
About this series: The market has taken a lot on faith about LiveRamp's onboarding solution, from what it passes through to what it delivers. In this two-part series, we're testing those assumptions and unpacking what they actually mean for performance, privacy, and control.
In part 1 of this series, we found that LiveRamp drops first-party data leading to lower match rates and performance. In some cases, the problem is so egregious that audiences activated through LiveRamp produce lower match rates than sending first-party data alone.
But even customers who'd seen the performance problems firsthand told us, begrudgingly, they were stuck with LiveRamp. Their privacy and legal teams trusted only a solution like RampID, one that promises to keep raw or hashed PII out of the ad platforms altogether.
In fact, some privacy and legal teams have all but restricted activation from happening through any method that is not LiveRamp. That restriction is often the reason marketing and data teams don't push back even when they can see the performance and operational costs of staying with LiveRamp.
So we looked at what's actually being sent when LiveRamp onboards audiences to ad platforms. To our surprise, their privacy promise doesn't hold up.
What buyers believe versus what’s actually being sent
Ask most data or privacy leads what happens when they activate through RampID, and you'll get some version of the same answer: their PII gets converted into a pseudonymous ID, and that ID, not the underlying PII, is what reaches Meta, Google, and the rest of the ecosystem.

That understanding is wrong. According to LiveRamp's own documentation, most of the ecosystem never activates on RampID.
Of the 20 ad platforms LiveRamp compares in this table, 8 of them don't ingest RampID at all, including Meta, X, Snapchat, Pinterest, LinkedIn, and Google Customer Match. Google DV360 and Ad Manager only accept RampID for open web display inventory, not for Search or YouTube where the large majority of Google’s ad spend actually runs. So in reality, these 10 destinations receive identifiers that they already know how to match, including hashed PII. And combined, they account for more than 50% of US digital ad spend.1
Put plainly, on the large majority of every ad dollar spent in the US, RampID is not what makes it downstream to ad platforms
The other 10 ad platforms compared in that same table accept RampID in some form, but not as the only identifier. The Trade Desk, Amazon, and TikTok are in this category. They ingest RampID alongside other identifiers, like cookies and mobile device IDs. In fact, we couldn't find a single publicly documented destination, in LiveRamp's own materials or anywhere else, where RampID is the only ID sent to the platform.

The costs of the illusion
Privacy and legal teams are under the impression that LiveRamp protects them from sharing PII with most ad platforms, facing two significant risks.
First, it is untrue. LiveRamp does not universally restrict the activation of PII. Believing this can lead to overly restrictive policies or overlooking important privacy safeguards on the assumption that PII is not shared.
Second, policies that show preference for LiveRamp may be limiting the business's ability to modernize, reduce costs, and grow. Specifically, we’ve seen major enterprises accept worse outcomes under the guise of privacy, including:
Worse performance. As we explored in part 1, LiveRamp's onboarding process replaces your first-party records that match to their graph with RampID. Records that don't resolve to a RampID get dropped, which puts a hard ceiling on your match rates before the campaign even launches.
Higher costs. Once a team believes RampID is the only privacy-safe way to activate their data, LiveRamp doesn't have to compete for that renewal, and can continuously raise their prices without improving the product.
Vendor lock-in. Teams accept worse performance and rising costs year after year because they believe RampID is the privacy-safe path, and that belief is what keeps them locked in. Once the privacy promise turns out not to hold up either, there's no longer a good reason to keep paying for it.
A better way to protect your customer data
If PII ends up moving through the ecosystem either way, the real question is how you ensure every datapoint shared is secure, compliant, and protected from outside exposure.

That’s why, when we built Match Booster, we chose to focus on privacy and governance tooling first instead of minting our own proprietary ID.
With Match Booster, first-party identifiers activate directly from your warehouse, so there's no PII retained in a separate system and no new processor added to your data map along the way. Consent and opt-out status live in your warehouse as the single source of truth, and Hightouch keeps consent up-to-date across every destination automatically, so a change in consent is honored without risk of human error or of an intermediary system failing to process it. Destination-level filters let your team decide exactly what leaves your warehouse and where it's allowed to go, and built-in observability and access controls mean your privacy team can audit and govern what's actually happening.
If you, or your privacy team, want to learn more about how to onboard data while reducing privacy risk, schedule a call with a product specialist.
Footnotes
-
Methodology: We totaled 2026 US ad revenue for the eight destinations that don't ingest RampID (Meta, X, Snapchat, Pinterest, LinkedIn, Google Customer Match, Nexxen, Nextdoor), plus Google Search and YouTube, since RampID-accepting Google destinations are limited to non-Google-owned properties per LiveRamp's own documentation. We compared that total against 2026 US digital ad spend forecasts of $410-450 billion. ↩

















