Keep Your Gifts and Your Data Under Wraps this Holiday Season

Santa Claus holding a red sack full of presents, pressing his index finger to his lips as if to say "shh"Have you ever searched for an item online and then had advertisements for that same item show up on your phone, tablet, or another computer later? How about ads for that item showing up on someone else’s device in your home? Many of us share devices with some of the same people we are looking to surprise with the perfect holiday gift. An unexpected ad seen by the wrong person – think engagement ring or spontaneous getaway – can ruin a holiday surprise.

Online advertising has gotten so good some people think that our phones are listening to us (we are pretty sure they are not). However, most websites and apps today do contain technologies that track what visitors are reading and viewing, including across other websites and apps, in order to serve more targeted ads.

Many technologies make connections between your phone, computer, and tablet, in order to show you ads across devices. For example, if devices are logged into the same apps, or if they are connected to the same Wi-Fi network, or are usually located in the same places (through sharing location with apps or services), they might be associated with the same person.

Here are 12 tips to keep your gift ideas a secret and your online shopping secure this year:


Keep it Secret…Keep it Safe!

1.  Look for “HTTPS” when shopping

Close-up of a computer screen focused on the padlock icon and the https part of the address barNever enter passwords, payment, or other personal information into a website that does not start with HTTPS.  The extra “S” at the end of “HTTP” stands for “secure” and means that your computer is protecting the data you send from getting intercepted and read by others. Many browsers now alert you when a site is not secure. Always verify that you are shopping on reputable sites and with retailers that you trust.


2.  Update your devices and software

Security is a moving target, and systems need to be updated frequently.  While it may be annoying to constantly receive alerts that a software update is available, it’s in your best interest to keep your software up to date. Otherwise, you’re leaving yourself exposed, which may make you an easier target for cybercrime.


3.  A word on passwords

You don’t need to change your passwords constantly, but it’s a good idea to make sure your password is unique and as memorable and complex as possible.  Avoid re-using the same password, especially for financial or other sensitive accounts. The longer you can make your password, the more secure it is. Try taking a memorable phrase and replacing some of the letters with numbers and characters (like “M3rryChr1$tm@$!”). If that all seems overwhelming, consider using a password manager (here’s a list of top password managers for 2018 from CNET). For extra security, use two factor authentication to Lock Down Your Login.


Santa Doesn’t Leave Cookies

A hand holding a smartphone; the screen has a shopping cart with a "3" icon on it. Buttons underneath read "View my items" and "Checkout"4.  Clean out your cart

Have you ever added a product to your shopping cart on a website, but never completed the purchase?  Sites will often remember these (using cookies), hoping that the next time you visit the website you’ll see it again and decide to finish the purchase.  It can be a helpful feature, but if you share a computer, it could spoil a surprise. Avoid this by deleting items from your shopping cart. Clearing cookies can also help empty the cart. More on cookies below.

5.  Manage your shopping history

In addition to saving your shopping cart, many popular shopping sites like Amazon remember items you have viewed.  It can make it easier for you to find something you looked at a while ago, but didn’t decide to buy yet. However, the next person visiting the site might see the gifts you are considering on the recently viewed list.

On Amazon, you can manage this by selecting “Browsing History,” then clicking “Manage History.”  From there, you can either clear your browsing history entirely, remove specific items, or turn it off for a period of time (like when you want to hide your gift ideas)

Close-up of a hand holding a pencil eraser, which is pointed at the words "Clear history," "Clear cookies," and "Clear cache" on a computer screen6.  Clear your cookies

Deleting cookies periodically is an easy way to clean up your browsing history.

Cookies are small pieces of data stored on your computer that help streamline your internet browsing experience.  For example, they will track what items you have added to your online shopping cart, record what links you have already clicked, or remember form data (like name and address) you have entered on a site previously.  All web browsers offer you the ability to delete cookies. Click here for instructions on how to clear cookies on different platforms.


Santa’s Little Helpers

7.  Use a dedicated search engine and browser for shopping

DuckDuckGo is a privacy-focused search engine that does not track IP addresses, store user information, or profile its users. It uses cookies minimally. It does keep a log of search terms used on the site, but it does not collect or share any personal information.

For enhanced privacy, you can also use a designated “private” browser, such as Firefox Focus or Brave.  These are separate browsers, available on multiple platforms, which you can use when you want to browse with enhanced privacy settings.  

Both can help keep your gifts a secret.

Overhead shot of Santa holding a tablet, which reads "Making a list, checking it twice..." with a candy-cane striped loading bar8.  Review your social media and other online ad settings

Before you start shopping, log out of your social media and other online accounts; this may help keep your gift ideas from showing up in ads targeted to your shared household devices – ads that might spoil the surprise.

The two largest online advertising platforms, Google and Facebook, provide consumers with the ability to review and adjust online ad settings. You may want to temporarily turn off personalized ads until after the Holidays.

