Menu
1. Introduction
Trillboards ("we," "our," "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our portals and services that turn idle TVs into digital billboards.
By using our services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Personal Information
We may collect the following personal information:
- Name and contact information (email address, phone number)
- Business information (company name, business address)
- Payment information (processed securely through third-party providers)
- Account credentials and profile information
2.2 Usage Information
We automatically collect:
- Device information (device type, operating system, unique device identifiers)
- App usage data (features used, time spent, performance metrics)
- Location data: your screen's GPS position, which the screen reports by default and which we store as a trail of positions with their times; for a screen registered without coordinates, an approximate location from the IP address of the phone or browser registering it, or, for a screen with no coordinates and no address, from the screen's IP address
- Network information (IP address, connection type)
- QR code scans: when you scan a QR code shown on a screen, the scan's time and screen, your phone's IP address and user agent, and the characteristics your browser reports, including a browser fingerprint
2.3 Content and Media
We may collect:
- Advertisements and content you upload to display on your billboards
- Analytics data about content performance and viewer engagement
- Technical data about content delivery and display
2.4 Audience Analytics (Screen Owner Devices)
For screen owners using Trillboards display devices (tablets, TVs, screens in vehicles), the screen collects data about the people and devices near it, to measure advertising and to supply measurement data to our data partners:
- Camera: face count, and for each detected person a record of their estimated age range, gender and dominant emotion, their dwell time and the time they spend looking at the screen, with head orientation, facial measurements and upper-body points for each analysed frame. On devices running the full sensing profile the screen also computes a face-identity template, a numerical vector we use to recognise the same person across screens and days. Camera frames selected for cloud analysis are sent to us and to Google Vertex AI, and we keep them for 400 days; frames captured in May and June 2026 are kept as a model-evaluation set with no scheduled deletion. From those frames a cloud model estimates the ethnicity, age band (from 0-2 to 75+), gender, social composition (including whether a family has children), purchase-intent stage, activity, phone and device use, attire and apparel tier, carried items, lifestyle segments and mood of the people in view, and where each occupant sits, including whether that occupant is driving; we store those estimates with a written description of the scene. No video is recorded.
- Audio: ambient noise levels and environment classification, and speech transcribed on the device; we store the transcript text, and a cloud model (Google Vertex AI) analyses each transcript for purchase intent, brands mentioned, sentiment and conversation type, and we store the results. No audio recording is stored or transmitted.
- Radio: the Bluetooth, Wi-Fi and local-network identifiers that nearby phones and other devices broadcast. We store them as received and as derived device keys, and link a device key to the person observed with it and to mobile device identifiers we receive from a measurement partner.
- Location: the screen's GPS position, stored as a trail of positions; for a screen in a vehicle, the trail records the route it travels.
- Aggregated engagement metrics: Screen interaction patterns and viewer attention scores
Important: Audience sensing runs on the device using on-device AI models, and the screen sends us the per-person records, face-identity templates, speech transcripts, radio identifiers and GPS positions described above, together with statistical summaries. No audio recording is stored or transmitted. Our Data Processing Addendum at trillboards.com/legal/data-processing sets out every category, how long each is kept and who receives it.
2.5 Advertising Identifiers and Installed Application Information (Screen Owner Devices)
Trillboards turns advertising identifier collection on for every screen by default. The Trillboards tablet, tablet-lite and Fire TV apps read the device's advertising identifier and send it to us with the screen's reports, with no consent dialog. The Android TV app reads it only after Google's consent flow, described below, allows ads. On screen-owner devices we collect:
- Advertising identifier (the Google Advertising ID, or the Fire OS advertising ID): a resettable device identifier, which we store in our device registry and use for ad delivery, frequency capping, reconciliation with our demand partners, measurement and cross-device identity resolution.
- List of installed applications on the device: collected by Google's Mobile Ads SDK (play-services-ads-lite) when registered against our content WebView, which happens only after Google's consent flow allows ads. Used by Google's ad-targeting infrastructure to verify app authenticity for ad partners and to power contextual ad selection.
- WebView ad-context bridge state: native-app context (consent state, app version, package name) shared with the Google IMA SDK running inside the playback WebView for VAST ad measurement.
Purpose: We use the advertising identifier for ad delivery, measurement and cross-device identity resolution. The Mobile Ads SDK transmits the installed-application list and the WebView ad context to Google's servers as part of Google's ad-targeting and measurement infrastructure.
Consent and revocation: At launch the apps run Google's consent flow (the User Messaging Platform), which shows Google's consent form where the rules configured for the device's location require one. The Mobile Ads SDK is registered against the WebView, and the Android TV app reads the advertising identifier, only after that flow allows ads: once consent is given, or where no consent is required. Where the form was shown, you may revoke or modify consent via Privacy Settings in the app's operator-PIN-protected settings menu; the Mobile Ads SDK is then not registered and ad serving falls back to limited (non-personalized) mode. Revoking consent does not stop the tablet, tablet-lite and Fire TV apps sending the advertising identifier.
