What is the ad-privacy cookie?
This cookie is used by Amazon Advertising to store and manage the user's privacy preferences and consent choices regarding interest-based advertising delivery.
Table of Contents
About ad-privacy
| Vendor | Amazon |
|---|---|
| Cookie Domain | amazon-adsystem.com |
| Category Category The functional category of the technology, such as Web Analytics or Social Media. Learn more | Advertising & Paid Media |
| Consent Category Consent Category The consent category this cookie most commonly falls under across sites we scan, normalized into four standard categories. Learn more | Targeting & Advertising |
| Prevalence | Very Common |
| Popularity Popularity Popularity is calculated from our dataset of 4.5B+ cookies analyzed across hundreds of millions of web pages. Learn more | Found on 14.2% of scanned pages |
| Expiration Type | Timestamp |
| Expiration Duration | 29 days |
| Party Type Party Type Whether the cookie is first-party or third-party. Learn more | 3rd-Party |
| Risk Level Risk Level Rates how sensitive the data stored by this cookie is (High, Medium, or Low) based on data classification and distribution. Learn more | Low |
| Vendor Privacy Policy | https://advertising.amazon.com/legal/privacy-notice |
| Vendor Website | https://www.amazon.com |
What is the purpose of ad-privacy?
The ad-privacy cookie is a persistent utility cookie deployed by the Amazon Advertising platform via the amazon-adsystem.com network layer. It exists strictly to store and transmit a user's local privacy preferences and programmatic consent choices - such as opt-out status for interest-based targeting or structural compliance flags required by regional privacy regulations like GDPR, CCPA/CPRA, and GPC signals. By executing at the network boundary, it ensures that Amazon's ad-serving infrastructure dynamically honors the user's data-sharing choices prior to rendering or optimizing any behavioral advertisements.
The cookie carries a minimal, highly concentrated payload consisting of an encrypted or single-digit binary compliance flag (such as the observed '0' parameter). This payload serves as an immutable network directive indicating whether tracking is permitted, blocked, or heavily restricted. It does not contain any persistent user profiling matrices, track behavioral web browsing history, or accumulate personal identity records, functioning purely as a structural gateway for consent state verification.
What are the Privacy Risks of ad-privacy?
Risk Level: Low
The Low risk level is assigned with 100% certainty because the ad-privacy cookie functions strictly as a technical compliance flag to store and execute user privacy choices, rather than an active user tracking mechanism. According to Amazon Advertising's official documentation, this cookie exists to register localized compliance signals, such as an opt-out status for interest-based advertising or regional privacy flags (GDPR/CCPA/GPC). It does not collect behavioral patterns, profile browsing history, or transmit cross-site marketing identifiers, which isolates it completely from the Medium risk tier.
This functional scope is verified by the telemetry data, which demonstrates that 100% of the recorded cookie payloads consist of a static, single-character binary value ('0'). Because this parameter represents a global structural state (such as tracking restricted or opt-out recorded) rather than a unique pseudonymous tracking token or a behavioral profile ID, it does not possess the technical capability to target or track individual users across the web. Consequently, it aligns perfectly with the criteria for Low risk, serving a role structurally equivalent to a site functionality preference or a CSRF token.
How to Remove ad-privacy from a Website
To remove the ad-privacy cookie from a website, the website administrator or technical operator must completely remove the Amazon Advertising deployment scripts, marketing pixels, or container tags from the site's source code or Tag Management System (such as Google Tag Manager or Adobe Launch). Because this cookie is an inseparable component of the core Amazon Advertising (amazon-adsystem.com) script used to register and execute compliance checks for ad serving, the identifier cannot be decoupled or disabled independently through account-level configuration settings while leaving the pixel active. Removing the vendor's tracking tags entirely from all web pages is the only administrative action that will stop the service from deploying this cookie.