Privacy by design

Built for the EU.
GDPR-ready by architecture.

GDPR-ready server-side tracking, hosted in the EU — designed with privacy requirements in mind, not bolted on later. No consent dark patterns, no workarounds.

Privacy architecture

  1. 01

    SHA-256 hash in browser

    Email and phone hashed client-side - plain text never leaves the page.

  2. 02

    EU servers only

    Hashed events processed in the EU. No plain-text PII is stored in the relay layer.

  3. 03

    Consent gate

    When marketing consent is denied, identifiable data is not forwarded to ad platforms.

  4. 04

    Hashed forwarding

    Permitted events forwarded to connected ad platforms under each platform's terms.

Data protection

How we protect your data

EU-Hosted Infrastructure

SyncBeacon's servers and database are hosted in the EU. Plain-text PII never reaches those servers - it is SHA-256 hashed in the browser first. The hashed event data forwarded to ad platforms (OpenAI, Meta, Google, Microsoft, Pinterest, Snapchat, X) carries no reversible personal information and is transmitted under each platform's own EU Data Processing Agreement.

Client-Side PII Hashing

Email addresses and phone numbers are SHA-256 hashed in the user's browser before transmission. Plain-text PII never leaves the page - ever.

Consent-Signal Aware

Reads signals from your existing Consent Management Platform (CMP). Non-consenting visitors never have identifiable data forwarded to ad platforms.

Zero Third-Party Cookies

No reliance on third-party cookies whatsoever. Works identically regardless of browser cookie settings — designed into the architecture, not bolted on as a workaround.

Data Minimisation by Default

Only the fields required for conversion matching are captured and forwarded. No behavioural profiling, no fingerprinting, no cross-site tracking.

Right to Erasure (RTBF)

Built-in GDPR Article 17 erasure support. Remove stored event data for a user through your dashboard controls when handling Data Subject Access Requests.

FAQ

Privacy and compliance questions

Is SyncBeacon GDPR-ready?

SyncBeacon provides GDPR-ready server-side tracking, hosted in the EU — with consent-aware forwarding, hashed matching where applicable, and DSAR assistance tools. Your overall compliance still depends on your consent setup, privacy policy, and how you configure destinations.

How does SyncBeacon handle cookie consent?

SyncBeacon reads signals from your Consent Management Platform. In explicit mode, hashed customer identifiers are only forwarded when marketing consent was granted. Non-consenting orders can send limited, non-identifying order data where configured.

Where is my data stored?

SyncBeacon processes and stores event data on EU servers in Germany. When you connect ad platforms, hashed identifiers may be forwarded under each platform's own terms — that is separate from SyncBeacon's EU hosting.

Does SyncBeacon use third-party cookies?

No. SyncBeacon does not rely on third-party cookies. Click IDs and session context are stored as first-party data where permitted, and confirmed conversions are delivered server-side.

What personal data is sent to ad platforms?

Only the fields needed for conversion matching: event name, value, currency, order ID, click IDs where available, and SHA-256 hashed email or phone when consent allows. Plain-text PII is hashed in the browser before it leaves the page.

Can I honour GDPR erasure requests?

Yes. SyncBeacon includes erasure workflows (GDPR Article 17) so you can remove stored event data for a user when handling data subject requests.