Platforms Use cases
Privacy Policy

How Crumblinks handles data

Crumblinks is an attribution platform for game and web journeys. This policy explains what data may be processed when studios, publishers, developers, performance marketing teams, UA teams, growth teams, creator teams, and influencer marketing teams use Crumblinks to track attribution and conversions.

Last updated: August 3, 2026

1. Scope

This Privacy Policy applies to the Crumblinks website, product dashboard, tracking links, SDKs, server-side event endpoints, and related services. It covers data we process for our own website and account operations, and data we process on behalf of customers who configure Crumblinks for their campaigns, games, websites, or creator programs.

Private application and dashboard data is not intended to be public or crawlable. Public pages such as the marketing website, this policy, sitemap, and documentation files may be accessible without signing in.

2. Roles

For customer-configured attribution and event tracking, the customer decides what campaigns, links, events, platforms, and conversion goals are tracked. In that context, Crumblinks generally acts as a service provider or processor for the customer. For our own website, account administration, security, and communications, Crumblinks may act as an independent controller of the relevant data.

3. Data We May Process

Customer account and workspace data

When a customer or user creates an account, accesses a workspace, or contacts us, we may process account and contact data such as name, email address, company or team information, role, login metadata, workspace settings, project names, tracker configuration, and support messages.

Campaign, link, and attribution data

Crumblinks may process campaign and attribution data such as tracking links, landing pages, referrers, UTM parameters, campaign names, source and medium labels, creator or influencer identifiers configured by the customer, ad campaign identifiers, click IDs, timestamps, and Crumblinks tracking IDs.

Crumblinks ID

A Crumblinks ID, sometimes represented as crumblinks_id or another implementation-specific identifier, is a pseudonymous identifier used to connect clicks, links, campaigns, visits, and conversion events. It is designed to support attribution without requiring Crumblinks to know a player's real-world identity.

Device, browser, and network data

Depending on customer configuration and how a user interacts with Crumblinks-enabled links or pages, we may process technical data such as IP address, user agent, browser type, operating system, device characteristics, language, approximate location derived from IP address, screen or viewport information, timestamps, and cookie or local storage identifiers where applicable.

Game and conversion event data

Customers may configure Crumblinks to receive conversion and product events. Depending on the platform and customer implementation, this may include Steam wishlist, purchase, and activation signals; Minecraft game or server visits, joins, and purchases; Roblox traffic sources, game or experience visits, and in-game purchases; and other custom events selected by the customer.

Steam and Meta server-side conversion data

When a customer enables the Meta Conversions API integration for a Steam tracker, Crumblinks may store limited information from the original Meta campaign redirect so that a later Steam conversion report can be matched and sent to Meta server-side. This may include Meta click and browser identifiers such as fbc and, when actually received, fbp; the original IP address and user agent; the Crumblinks landing URL; a Steam application identifier; and the redirect timestamp. Crumblinks does not create an fbp identifier when one was not received.

Steam reports used by this integration provide boolean conversion signals but do not provide a reliable row-level event time for this workflow. The event time shared with Meta is therefore the time Crumblinks first observed the signal during CSV import. It is approximate and may be later than the person's actual wishlist, purchase, or activation. Crumblinks does not add a synthetic purchase value or currency to these Meta events.

4. How Data Is Collected

Data may be collected when a person visits our website, opens a Crumblinks tracking link, lands on a customer page that uses Crumblinks, triggers an event through a customer-integrated SDK or server-to-server integration, signs in to the dashboard, or communicates with us.

Crumblinks may use cookies, local storage, pixels, SDK requests, server-side events, postbacks, and similar technologies to receive and associate events. The exact collection method depends on the customer's implementation and the user's browser or platform settings.

5. How We Use Data

We use data to provide, maintain, secure, and improve Crumblinks. Typical uses include:

6. Customer Responsibilities

Customers are responsible for configuring Crumblinks lawfully and for providing any notices, disclosures, choices, or consents required for their own websites, games, stores, communities, and marketing campaigns. Customers should not send Crumblinks sensitive personal information unless they have a valid legal basis and a written agreement with us that permits that processing.

