Privacy & Consent

Hashing

One-way encoding of customer data

In short

Hashing turns data such as an email address into a fixed-length string using an algorithm, usually SHA-256, that cannot be directly reversed.

Also known as: SHA-256

Hashing is a method that converts any input, such as an email address, into a string of fixed length using a mathematical algorithm. In ad tracking that algorithm is almost always SHA-256. A hash cannot be directly reversed, but the same input always produces the same hash.

How does hashing work?

A hash function is a one-way function. Run max@example.com through SHA-256 and you get a 64-character hexadecimal string. Change a single character and the hash is completely different. That is why data has to be normalized first: emails lowercased and trimmed, phone numbers in a consistent format with country code.

Ad platforms hash their own user data with the same algorithm. When the two hashes match, the platform knows it is the same person, without you ever sending the email in plain text.

Why does hashing matter?

Hashing is what makes it possible to match first-party data with ad platforms. Neither Advanced Matching at Meta nor Enhanced Conversions at Google work without hashed customer data, and the Conversions API requires personal data to be hashed. More hashed parameters typically improve Event Match Quality.

A key privacy point: hashing is pseudonymization, not anonymization. Under the GDPR the data remains personal because it can be matched with existing records, so you still need consent or another legal basis. Our guide to GDPR-compliant tracking covers the details.

Example

A lead types their email as Max@Example.com, with capital letters and a trailing space. Before hashing, it becomes max@example.com. Only this normalized value produces the hash that Meta or Google have stored for the matching account. Without normalization, there would be no match.

Hashing with LeadSignal

LeadSignal automatically detects email, phone, first name and last name in your forms and hashes the values with SHA-256 before they are sent to Meta, Google or TikTok. You do not write any code or map any fields. Ad pixels only load once the visitor has given marketing consent via the built-in cookie banner.

Frequently asked questions

Is hashed data anonymous?+

No. Under the GDPR, hashed email addresses or phone numbers are generally considered pseudonymized, not anonymous, because they can be linked back to a person by comparing them with known data. You still need a legal basis.

Why do Meta and Google require SHA-256?+

SHA-256 is a widely used, standardized hash algorithm. Because advertiser and platform use the same algorithm, the same email always produces the same hash, so the platform can match it against its own data without receiving the plain-text address.

Do I need to normalize data before hashing?+

Yes. A single capital letter or space produces a completely different hash. Platforms therefore require, for example, lowercase emails, trimmed whitespace and phone numbers with country code.

Guides on this topic

Articles on this topic

Related terms