The Digital Advertising Alliance (DAA) and Network Advertising Initiative (NAI) are two trade groups for online advertisers.  Internet advertisers collect data about users to target them with ads that align with their interests. Both of these trade organizations offer consumers the ability to opt-out of targeted ads. You will still see ads, they just may not be as personalized to you. This might be a good option before you start your holiday shopping.  The DAA tool can be accessed here and the NAI tool can be accessed here.  Keep in mind the opt-out is tracked through the use of digital “cookies.” Clearing your cookies will void your opt-out, so clear your cookies first.

9.  Rein in your phone’s privacy and ad settings

Adjusting the privacy and location settings on your device can limit what you’re sharing, whether you’re actively using your device or not. iOS, Android, and Windows devices use a unique identification number (Ad ID) to communicate your identity to the apps you use, enabling better-targeted advertising through those apps.  In each operating system you can disable or reset the number to limit tracking. You can do this within the settings of your device, either under “privacy” or “ads.” On some platforms it can be turned off completely. If you don’t mind targeted ads but want to avoid being targeted with ads related to holiday gift shopping you’ve done recently, reset the Ad ID after shopping.  Click here for instructions on how to adjust your privacy settings and turn off or reset your Ad ID on different platforms.

10.  Browser plugins

A number of browser extensions (or plugins) are designed to block online tracking and provide you with more privacy while surfing the web. If you use Chrome, Firefox, Opera, or Firefox for Android, you can download the Privacy Badger extension, which blocks ads and tracking cookies.  Ghostery is another popular option available as a plugin for desktop browsers or as a standalone browser for mobile devices. Google offers the IBA Opt-out extension for Chrome. Other browsers also have plug-ins that serve a similar function.  Just make sure before you install a browser plugin or extension that you are using one that is known, well-reviewed, and trusted.


Not-so-Secret Santas

11.  “Private Browsing” and Do Not Track

Before relying on “private browsing” or “incognito mode” it is important to understand what those settings do and don’t do. These settings do not prevent websites or your internet service provider from seeing what sites you visit.  They do not protect you from viruses.  They don’t necessarily stop your search history from being tracked, as some search engines save these, even if your computer doesn’t. Enabling these browser modes will limit how much information your computer saves when you visit websites and can function to limit what your computer shows in subsequent browsing sessions. Many people get a false sense of security by thinking it enables truly anonymous browsing.

“Do Not Track (DNT)” is a setting you can enable on your web browser, instructing the sites you visit that you do not wish to be tracked.  Unfortunately, it is not legally binding and most websites simply ignore the request.


The Best Hiding Places

A man's hands holding a tablet, which has on its screen a green shield with the letters "VPN"12.  For the diehards, use a VPN

A VPN, or “Virtual Private Network,” is a privacy tool that is growing in popularity.  A VPN encrypts all your internet traffic and channels it through a designated server. VPNs are useful when you’re using public Wi-Fi or don’t want your internet service provider to get too many details about your online activities, since a VPN encrypts your internet traffic and makes it appear like your traffic comes from your VPN’s server. (This can also make it harder for online services to know your precise location.)  Keep in mind that one party still has access to what you are doing on the internet — the VPN service itself. Do your homework and choose a VPN that can protect your data and will commit to not selling information about you to advertisers and other third parties. Learn more about choosing a VPN here.


Bonus:  A stocking stuffer for those gifts you just can’t find online

Don’t give out your email address!
– Many brick and mortar retailers ask you for your email address and/or phone number when you check out.  You don’t need to provide either. Providing a retailer with your email may seem convenient for getting an electronic receipt, but beware you may also be opting in to receive offers and other solicitations. Many times, they will distribute the email addresses and phone numbers they have on file to data brokers who will use it for marketing purposes.


Here’s how to clear your browser cookies:

  • For Chrome, select “Clear Browsing Data” under the “Chrome” menu.
  • For Firefox, click the menu icon and select “Preferences,” then “Privacy & Security.”  From there, you can enable or disable cookies, clear cookies and other browsing data, or set how frequently that data is periodically cleared.
  • For Internet Explorer, open “Internet Options” from your Control Panels menu and manage browser history there.
  • For Safari, select “Clear History” under “History.”


Here’s how to adjust your device’s privacy settings, including Ad ID:

  • On Android devices, select “Settings” and then “Google,” or just select “Google Settings” (the pathway depends on the device).  From there, you can select “Security & Location” to turn off your location settings.
    • To change your Ad ID settings, select “Ads.”  From there, you can either select “Opt out of interest based ads” to turn off your Ad ID, or alternatively select “Reset advertising ID” to reset it.
  • On iOS, under “Settings,” select the browser you use.  From there, you can adjust location services and manage privacy settings for each app for your web surfing.  
    • To adjust your advertising settings, from the “Privacy” menu, select “Advertising,” then set “Limit Ad Tracking” to “On” to turn off the Ad ID.  To reset the Ad ID while leaving it on, from “Privacy” select “Advertising,” then “Reset Advertising Identifier.”
  • On Windows devices, go to the “Start” menu, then select “Settings,” then “Privacy” to modify privacy settings.  
    • To modify Ad ID settings, from “Privacy” select “General.” You can turn the Ad ID off from there.  Turning it back on will reset the Ad ID.