Security & privacy

Buying signal, without the personal data.

Most visitor-identification tools de-anonymize individuals. Backstory identifies the account — the organization, never the person who visited — from first-party signals, with no cookies and no PII. Reaching the buying committee is a separate, opt-in step you control.

first-party · company-level · no PII to identify · cookieless

Two layers, one honest line

No PII to identify the account — opt-in, DPA-governed data for the people

Layer 1 · Always on

Account identification — no PII

Backstory resolves your anonymous traffic to the organization behind it, from first-party signals only. Company-level: the account, never the individual who visited.

  • First-party — your own site traffic, nothing bought from across the web.
  • No PII to identify the account — the visitor’s IP is enriched to a company domain, then discarded.
  • Cookieless — nothing for visitors to accept, nothing for you to manage.
  • Never de-anonymize the individual who visited.
Layer 2 · Opt-in

Lead identification — DPA-governed

When an account is worth a conversation, you can reach the buying committee there — the decision-makers matched to your target roles. This step deliberately surfaces business-contact details — so it is opt-in and governed by a data-processing agreement.

  • Opt-in — off by default; you choose when to involve personal data.
  • Gated behind the Leads data-processing agreement (DPA), with opt-out honored.
  • Business-contact details (name, title, LinkedIn, verified work email) from a business-contact provider — matched by your target roles and locations.
  • Credit-metered, pay-as-you-go — never derived from the individual who browsed.
What we collect — and what we never do

An auditable data ledger

At the account layer, here is exactly what Backstory does and does not touch.

What we collect

  • The first-party network signal of each visit — resolved to the organization, then the IP is discarded.
  • The pages viewed on your own site — to score buying intent and read interests.
  • Up to 60+ firmographic fields about the identified enterprise account.

What we never collect

  • No cookies, no consent banner, no device fingerprinting.
  • No PII to identify the account — no named individual, ever, at this layer.
  • Never de-anonymize the individual who visited your site.
  • No third-party intent data bought from across the web.
How identification works

The account, then the IP is gone

Identifying the account never de-anonymizes a person. The visitor’s IP is used to resolve the organization, then discarded.

  1. Anonymous visit
  2. Resolved to the organization
  3. Enriched to a company domain
  4. The IP is discarded
FAQ

Questions security & privacy teams ask

Do you store personal data?
To identify the account, no — Backstory resolves each visit to the organization, never a named individual; the visitor’s IP is enriched to a company domain and then discarded, and there are no cookies. Lead identification is separate and deliberate: when you opt in, it provides the decision-makers’ business-contact details for an account you choose, DPA-governed and credit-metered. So there is no PII to identify the account, and personal business-contact data only under a data-processing agreement you accept.
Do you use cookies or track individual visitors?
No. Account identification is cookieless and company-level — there is nothing for your visitors to accept and no tracking of the individual who browsed. Backstory identifies the organization, not the person.
How is this different from third-party intent or visitor-tracking tools?
Third-party tools infer intent from activity across the web and hand you person-level data on the individual visitor. Backstory scores what accounts did on your own site — first-party and company-level — and only surfaces the people to reach as a separate, opt-in step. Different signal, and you never track the individual visitor.

See the accounts, not the individuals.

Identify the enterprise accounts on your site — company-level, cookieless, no PII to identify the account.