we may collect are outlined in Section 6, and the purposes are outlined in Section 7.

We do not sell or share data that identifies you without your prior consent. This is the whole of our position, and it holds in both directions: where we make data available to third parties for commercial purposes we do so in de-identified form, and the one use that makes you identifiable to a recipient โ€” the advertising and ad-targeting use described in Section 9 โ€” happens only if you opt in to it separately.

Why de-identified sharing is not a sale. Data we have de-identified is not personal information under the CCPA, so making it available is not a sale or a share. That rests on three things, all of which apply:

  • We apply reasonable measures to ensure the data cannot be linked back to you, and we do not release data where those measures would not hold. Section 7.13 and our scrubbing and anonymisation process explain how.
  • We publicly commit to maintain and use that information in de-identified form, and not to attempt to re-identify it, except where testing our own de-identification requires it.
  • We contractually require anyone who receives it to do the same.

Categories that may be sold or shared. Where you have opted in under Section 9, Measure may sell or share the following categories: Demo Data, Survey Data, Retro Data, Browser Extension Data (excluding special category content), and Matching Identifiers. Measure does not sell or share sensitive personal information, and does not sell or share the personal data of anyone under 16.

Categories sold or shared in the preceding 12 months. None. In the preceding 12 months Measure has not sold or shared personal information, and has made no data available under the Section 9 advertising and ad-targeting opt-in. We have not sold or shared sensitive personal information in that period, and we have not sold or shared the personal data of anyone under 16.

Accessibility of Privacy Notice

Measure is committed to providing a site and Privacy Policy that is accessible to the widest possible audience regardless of technology or ability. If you experience difficulty in accessing any part of this website or this Privacy Policy, please email us at privacy@measureprotocol.com and we will work with you to provide the information, item, or transaction you seek through an alternate communication method or that is accessible for you consistent with applicable law.

Published: 4 September 2026 ยท Effective: 21 September 2026