Server-Side Conversion Tracking (Meta CAPI & TikTok Events API): SHA-256 PII Hashing Explained
Field-by-field PII normalization, SHA-256 cryptographic hashing, event deduplication, and data retention rules for Meta Conversions API and TikTok Events API.
By Salfars Security Team · Privacy & Data Engineering · Published
Summary & Direct Answer
Server-side conversion tracking complements browser pixels by sending permitted events from your server. Follow each provider’s field-specific normalization and hashing rules, preserve event identifiers for deduplication, and validate event receipt before using the data to make bidding decisions.
Methodology: This is an implementation checklist, not a certification of a deployed tracking pipeline. Field requirements differ by provider; consult the linked documentation and validate sample events in the provider diagnostics tools.
Why Browser-Only Tracking Fails Modern E-Commerce
Relying solely on client-side JavaScript pixels (such as fbevents.js) creates severe signal loss. Modern browser protections (Safari ITP, Firefox ETP, ad blockers, and mobile privacy toggles) frequently block client-side network calls or truncate cookies to 24 hours.
Server-side conversion tracking solves this by dispatching purchase, checkout, and lead events directly from server infrastructure to advertising endpoints. Server delivery avoids dependence on a browser request, but event completeness still depends on collection, permissions, matching data, and delivery reliability.
Audit & Verification Checklist
- ✓ Measure browser and server event coverage against your own order records rather than assuming a fixed recovery percentage.
- ✓ Truncated cookies prevent 7-day and 28-day attribution windows from crediting prospecting campaigns.
- ✓ Monitor Event Match Quality (EMQ) and delivery diagnostics; server delivery alone does not guarantee better matching or performance.
Field-by-Field PII Normalization & Hashing Standards
Hashing requirements are field-specific. Normalize and hash customer match identifiers as required by the receiving provider. Do not apply a blanket hash to event identifiers or other fields whose API specification requires their original representation.
| Field Name | Raw Format Example | Normalization Rule | Hashing Requirement |
|---|---|---|---|
| email (em) | [email protected] | Trim whitespace, lowercase all characters | SHA-256 hex string (64 characters) |
| phone (ph) | +1 (555) 019-2834 | Remove all spaces, brackets, hyphens; include country code | SHA-256 hex string of normalized digits |
| external_id | Shopify Customer #98421 | Trim whitespace, ensure stable customer identifier | SHA-256 hex string for customer matching |
| first_name / last_name | Jane / Doe | Trim whitespace, lowercase, remove punctuation | SHA-256 hex string per name field |
| event_id | ord_98421_1727500000 | Unique transaction identifier shared between browser & server | Plaintext string (used for deduplication) |
Deduplication: Running Browser Pixel and Server CAPI in Parallel
To achieve maximum signal redundancy without double-counting revenue, both the browser pixel and the server-side API must transmit identical event_name and event_id values for each occurrence.
Deduplication rules and timing depend on the provider. Keep the event name and event ID consistent for both copies of the same conversion, and use the provider diagnostics to confirm that it is counted once.
Inspect test payloads and logging configuration before launch. Hashing customer match fields does not by itself establish consent, data minimization, or safe logging.
Prompt Playbook: Checking Conversion Signal Health
Diagnose whether your server-side conversion pipeline is functioning correctly with this diagnostic query:
Authoritative Documentation Sources
Plan your next campaign with Salfars
Explore supported workflows, review recommendations, and confirm the available approval controls before making live changes.
Salfars is in beta. Platform access depends on provider approval, your account permissions, and the features enabled for your workspace. A connected account does not guarantee every feature is available.