Privacy-first measurement

    First-party tracking for a cookieless, consent-first web

    Prism, Adsidian's server-side tracking layer, recovers the conversions browser pixels miss — and does it with consent, hashing, and data minimization built in. Better measurement and GDPR/CCPA compliance, at the same time.

    GDPR & UK GDPR ready
    CCPA / CPRA aligned
    Consent-gated by default

    Why first-party tracking wins

    Pixel-only measurement is leaking data. First-party, server-side collection closes the gap — without cutting corners on privacy.

    Recover conversions you're losing

    Ad blockers, Safari/Firefox tracking prevention, and short-lived cookies silently drop a large share of browser-side pixel events. Server-side, first-party collection captures those conversions the pixel never sees.

    Sharper ad optimization

    Cleaner, more complete conversion data feeds Meta's Conversions API and Google Ads directly — so the platforms' algorithms optimize on real outcomes instead of a partial, degraded signal.

    You own the data

    Events are collected first-party on your own domain and land in your own store — not siphoned into a third party's black box. Your measurement doesn't depend on someone else's cookie.

    Built for a cookieless web

    Third-party cookies are going away and browser restrictions keep tightening. First-party, server-side measurement is durable by design — resilient to changes that break pixel-only setups.

    Accurate attribution

    Click IDs and pseudonymous visitor identifiers are resolved server-side and matched to conversions, so revenue is attributed to the campaigns that actually drove it.

    Privacy-first, not privacy-hostile

    Better measurement and respecting your visitors aren't in tension. Identifiers are hashed before they leave the browser and every downstream share honors the visitor's consent choice.

    How Prism handles data

    Three steps, privacy enforced at each one.

    1

    Collect first-party, server-side

    A lightweight snippet on your site sends events to Prism running on your own subdomain — first-party, so browser restrictions and ad blockers don't strip it.

    2

    Hash & minimize in the browser

    Email and phone are SHA-256 hashed in the visitor's browser before transmission. IP addresses can be truncated at your election. Raw identifiers never leave the page.

    3

    Check consent, then deliver

    Every event is evaluated against the visitor's consent signal before anything is shared. Consented conversions are delivered to Meta's Conversions API and Google Ads.

    GDPR & CCPA, by design

    Compliance isn't bolted on after the fact — it's enforced in the data path. Here's how we handle it.

    Consent-gated by default

    Prism reads the visitor's consent signal from your consent manager or an IAB TCF-compatible CMP. An explicit denial always suppresses sharing with ad platforms. Where a visitor opts out of personalized ads, we forward restricted-processing signals — Meta Limited Data Use and Google Consent Mode.

    Data minimization

    Contact identifiers are SHA-256 hashed in the browser before they're transmitted, and visitor IP addresses can be truncated at the website operator's election. We collect what's needed to measure — not more.

    Retention & data-subject rights

    Raw event data is retained 13 months by default (configurable per customer), then kept only in de-identified aggregate. We support access, correction, and erasure (DSAR) requests, and refer requests about a specific site to that site's operator.

    No sale, no cross-context sharing

    We do not sell personal information and do not share it for cross-context behavioral advertising. Conversion data is delivered to the ad platforms you connect, as a service provider acting on your instructions.

    Transparent cookies

    Prism sets a first-party visitor identifier (up to 1 year) and ad click-ID cookies (90 days) — no third-party advertising cookies. Everything is disclosed in your privacy notice.

    Contracts & transparency

    Processing on your behalf is governed by our Data Processing Agreement, with a current subprocessor list published at docs.adsidian.ai and EU/UK/Swiss transfers covered by Standard Contractual Clauses.

    When Prism runs on your website, you are the data controller and Adsidian acts as your processor under our Privacy Policy and Data Processing Agreement. This page is an overview, not legal advice.

    Measure more. Compromise less.

    See first-party tracking running on your own accounts — recovered conversions and a consent-respecting data path, side by side with your current setup.