All Vendors
advertising
Bidvertiser

Bidvertiser

BidVertiser openly admits to browser fingerprinting for "unique user delivery" on its homepage while operating undisclosed identity resolution vendors Contactout and Firmable — an ad network that fingerprints users by design.

100 IOCs33 detections36% pre-consent31 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Bidvertiser discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

33 detections across 31 sites36% pre-consent activity1 critical disclosure gap
CRITICAL

Fingerprinting Disclosure

Homepage explicitly states: Unique user delivery guaranteed by our accurate fingerprinting

GDPR Art 5(1)(a)ePrivacy Directive
HIGH

Pre-Consent Activity

Bidvertiser was observed loading and executing before user consent was obtained on 36% of sites where it was detected.

GDPRePrivacy
HIGH

Pre-Consent Tracking

35.5% of detections occur pre-consent

GDPR Art 6GDPR Art 7
HIGH

Undisclosed Vendors

10+ vendors detected on their own site including identity resolution services

GDPR Art 28GDPR Art 30
HIGH

Undisclosed Party

Not in privacy policy

Disclosure Gaps

Claims vs. Observed Behavior

4 gaps
1 CRIT2 HIGH1 MED
Classified:BTI-X01BTI-X02BTI-X05

Fingerprinting Disclosure

GDPR Art 5(1)(a) · ePrivacy DirectiveCRITICAL
They Claim

GDPR compliance claimed in privacy policy

Observed Behavior

Homepage explicitly states: Unique user delivery guaranteed by our accurate fingerprinting

Homepage text at bidvertiser.com under In-House Technology section

Undisclosed Vendors

GDPR Art 28 · GDPR Art 30HIGH
They Claim

Privacy policy lists 3 subprocessors (Google Analytics, PayPal, Braintree)

Observed Behavior

10+ vendors detected on their own site including identity resolution services

Runtime scan of bidvertiser.com showing Contactout, Firmable, TrenDemon, multiple Google services

DNT Non-Compliance

CCPA 1798.185(a)(6)MEDIUM
They Claim

None - explicitly states DNT not honored

Observed Behavior

Consistent with claim but increases regulatory risk

Privacy policy states: We do not support Do Not Track

Customer Impact

What This Means For You

YOUR publisher inventory served through BidVertiser includes browser fingerprinting that YOUR users cannot opt out of through standard cookie controls. YOUR visitors are fingerprinted for "unique user delivery" — a tracking method that persists across cookie deletion and private browsing. YOUR regulatory exposure is heightened because fingerprinting requires explicit consent under ePrivacy Directive Article 5(3), yet BidVertiser's undisclosed identity resolution vendors Contactout and Firmable further compromise YOUR consent framework. YOUR privacy policy cannot accurately disclose data flows when BidVertiser's own subprocessor list names only Cloudflare.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Bidvertiser

  • Audit your consent flow to ensure BidVertiser code loads only after valid explicit consent including fingerprinting disclosure
  • Update your privacy policy to disclose BidVertiser, browser fingerprinting, and their undisclosed subprocessors
  • Request their current subprocessor list — privacy policy only names Cloudflare
  • Assess whether browser fingerprinting aligns with your compliance posture under ePrivacy Directive

If You're Evaluating Bidvertiser

  • Assess whether admitted browser fingerprinting is compatible with your privacy standards
  • Request complete subprocessor list beyond Cloudflare before any engagement
  • Compare with ad networks that do not use fingerprinting or invasive ad formats
  • Require contractual prohibition on fingerprinting YOUR visitors without explicit consent disclosure

Negotiation Leverage

  • Admitted fingerprinting: BidVertiser homepage states unique user delivery via fingerprinting — use this self-admission to negotiate consent requirements or termination rights under ePrivacy Directive
  • Identity resolution undisclosed: Contactout and Firmable detected but not in privacy policy — require named vendor disclosure and DPA coverage for all detected vendors
  • Single subprocessor: Only Cloudflare listed while multiple vendors detected — require complete subprocessor list as a contract condition
  • Pop-under ad formats: Invasive formats combined with fingerprinting create compounded regulatory risk — negotiate format restrictions and enhanced consent requirements
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C10Fingerprinting

Device identification

IOC Manifest

IOC Manifest

96 INDICATORS

Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.bidvertiser.com/wp-content/plugins/handl-utm-grabber/js/handl-utm-grabber.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/plugins/siteorigin-panels/js/styling.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/plugins/tf-numbers-number-counter-animaton/assets/js/tf_numbers.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/plugins/handl-utm-grabber/js/js.cookie.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/plugins/inbound-feature-pack//js/featherlight-pack.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/classie.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/salvattore.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/jquery.pagescroll2id.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/jquery.smartmenus.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/inbound.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/jquery.flexslider-min.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/animated-header.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/sticky.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/imagesloaded.pkgd.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/wow.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/skrollr.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/jquery.placeholder.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-content/themes/inbound/js/jquery.waypoints.js*
Tracking script
TRACK
*www.bidvertiser.com/wp-includes/js/wp-emoji-release.js*
Tracking script
TRACK
www.bidvertiser.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/plugins/siteorigin-panels/js/styling.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/plugins/handl-utm-grabber/js/js.cookie.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/plugins/handl-utm-grabber/js/handl-utm-grabber.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/plugins/tf-numbers-number-counter-animaton/assets/js/tf_numbers.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/plugins/inbound-feature-pack//js/featherlight-pack.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/jquery.pagescroll2id.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/classie.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/animated-header.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/jquery.smartmenus.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/jquery.flexslider-min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/salvattore.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/imagesloaded.pkgd.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/jquery.placeholder.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/jquery.waypoints.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/sticky.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/skrollr.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/wow.min.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-content/themes/inbound/js/inbound.js
Auto-extracted from scan
TRACK
www.bidvertiser.com/wp-includes/js/wp-emoji-release.min.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

BidVertiser operates as a self-serve advertising platform connecting advertisers with publishers across desktop and mobile. Common load method is indirect (via tag managers or ad containers). They are detected on 30 distinct sites in the database with an average 35.5% pre-consent rate. On their own website, they load identity resolution vendors (Contactout, Firmable), multiple Google advertising products, and TrenDemon. Their ecosystem position is as a demand-side platform (DSP) and ad network that aggregates publisher inventory for advertiser campaigns. Publishers embed their code to monetize traffic; advertisers use their platform to target users across the publisher network.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

100 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details