Hashing is a one-way mathematical process that turns a piece of data, such as an email address, into a fixed-length string of characters that cannot simply be turned back into the original. In marketing, it is how customer details are scrambled before they are sent to Google, Meta and other platforms, so the platforms can match them to their own users without the plain text travelling with them.
How hashing works
A hashing function always produces the same output for the same input. Ad platforms use SHA-256, which turns an address like jane.smith@example.co.uk into a 64-character string of letters and numbers. Change a single character, even a capital letter or a trailing space, and the result is completely different.
Matching depends on that consistency. You hash a customer’s email address on your side. The platform has already hashed the addresses of its own users. If the two strings are identical, the platform knows the same person is involved, without you having sent the address itself. Several common features work this way:
- Enhanced conversions in Google Ads, which send hashed details from your conversion page to improve measurement.
- Meta’s Conversions API and advanced matching, which attach hashed customer details to each event.
- Customer list uploads, such as Google’s Customer Match and Meta’s custom audiences, where a list of customers is hashed before or during upload.
Before hashing, data has to be normalised exactly as each platform specifies: lower case, no spaces at either end, and phone numbers in international format. Google, for instance, asks for the plus sign and country code, so the UK mobile 07700 900123 becomes +447700900123, while Meta asks for the same digits without the plus sign. If your formatting differs from the platform’s rules, the hashes never match and the data is wasted.
Why it matters
Cookie refusals and browser privacy features mean ad platforms see fewer conversions than really happen. Sending hashed first-party data lets them connect more sales and leads to the ads that produced them, which improves reporting and gives automated bidding better information to learn from.
It is easy, though, to read hashing as making data anonymous. It does not. A hashed email still points to one person, and anyone holding the same address can produce the same hash and find the match; that is the whole purpose of the feature. Under UK GDPR, hashed contact details are pseudonymised data, which is still personal data. You still need a lawful basis to share it, a privacy notice that says you share customer details with advertising platforms for matching, and, where details are collected through cookies or similar technology on your site, the consent PECR requires.
Common mistakes
- Describing hashed data as anonymised in a privacy notice or a data protection impact assessment.
- Skipping normalisation, so capital letters, stray spaces or a leading zero on a phone number stop records matching.
- Hashing twice. If a platform’s tag or upload tool hashes the data for you and you send values you have already hashed in a plain-text field, they are hashed again and match nothing.
- Uploading customer lists that include people who never agreed to their details being used for advertising.
- Adding a salt or secret key. That is good practice for storing passwords, but it breaks platform matching, because the platform cannot recreate your salted value.
How to act on it
Work out where hashed data already leaves your business. Check whether enhanced conversions are switched on in Google Ads, whether advanced matching is on in Meta Events Manager, and who uploads customer lists, how often, and from which system.
For each route, confirm three things. The data is normalised to the platform’s published rules before hashing; low match rates in the platform’s diagnostics usually point to formatting problems. The visitor’s consent choice controls whether the browser-based routes run at all. And your privacy notice names the platforms and explains the matching in plain words.
Then judge whether it is working by comparing reported conversions before and after, and by checking match rates on uploaded lists. Setting up enhanced conversions and the Conversions API correctly, with consent in place, is part of my performance marketing service.
