How Procurement Teams Use MAID, POI and ACR Terms in RFPs and Contracts
A procurement term checklist links each data term in an RFP to one agreed definition and lists what the vendor must disclose and commit to. For identity, fix the keys, hash rules and a dated match rate formula. For location, name the geometry, visit rules and sensitive place exclusions. For licensing, tie permitted use and refresh timing to remedies.
Relationship disclosure: X-Mode and its successor Outlogic, InMarket, and Mobilewalla are referenced here as subjects of FTC consent orders finalized in 2024 and 2025. GSDSI has no supplier, partner, or reseller relationship with any of them.
How to use this article
Read the checklist here, then use the linked hub and product pages for procurement citations.
Procurement stalls when legal, engineering and finance read the same word three ways. A match rate in one vendor deck is a deterministic join yield, and in the next it is a modeled score. This page is a working checklist for putting identity, location and TV data terms into RFP questions and license clauses. It does not repeat the definitions. Each term links to its entry in the GSDSI data glossary, which is where the definitions live, so your RFP appendix can point at one stable source. The checklist covers teams licensing MAID feeds, POI geofencing and CTV/ACR data.
What a procurement term checklist is
A procurement term checklist is the RFP appendix that lists each data term the deal depends on, links it to one agreed definition, and says what the vendor must disclose and commit to for that term. Definitions answer what a word means. The checklist answers what you need in writing so the word cannot drift between the pilot and the renewal.
The stakes are not academic. The FTC order against X-Mode and Outlogic turned on how device-level location data was collected and sold, which is exactly the kind of detail a vague contract leaves open. Legal reviews permitted use against field names engineering already mapped, and finance models costs against metrics nobody defined. A shared checklist stops those three conversations from running in parallel.
Identity terms: what to ask and what to sign
Identity is where most rework starts, because the keys look simple and are not. Use these items in the RFP and carry the answers into the order form. IAB Tech Lab standards are the external reference many legal teams cite for identifier handling.
MAID. Ask for counts and recency split by platform (IDFA vs GAID), and require that zeroed or deleted IDs are removed before any count is quoted.
HEM and SHA-256 normalization. Write the hash algorithm and the exact normalization steps into the match test instructions, so a formatting mismatch is not read as a coverage gap.
Match rate. Put the formula in the pilot charter with a numerator, a denominator after suppressions, the vendor data date and the output grain (device, household or person).
Device graph and decay. Ask for first seen and last seen dates on every edge, and how often stale links are removed, not only added.
Shared IDs (UID2, RampID, ID5). List which ones the vendor can deliver or accept, since that decides where the audience can be activated.
Match rate clause template
Numerator: distinct seed IDs with at least one vendor attribute above the agreed confidence threshold.
Denominator: distinct seed IDs provided, after suppression and legal exclusions.
Window: the vendor data date used for the test, restated if the vendor rebuilds its graph.
Output grain: device, household or person, matching what production activation will use.
Location terms: geometry, visits and exclusions
Location contracts go wrong when nobody wrote down how a place is drawn or what counts as a visit. The location intelligence hub routes to global mobility specs if you need the product detail behind these items.
POI, POI polygon and centroid. State which geometry each use relies on. Visit counting and attribution should name polygons, and the RFP should ask for polygon coverage for your own brands.
Geofence and dwell time. Fix the fence type and the minimum and maximum dwell rules for the life of a test, because changing either changes the totals.
Foot traffic and visitation panel. Ask for panel size over time and how breaks in the history are flagged and restated.
Sensitive location. Require the exclusion list, its version in each delivery manifest, and a clause barring any attempt to rebuild visits to excluded places. The final FTC order against X-Mode and Outlogic is the reference most counsel start from.
Precise geolocation. Ask whether the feed contains location precise enough to fall under state definitions, which states it covers and what consent was collected. Virginia's definition is a common reference point.
TV terms: households, exposure and measurement
TV data carries an unstated assumption about the household in almost every metric. Pair these items with the CTV/ACR hub, and with clean room joins when outcomes live in a partner environment.
