Meta · TikTok · Shopify · Governance • 8 min read • Updated 2026-09-29

Server-Side Conversion Tracking (Meta CAPI & TikTok Events API): SHA-256 PII Hashing Explained

Field-by-field PII normalization, SHA-256 cryptographic hashing, event deduplication, and data retention rules for Meta Conversions API and TikTok Events API.

By Salfars Security Team · Privacy & Data Engineering · Published

Summary & Direct Answer

Server-side conversion tracking complements browser pixels by sending permitted events from your server. Follow each provider’s field-specific normalization and hashing rules, preserve event identifiers for deduplication, and validate event receipt before using the data to make bidding decisions.

Methodology: This is an implementation checklist, not a certification of a deployed tracking pipeline. Field requirements differ by provider; consult the linked documentation and validate sample events in the provider diagnostics tools.

Why Browser-Only Tracking Fails Modern E-Commerce

Relying solely on client-side JavaScript pixels (such as fbevents.js) creates severe signal loss. Modern browser protections (Safari ITP, Firefox ETP, ad blockers, and mobile privacy toggles) frequently block client-side network calls or truncate cookies to 24 hours.

Server-side conversion tracking solves this by dispatching purchase, checkout, and lead events directly from server infrastructure to advertising endpoints. Server delivery avoids dependence on a browser request, but event completeness still depends on collection, permissions, matching data, and delivery reliability.

Audit & Verification Checklist

  • ✓ Measure browser and server event coverage against your own order records rather than assuming a fixed recovery percentage.
  • ✓ Truncated cookies prevent 7-day and 28-day attribution windows from crediting prospecting campaigns.
  • ✓ Monitor Event Match Quality (EMQ) and delivery diagnostics; server delivery alone does not guarantee better matching or performance.

Field-by-Field PII Normalization & Hashing Standards

Hashing requirements are field-specific. Normalize and hash customer match identifiers as required by the receiving provider. Do not apply a blanket hash to event identifiers or other fields whose API specification requires their original representation.

PII Normalization & SHA-256 Hashing Protocol
Field NameRaw Format ExampleNormalization RuleHashing Requirement
email (em) [email protected] Trim whitespace, lowercase all charactersSHA-256 hex string (64 characters)
phone (ph) +1 (555) 019-2834 Remove all spaces, brackets, hyphens; include country codeSHA-256 hex string of normalized digits
external_id Shopify Customer #98421 Trim whitespace, ensure stable customer identifierSHA-256 hex string for customer matching
first_name / last_name Jane / Doe Trim whitespace, lowercase, remove punctuationSHA-256 hex string per name field
event_id ord_98421_1727500000 Unique transaction identifier shared between browser & serverPlaintext string (used for deduplication)

Deduplication: Running Browser Pixel and Server CAPI in Parallel

To achieve maximum signal redundancy without double-counting revenue, both the browser pixel and the server-side API must transmit identical event_name and event_id values for each occurrence.

Deduplication rules and timing depend on the provider. Keep the event name and event ID consistent for both copies of the same conversion, and use the provider diagnostics to confirm that it is counted once.

Validate Data Handling End to End

Inspect test payloads and logging configuration before launch. Hashing customer match fields does not by itself establish consent, data minimization, or safe logging.

Prompt Playbook: Checking Conversion Signal Health

Diagnose whether your server-side conversion pipeline is functioning correctly with this diagnostic query:

Workflow Intent / Assistant Prompt Example Audit Safe
Help me review the Purchase and InitiateCheckout diagnostics I exported from Meta Events Manager. Identify missing match parameters and deduplication warnings without changing my tracking configuration.
What It Reads: Uses the diagnostics you provide from Meta Events Manager; do not assume Ads Insights exposes Event Match Quality scores.
Approval Boundary: Read-only interpretation of the supplied diagnostics. Test any proposed tracking changes separately before deployment.

Plan your next campaign with Salfars

Explore supported workflows, review recommendations, and confirm the available approval controls before making live changes.

Salfars is in beta. Platform access depends on provider approval, your account permissions, and the features enabled for your workspace. A connected account does not guarantee every feature is available.