If a customer enables Steam conversion sharing with Meta, the customer's notice should explain that campaign redirect information may be retained and combined with a later Steam conversion signal, and that a limited server-side event may be sent to Meta for measurement, attribution, reporting, or campaign optimization. Customers are responsible for configuring Meta, obtaining any required consent, honoring user choices, and selecting only advertising accounts and Event Sources they are authorized to use.

Practical example: if a customer uses Crumblinks to track a Roblox experience visit or a Minecraft server purchase from a campaign link, the customer is responsible for making sure their own user-facing notices explain that tracking where required.

7. Sharing and Service Providers

We may share data with vendors and service providers that help us host, secure, operate, analyze, support, or improve Crumblinks. These providers are expected to process data only for the services they provide to us or to our customers.

We may also disclose information if required by law, to protect rights and safety, to investigate abuse, or as part of a business transaction such as a merger, acquisition, financing, or sale of assets. We do not sell customer workspace data as a standalone data product.

8. Third-Party Advertising and Analytics Services

The third-party services that we use on our websites or partner websites are listed below:

These services may process identifiers and event data such as campaign IDs, click IDs, referrers, UTM parameters, Crumblinks IDs or other pseudonymous IDs, device and browser information, network information such as IP address, and conversion or product events. The exact data shared depends on the customer's configuration, the advertising platform, the browser or device settings, and the relevant campaign flow.

For customer-enabled Steam Meta conversion reporting, Crumblinks may send Meta a fixed event name, an approximate first-observed import time, a pseudonymous event ID, the original landing context, and available matching data such as fbc, a received fbp, IP address, and user agent. This integration is not enabled for every customer or tracker, and Crumblinks does not send email or phone data through this Steam workflow.

9. Retention

We retain data for as long as reasonably needed to provide the service, maintain attribution reports, support customers, comply with legal obligations, resolve disputes, enforce agreements, and protect the service. Retention periods may vary depending on the type of data, customer configuration, contract terms, backup schedules, and operational requirements.

For the Steam Meta Conversions API workflow, original redirect match data is normally retained for up to 90 days and then deleted. Sensitive request snapshots associated with completed, failed, skipped, or cancelled Meta deliveries are normally redacted after 30 days, while non-sensitive delivery status, identifiers, timestamps, and limited diagnostics may remain for audit and reliability purposes. Data may be deleted earlier when the customer disconnects Meta, deletes the relevant tracker, or completes an applicable provider data-deletion flow.

10. Security

We use administrative, technical, and organizational measures intended to protect data from unauthorized access, loss, misuse, or alteration. No internet service can guarantee perfect security, so customers should also protect their account credentials, restrict workspace access, rotate integration credentials when needed, and configure events carefully.

11. International Transfers

Crumblinks may process and store data in countries other than the country where a user or customer is located. Where required, we use appropriate contractual, technical, and organizational measures for cross-border processing.

12. Privacy Rights and Choices

Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing. If the request relates to a customer's campaign, game, or workspace, we may direct the individual to that customer or work with the customer to respond.

Browser settings may allow users to block or delete cookies and local storage. Some tracking and attribution features may not work as intended if these technologies are disabled.

Meta data deletion requests

Meta may send Crumblinks a signed data-deletion callback when a connected business integration is removed or a deletion request is initiated. After validating the request, Crumblinks cancels affected unsent delivery work, deletes the related Meta configuration and match-data records within the relevant customer workspace, preserves limited non-sensitive delivery history where needed for reliability and audit, and returns an opaque confirmation code. Individuals may also contact us or the relevant customer using the details below.

13. Children's Privacy

Crumblinks is a business service for game companies and marketing teams. It is not directed to children as a standalone consumer product. Customers are responsible for determining whether their own games, experiences, servers, websites, or campaigns require additional notices, parental consent, age gates, or other protections.

14. Changes to This Policy

We may update this policy from time to time. When we make changes, we will update the date above and may provide additional notice where appropriate.

15. Contact

If you have questions about this Privacy Policy or want to make a privacy request, contact us through the Crumblinks website. If your request concerns a specific game, campaign, creator link, Steam title, Minecraft server, or Roblox experience, please include enough context for us to identify the relevant customer or workspace.