Skip to content

Comment on Brands Are Wasting Money on Facebook and Twitter, Forrester Says

Comments

We were successfully running retargeting ads on Facebook by uploading our customers email addresses. We were getting lots of conversions cheaply. Initially CPM was $1.70, then a few months later it was $4, now 6 months later it's $9. At this point it became unviable.

I spoke to our account manager at Facebook and he confirmed my suspicions. Every time one of our customers converts though our ads, Facebook assigns a high value to that user, since that user purchased something through a FB ad. So now I have more competition to get in front of our existing customer from our competition who our customer is not interested in. FUCK THAT. Moral of the story DO NOT tell Facebook about conversions from your existing customers. Keep that info to yourself.

Maybe also don't leak your customers email addresses to FB at all.

Here is a catch 22. In a sufficiently competitive environment, "it's profitable to do X" quickly becomes "It's essential to do X."

Here is a contrived example that doesn't reflect reality:

There are 10 banks in a market. The banks have a range of new online services. Adoption of as many of these services as possible is the key to success. A viable strategy is to retarget customers (segmented by income/family status and other things that make certain services relevant) and tell them about various services. This increases the adoption of value add services substantially.

If one bank takes a moral stance, they either need to live with lower adoption of their services or spend more via less effective advertising channels.

If Facebook advertising is good enough, that one bank would go out of business, have its management replaced by shareholders or get bought out by one of the others.

This probably doesn't apply to banks, but there are businesses where effective online advertising is the difference between success and failure. All the tourist/hotel/flight booking sites, for example.

In that scenario, not violating your users' privacy would become a differentiator for your product, something you could market. Ever noticed how much advertising in highly competitive businesses seem to hinge on ever more strained explanations of how one product is different from the other?

Except, of course (and this is probably the ugly truth) - as long as Facebook doesn't do creepy/embarrassing things or otherwise actively annoy their customers, the vast, vast majority of customers just doesn't care. And then there isn't really a problem.

Privacy is very much a market for lemons. Lets take two scenarios and see which is more profitable.

1. Respect privacy.

2. Carefully mislead the customer to believe the company respects user privacy in a way their fuzzy morals tell them isn't a "lie," bury the truth in the fine print. Lose the handful of customers both technically savvy, principled and capable enough to not use the product while profiting from abusing the privacy of their users.

Your second paragraph explains it. As long as companies are sufficiently non-creepy in their privacy invasion (or at least APPEAR to be such), then the only people who will care are cypherpunks and privacy nerds, who don't form a large part of the market. The "masses" usually go for the latest shiny toy.

You can re-target users on various ad networks without using their e-mail addresses.

You're not allowed to break my facetious example by adding your own facetious information! :)

This is true in some cases, false in others. If you have 8 years worth of emails, that's what you have. If you want to segment your data based on info in your DB (people with & without a mortgage), you will probably need to use emails.

In any case, you are still leaking data. FB now know that your customer is John Lennon.

The email in this case is somewhat trivial. It serves as a userID. If you are super concerned with giving away an email, there are services like LiveRamp that can translate that into an anonymous audience ID for use with your DMP and/or DSP so you target the ID without handing over the email.

Yes, if I was a customer I'd be a bit miffed if a supplier sent my email address to Facebook.

yeah wtf is going on here: a company is bulk uploading all customer e-mail addresses to facebook?

To you and the others: yes you can. You can also upload phone #s. They are hashed.

You're still letting FB know that its existing users are your customers, which breaches your customer's privacy. Imagine that Ashley Madison did that!

In case anybody else has no idea what Ashley Madison is: it's an online dating service that seems to be focussed on people who are already in a relationship and cheat on their partners. Or something like that.

I agree that the privacy violation is bad as it is, but I don't see how this is a good example for why it's bad.

Well... I imagine that you wouldn't want random advertisers and FB employees knowing that you're interested in cheating on your spouse.

They are hashed

So what if they are hashed? Facebook has the solution to all the hashes.

One could give away a unique e-mail address to every web site. Quite a hassle though.

I've been doing it for years without problem, it's a lot easier than you'd first think. Markov chain makes the leader of the email address, domain is selected from a random pool.

Are those your own domains?

For things I care about the domains are owned by me, for things I consider spammy I have a round robin of afraid.org aliases which are for all intents and purposes disposable. They are very effective for this sort of thing, but you would be wise to do your research into the history of the domain you're piggybacking to be sure it's not going to disappear.

if you use a gmail account, you can use a + after yourusername

So cpach@gmail.com and cpach+hackernews@gmail.com would both end up in the same inbox, then you can use gmail filters to separate them

This trick only works because it's not that popular. If a substantial amount of people started doing it, firms would simply start removing the extra +info that you pad to your address.

Good point. But I doubt any significant share of users will consider doing it. Most of them are of course unaware that it’s even possible.

Perhaps someone here has some statistics to share? It would be interesting to know how common this trick is :)

[Edit: Better wording]

This could potentially be solved by using alias emails instead of just adding a tag to your normal e-mail address. I can imagine gmail offering a quick "generate alias" button that creates a EkTG522f3fhgtfh@gmail.com address that instantly forwards to your real address. Obviously you can delete this alias if you find that you are being spammed.

Regrettably a significant number of back ends (principally Microsoft ones in my experience) regard the +bit as malformed and reject the email address.

Actually yes, I remember now that's why I use - in my Postfix instead.

Postfix allows you to choose any character as a separator.

Yep. But it can be circumvented if one’s mail server use another delimiter. E.g. ”.” will hardly be filtered.

You set up a catch-all on your domain, and just make up whatever@domain.tld whenever you need an address. I have all my domains set up that way. Not even for unique addresses, just for convenience.

I have exim set up to accept all mail to my domain that starts with a particular prefix. So I sign up to websites as myprefix-sitename@mydomain.com.

Setting it up was a bit of a fiddle because I suck at exim, but it's no ongoing hassle.

I am stating facts. Opinions and deductions are yours to make.

FYI - This is the privacy policy for it: https://www.facebook.com/ads/manage/customaudiences/tos.php

"Facebook’s custom audience feature enables you to create an audience using your data such as email addresses and phone numbers. When using Facebook’s custom audience feature, your data is locally hashed on your system before you upload and pass such data to Facebook to be used to create your custom audience (the “Hashed Data”)."

This practice is very common. I'm not saying I agree with it but you should expect that every service you signup with to do this. As the company retargeting you do not know anything extra about your customers. The retargeting audience is a black box. It's Facebook you have to worry about. My suggestion is to have a different email for Facebook than everything else.

It's also companies leaking your address to any third party like crazy we have to worry. Seriously, WTF.

How were you telling Facebook about your conversions?

Facebook Conversion Pixel

Thanks for this. I have to say that it is rather short sighted for Facebook to be using this data to cut the legs off their advertisers. This sort of activity is really going to poison their platform.

It's not malicious. FB have been trying everything frantically to make their super-complicated ad platform work since the IPO.

They use all sorts of (rapidly changing) black boxes to figure out what ads to show to who. Second order effects spring up. They are trying to profile users in various ways so that ads with a particular goal (clicking off-page ads, interacting with advertiser content, "conversions," etc.) are shown to users with a propensity to do those things. This increases competitiveness for customers with a propensity to do in demand things.

Good call.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.