I have spent a lot of time deep in ad tech and a ton of time specifically thinking about identity resolution for ads - i have never seen a DSP make a conscious effort to do "target every cookie that belongs to a specific IP address" as a default rule (or even an option) but I see DSPs automatically opting in to the Liveramp cross device map - is this what causes this behaviour? I am even skeptical that Liveramp can robustly provide this data at scale and fast enough, so I wonder if its almost alway coincidence?
That shouldn't work if the GP uses a VPN, as theg'd have a perceivably different IP address.
More likely they are logged into youtube, and their account has been associated with their girlfriend's account (location data from gmail/android phones/maps/etc, probably not using the VPN 24/7, etc)
Even better, thanks to criteo's bluetooth beacon service, if you go to pick up your pizza, they will know you bought it and can present you with further ads from that specific pizza chain.
If you think Criteo isn't doing that, you should check out their marketing material.
Typically on a busy train or plane