Principles
DealOracle moves conversion signals, not customer files. The design follows three rules:
- Hash before it leaves. Email, phone, name and address fields are normalized and hashed with SHA-256 on DealOracle's servers before any event is sent to an ad platform. The platforms receive hashes they can match against their own hashed user data; they never receive the plaintext from us.
- Consent decides. Where consent is required, the visitor's choice gates both the pixel and the server-side events for that visitor.
- Minimum necessary. Events carry the identifiers needed to match and attribute, the event name, time and value. Nothing about the content of your CRM notes or deals travels beyond the value you choose to send.
What each platform receives
| Field | Sent as |
|---|---|
| Email, phone | SHA-256 hash, normalized |
| First name, last name, city, state, zip, country | SHA-256 hash where the platform supports it |
| Click ID (fbclid, gclid, ttclid, and others) | As captured |
Browser IDs (_fbp, TikTok browser ID) | As captured, browser events only |
| IP address, user agent | Browser events only, where the platform requests them |
| Event name, time, value, currency | Plain |
| Event ID | Random identifier for deduplication |
Meta, Google, TikTok, Snapchat, Microsoft, Pinterest and LinkedIn each publish the fields their API accepts; DealOracle sends the subset you have for the lead.
Consent
DealOracle includes a cookie consent banner for your public pages. When it is enabled for a region, the tracking pixel waits for consent before storing identifiers, and server-side events for that visitor are sent only if consent was recorded. Consent choices are stored with the visitor record, and visitors can change them from the footer's cookie preferences link at any time.
For visitors outside regions that require consent, the pixel runs first-party on your domain and the same hashing rules apply.
Retention, deletion and your rights
- Storage: lead and event data is stored encrypted at rest and in transit, isolated per account.
- Retention: data stays while the account is active. Closed accounts are purged after the retention period stated in the Terms of Service.
- Deletion requests: a contact's data can be deleted from the Lead Manager, or by request through the data deletion page. Deletion removes the lead, its events and its journey; events already delivered to ad platforms are governed by those platforms' policies.
- Agreements: a Data Processing Agreement is available for customers who need one under GDPR; DealOracle acts as a processor for lead data and the customer as controller.
- Rights: access, correction and deletion requests from your contacts should be sent to you as the controller; DealOracle assists within the DPA's terms.
Full details are in the Privacy Policy and Cookie Policy.
