Skip to main content

Data and security overview

Leading ecommerce businesses use Rokt Ecommerce to make the Transaction Moment™ more relevant for each individual customer. Rokt uses advanced AI to determine and render the next best action for each customer in real time, based on the signals you provide about customer behavior, preferences, and transaction context.

You are in complete control of the data you choose to integrate and how it is applied. Your data remains yours and is only ever used to deliver relevance on your site; it is never sold or shared with third parties.

You can use your data to:

  • Personalize the experience: Tailor messages and experiences for different customer contexts, such as recognizing returning customers or loyalty members.
  • Maximize relevance: Harness Rokt's advanced AI to predict what each customer is most likely to engage with and avoid showing actions or offers they cannot use or redeem.
  • Fulfill customer requests: Deliver the right follow-up when a customer takes an action, such as sending a confirmation email with offer redemption details or adding an item to a cart.

Classes of dataDirect link to Classes of data

Rokt enables you to take advantage of four types of data to deliver relevance to your customers while they are on your site.

CategoryDescription
Your Data
Examples: Name, email address, customer ZIP code, payment type, cart value, order confirmation number
Your data is referred to as "Partner Data" in Rokt's agreement. This is any data you choose to integrate with Rokt to create a better experience in the checkout. Typically, this includes data from the ecommerce transaction, such as a customer's name, ZIP code, and cart value. It can also include an aspect of the customer's profile, such as whether they are a first-time shopper or a member of your loyalty program. This data is confidential information that is wholly owned by you at all times and is only used for your purposes. Think of Rokt as you would your CRM or email service provider (ESP). Rokt serves as a trusted platform that you can use to accomplish your business objectives and never shares your data with third parties.
Rokt Data/Derived Data
Examples: Date and time of customer engagement, customer engaged with creative1234, customer added product1234 to their cart
Rokt also improves the customer experience using its own data, referred to as "Derived Data" in Rokt's agreement. Rokt's machine learning creates lookalike segments, similar to the decisions made by Facebook's algorithm. Derived Data is also used to ensure relevant creative rotation so customers who never add a certain upsell to their cart do not see it repeatedly. Rokt owns Derived Data and uses it to benefit all Rokt Ecommerce clients and their customers.
Advertiser & Provider Data
Examples: Audience lists, creative ID, conversion event
This is the data that Rokt manages as a trusted intermediary on behalf of its Advertisers and Providers. This data is confidential information that is wholly owned by the Advertiser or Provider and is only used for its purposes. This data largely comprises audience data, such as suppression and inclusion lists, and conversion data, such as which customers convert into customers of the Advertiser or Provider.
Licensed Data
Examples: Discount shoppers, pet owners
Rokt secures permission to use licensed data from third parties such as LiveRamp for the benefit of all Rokt clients outside the EU or UK. This data builds on Rokt's cohorts and makes experiences even more relevant. It is generally owned by the third party that provides and manages it and licensed to Rokt.

Client data is kept separateDirect link to Client data is kept separate

Your data, as well as other client data from Advertisers and Providers, is stored separately. It is not commingled or combined with data from other clients. Rokt acts as the trusted intermediary between its clients and does not share any given client's data with another.

Data is securely stored in AWSDirect link to Data is securely stored in AWS

Rokt stores data using Amazon Web Services (AWS), with data centers in Oregon, Virginia, Sydney, and Ireland to support caching in different markets.

All data in AWS is encrypted at rest using AES-256. Personally identifiable information is further encrypted at the cell level through envelope encryption using unique keys for each client.

All data access occurs over secure protocols. Data transfers at Rokt use HTTPS/TLS 1.2, SFTP, or IPSec VPN. Insecure connection requests are upgraded to HTTPS where possible or otherwise dropped.

Rokt can encrypt all non-PII data upon request.

AWS service levels for Rokt's core infrastructure are available for the following services:

Data complianceDirect link to Data compliance

See the Trust Center for complete compliance and security information.

Robust content standardsDirect link to Robust content standards

Providing a high-quality experience for the end customer is important to Rokt, so Advertisers and Providers must meet Rokt's quality guidelines and campaign policies for everything displayed on your site. Rokt enforces robust Campaign Policies that meet high standards in each international market where Rokt operates.

While Advertisers and Providers are responsible for the conduct and content of their campaigns, every upsell, creative, campaign, and audience is submitted to an approvals platform and checked for compliance with the Rokt Ads campaign policies by a member of the Rokt team before it is approved and eligible to be shown.

Customer confirmation emailsDirect link to Customer confirmation emails

When you show third-party offers to your customers, certain offers, such as those with a unique coupon code or time-sensitive offer, require the customer to receive a record. When customers accept a third-party offer, they immediately receive a Customer Confirmation Email with the details they need to redeem the offer. Declining an offer or closing the placement does not trigger a confirmation email. You can also include a reminder email scheduled for 24 hours later.

When Rokt Ads clients set up a campaign, they indicate whether a Customer Confirmation Email is required, such as for coupon-code delivery. About 20% of offers require this feature.

You have complete control over whether to enable Customer Confirmation Emails. Enabling them increases offer redemption and can help generate more revenue per transaction.

More questions?Direct link to More questions?

For more information, contact legal@rokt.com.

Was this article helpful?