Analytics and Tracking

Hashing

A one-way process that turns an email or phone number into a fixed code, so ad platforms can match customers without receiving the plain text.

Quick facts: Hashing

Category
Analytics and Tracking
Level
Intermediate
Affects
Enhanced conversions, Meta Conversions API match quality, customer list match rates, UK GDPR compliance
Where to see it
Google Ads conversion diagnostics, Meta Events Manager, Customer Match and custom audience uploads, Google Tag Manager
In this article4
  1. How hashing works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

Hashing is a one-way mathematical process that turns a piece of data, such as an email address, into a fixed-length string of characters that cannot simply be turned back into the original. In marketing, it is how customer details are scrambled before they are sent to Google, Meta and other platforms, so the platforms can match them to their own users without the plain text travelling with them.

How hashing works

A hashing function always produces the same output for the same input. Ad platforms use SHA-256, which turns an address like jane.smith@example.co.uk into a 64-character string of letters and numbers. Change a single character, even a capital letter or a trailing space, and the result is completely different.

Matching depends on that consistency. You hash a customer’s email address on your side. The platform has already hashed the addresses of its own users. If the two strings are identical, the platform knows the same person is involved, without you having sent the address itself. Several common features work this way:

  • Enhanced conversions in Google Ads, which send hashed details from your conversion page to improve measurement.
  • Meta’s Conversions API and advanced matching, which attach hashed customer details to each event.
  • Customer list uploads, such as Google’s Customer Match and Meta’s custom audiences, where a list of customers is hashed before or during upload.

Before hashing, data has to be normalised exactly as each platform specifies: lower case, no spaces at either end, and phone numbers in international format. Google, for instance, asks for the plus sign and country code, so the UK mobile 07700 900123 becomes +447700900123, while Meta asks for the same digits without the plus sign. If your formatting differs from the platform’s rules, the hashes never match and the data is wasted.

Why it matters

Cookie refusals and browser privacy features mean ad platforms see fewer conversions than really happen. Sending hashed first-party data lets them connect more sales and leads to the ads that produced them, which improves reporting and gives automated bidding better information to learn from.

It is easy, though, to read hashing as making data anonymous. It does not. A hashed email still points to one person, and anyone holding the same address can produce the same hash and find the match; that is the whole purpose of the feature. Under UK GDPR, hashed contact details are pseudonymised data, which is still personal data. You still need a lawful basis to share it, a privacy notice that says you share customer details with advertising platforms for matching, and, where details are collected through cookies or similar technology on your site, the consent PECR requires.

Common mistakes

  • Describing hashed data as anonymised in a privacy notice or a data protection impact assessment.
  • Skipping normalisation, so capital letters, stray spaces or a leading zero on a phone number stop records matching.
  • Hashing twice. If a platform’s tag or upload tool hashes the data for you and you send values you have already hashed in a plain-text field, they are hashed again and match nothing.
  • Uploading customer lists that include people who never agreed to their details being used for advertising.
  • Adding a salt or secret key. That is good practice for storing passwords, but it breaks platform matching, because the platform cannot recreate your salted value.

How to act on it

Work out where hashed data already leaves your business. Check whether enhanced conversions are switched on in Google Ads, whether advanced matching is on in Meta Events Manager, and who uploads customer lists, how often, and from which system.

For each route, confirm three things. The data is normalised to the platform’s published rules before hashing; low match rates in the platform’s diagnostics usually point to formatting problems. The visitor’s consent choice controls whether the browser-based routes run at all. And your privacy notice names the platforms and explains the matching in plain words.

Then judge whether it is working by comparing reported conversions before and after, and by checking match rates on uploaded lists. Setting up enhanced conversions and the Conversions API correctly, with consent in place, is part of my performance marketing service.

Do and do not

Do

  • Normalise data to each platform's rules before hashing
  • Explain hashed matching in your privacy notice
  • Check match rates after setting it up

Do not

  • Describe hashed data as anonymous
  • Salt hashes that are meant for platform matching
  • Upload customer lists without a lawful basis for each person on them

Questions people ask about this

Is a hashed email address anonymous?

No. Anyone who already has the same email address can produce the same hash and link it to the person, which is exactly how platform matching works. Data like this is pseudonymised, and pseudonymised data is still personal data under UK GDPR, with all the duties that brings.

Do I need to hash data myself before sending it to Google or Meta?

Not always. Google's tag can hash details collected on your conversion page before sending them, and Meta's pixel does the same for automatic advanced matching. If you send data from your server or upload a file through an API, you usually hash it yourself, following each platform's normalisation rules exactly.

Is hashing the same as encryption?

No. Encryption is designed to be reversed by whoever holds the key, so data can be stored or sent and read again later. Hashing has no key and is not meant to be reversed; it produces a fingerprint for comparing values. Common values such as email addresses can still be guessed by hashing likely candidates and comparing the results, which is why hashing alone is not anonymisation.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.