3. How We Use Your Information
We use the collected information for:
- Providing and maintaining our services
- Processing payments and managing your account
- Delivering advertisements to your connected displays
- Measuring audiences at screens, and delivering audience measurement and location data to our data partners (Section 4.4)
- Analyzing usage patterns to improve our services
- Providing customer support and responding to inquiries
- Sending important updates and notifications
- Complying with legal obligations
- Preventing fraud and ensuring security
4. Information Sharing and Disclosure
We sell and share personal information: we deliver audience measurement and location data to our data partners, as described in Section 4.4. We share information in the following circumstances:
4.1 Service Providers
We may share information with trusted third-party service providers who assist us in:
- Payment processing
- Cloud hosting and data storage
- Analytics and performance monitoring
- Customer support services
- Advertising infrastructure (Google AdMob: receives the Google Advertising ID, installed-app information and WebView ad context from screen-owner devices once Google's consent flow allows ads, through the Google Mobile Ads SDK)
4.2 Legal Requirements
We may disclose your information if required by law or in response to:
- Valid legal requests from government authorities
- Court orders or subpoenas
- Protection of our rights, property, or safety
- Prevention of fraud or security threats
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.
4.4 Data Partners
We sell and share audience measurement and location data collected at venue partners' screens with our data partners, for their own purposes, by default. Our data partners fall into four categories: data buyers, data valuation partners, measurement partners and advertising partners. Measurement partners receive hourly audience measurements for each screen with its GPS position, each screen's daily GPS trail and a location record for each approved screen with coordinates. Data buyers receive datasets built from measurement data, such as hourly screen activity, audience attribute mixes, screen-to-screen mobility flows and ad delivery. Data valuation partners receive extracts of measurement data, including device-level records, links between sensed devices and mobile advertising identifiers, and the mobile advertising identifier visits to screens we receive from a measurement partner. Advertising partners (demand-side platforms and ad exchanges) receive each screen's IP address, location and live audience measurements in bid requests. trillboards.com/legal/data-partners describes each category. The Do Not Sell or Share page describes what an opt-out request does.
5. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Secure data centers and infrastructure
- Employee training on data protection
6. Your Rights and Choices
6.1 Access and Control
You have the right to:
- Access and review your personal information
- Update or correct inaccurate information
- Request deletion of your personal information
- Opt-out of marketing communications
- Withdraw consent for data processing
6.2 Location Services
You can control location permissions through your device settings. Disabling location services may affect certain features of our app.
6.3 Data Retention
We keep account information while your account is open. When you delete your account we delete your user record, your advertisements, your saved locations and your consent records, and mark your screens deleted. We then delete your screen records, unless one of your screens has a default content stream, in which case all of your screen records (name, address and coordinates) are kept, marked deleted. The records of your screens' devices (device fingerprint, IP address and advertising identifier) are kept. Data your screens collected (audience measurements, camera frames and the estimates made from them, face-identity templates, radio identifiers and GPS positions) is kept after your account is deleted for the periods set out in Section 6 of our Data Processing Addendum, several of which have no scheduled deletion, and backups keep deleted records until they expire, the last on 1 April 2027.
7. Children's Privacy
Our portals and apps are not intended for children under 13 years of age, and we do not knowingly collect personal information from children under 13 who use them. Screens measure every person their cameras detect, whatever their age: a per-person record carries an estimated age range, and our models place some people in the 0-9 and 10-19 ranges. If you believe we have collected information from a child under 13, please contact us immediately.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of our services after such changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Protection Officer: For privacy-related inquiries, please contact our Data Protection Officer at support@trillboards.com
California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). You may request information about the personal information we collect, use, and disclose about you, and request deletion of your personal information.
Trillboards, Inc. is a "service provider" as defined under the CCPA (Cal. Civ. Code Section 1798.140(ag)) for the audience measurement it carries out for venue partners (the "business" under the CCPA). Trillboards also uses that data on its own account: it delivers audience measurement and location data to its data partners (Section 4.4), keeps it in an encrypted archive with no scheduled deletion, links observations of the same person and device across venue partners' screens, and combines it with device visit data received from a measurement partner. That delivery to data partners, and the data sent to demand-side platforms and ad exchanges in bid requests, are a sale and a sharing of personal information under the CCPA/CPRA.
As a California resident, you have the right to: (1) know what personal information we collect, use, and disclose; (2) request deletion of your personal information; (3) opt out of the sale or sharing of your personal information; (4) correct inaccurate personal information; (5) limit the use of sensitive personal information; and (6) not be discriminated against for exercising your privacy rights. To exercise these rights, contact us at privacy@trillboards.com or use the Do Not Sell page on our website.
GDPR Compliance
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR). You may request access, rectification, erasure, and portability of your personal data, and object to or restrict processing.