Hashing is a method that converts any input, such as an email address, into a string of fixed length using a mathematical algorithm. In ad tracking that algorithm is almost always SHA-256. A hash cannot be directly reversed, but the same input always produces the same hash.
How does hashing work?
A hash function is a one-way function. Run max@example.com through SHA-256 and you get a 64-character hexadecimal string. Change a single character and the hash is completely different. That is why data has to be normalized first: emails lowercased and trimmed, phone numbers in a consistent format with country code.
Ad platforms hash their own user data with the same algorithm. When the two hashes match, the platform knows it is the same person, without you ever sending the email in plain text.
Why does hashing matter?
Hashing is what makes it possible to match first-party data with ad platforms. Neither Advanced Matching at Meta nor Enhanced Conversions at Google work without hashed customer data, and the Conversions API requires personal data to be hashed. More hashed parameters typically improve Event Match Quality.
A key privacy point: hashing is pseudonymization, not anonymization. Under the GDPR the data remains personal because it can be matched with existing records, so you still need consent or another legal basis. Our guide to GDPR-compliant tracking covers the details.
Example
A lead types their email as Max@Example.com, with capital letters and a trailing space. Before hashing, it becomes max@example.com. Only this normalized value produces the hash that Meta or Google have stored for the matching account. Without normalization, there would be no match.
Hashing with LeadSignal
LeadSignal automatically detects email, phone, first name and last name in your forms and hashes the values with SHA-256 before they are sent to Meta, Google or TikTok. You do not write any code or map any fields. Ad pixels only load once the visitor has given marketing consent via the built-in cookie banner.