Alternate theory: someone at AA sold an email list to a shady marketer.
Art galleries are not typically considered sensitive topics.
Or, more legally, the advertisers could be part of a specific email retargeting campaign where they give us your email addresses, and then we can establish the mapping in a more direct way.
Obviously there must have been more shading goings on in this case, but the principle is the same.
Once you have the email addresses(see unshift's comment above) you upload them to Google and then target the addresses with specific ads.
1: http://blogs.msdn.com/b/oldnewthing/archive/2006/05/08/59235...
This helps solve the issue for advertisers using retargeting where cookies don't have a long shelf life. So they leverage 2nd party data sources to basically set those cookies again for them so they can continue retargeting.
They can also work with vendors to upload their hashed email lists from their CRMs and gain access to the relevant cookies in the pool to market to them.
Onboarding vendors like this tend to pay a CPM rate based on the number of matches they can make with their cookie pool, so really all that matters is that you have a massive number of people authenticating with email addresses.