ACR. Ask how viewer opt-in is collected at TV setup, what content sources are recognized and how logs are tied to a device or household ID.
CTV. Write down how CTV IDs are linked to households and how often those links refresh, since a stale link sends exposure to the wrong home.
Reach and frequency. Reach counts households or devices with at least one exposure, and frequency counts exposures. Keep them as separate fields so pacing analysis does not mix them.
Data clean room. Name the minimum group size, who approves new queries and what may be exported.
Licensing terms: rights, refresh and delivery
The licensing vocabulary decides what you can actually do with the data after signature, so it belongs in the order form, not only in the RFP.
Permitted use. List every intended use and map each to a clause. Anything not listed is outside the license.
Refresh cadence. Make it a service level with a delivery window and a remedy for late files, and monitor it with the drift guide.
Delivery formats and Snowflake secure share. Settle format, channel, file naming and manifests during the pilot so production files load without new work.
Data dictionary. Require notice before any field changes meaning or is removed, with a set lead time for deprecations.
Attach the glossary as the definitions appendix and this checklist as the requirements appendix. Ask each vendor to map its field dictionary to the glossary terms and to answer every checklist item in writing. That one step cuts rework in legal review and speeds pilot acceptance. For bake-offs, add the vendor comparison checklist and the relevant GSDSI comparisons page for your category. Finance should see total cost defined to include integration and monitoring, not the license fee alone.
Engineering should not translate vendor field names on the fly during ingest. When one vendor's device_id is another's maid with different normalization, the mismatch hides until a report is wrong. With the mapping agreed up front, legal can tie each field to a permitted use without reopening the schema every week. When programs span cross-channel measurement, add exposure and outcome terms to the same appendix so CTV and store visit stakeholders argue from one vocabulary.
Experienced procurement leads keep a term dispute log: the phrases that caused rework, the resolved wording and the date. That log becomes appendix B on the next RFP and shortens legal review. It is most useful when vendors rename fields without changing their meaning, because it stops your warehouse from drifting away from the contract language. Share it with vendor account managers so renewal answers stay consistent, and review it every quarter even when no RFP is open.
When a vendor proposes new fields, ask for a short change note: what changed, whether the field is personal data and which permitted use applies. Tie those notes to drift monitoring tickets so procurement knows which change notice clause applies. Send updates to ad ops as well as analytics, since trafficking mistakes are often vocabulary mistakes.
New team members should read the glossary before joining vendor calls. A term misheard in negotiation can become a permanent contract definition, especially match rate, household and refresh cadence. Half an hour with the MAID Feed and CTV/ACR field names saves rework during ingest. If you want a scoped sample with field definitions, use contact and reference this checklist in your message. See AI search readiness for B2B data sites for why consistent field names also reduce mis-citations in AI generated diligence summaries.
Frequently Asked Questions
Is this checklist legal advice?
No. It is buyer education. Binding use restrictions live in your contract, the privacy policy and executed data processing agreements. Have counsel turn resolved terms into permitted use clauses.
Why link to the glossary instead of defining terms in the RFP?
One definition in one place stops drift. When the RFP, the pilot charter and the contract all point at the same glossary entry, a vendor cannot answer a different question than the one you asked.
Why define match rate in writing?
Without a defined seed, cohort and date, vendors can quote headline figures that do not predict production performance. Put the formula and the acceptance band in the pilot charter before files move. See match rate.
Are MAID and IDFA the same thing?
IDFA is the iOS form of a MAID, and GAID is the Android form. The difference that matters in a contract is that the IDFA is opt-in. See IDFA vs GAID and ask for counts split by platform.
Does a clean room guarantee privacy compliance?
No. It governs how joins run. Consent, exclusions, retention and permitted use still need to be documented outside the clean room and tested on your use case. See data clean room.
✓ Opt-Out Request Honored via Global Privacy Control
We use cookies and similar technologies to improve your experience. No marketing cookies are pre-selected. Learn more in our Privacy Policy. Your Privacy Choices.