Zendesk integration
Google + Meta Ads Conversion Tracking
Last updated: 30 July 2026
This page describes the Zendesk app specifically. The legal terms that govern it are the Privacy Policy and Terms of Service, which cover the Service on every platform it integrates with.
What the app does
The app connects a Zendesk account to the operator's own Google Ads and Meta advertising accounts and uploads offline conversions. When a person clicks one of the operator's ads, becomes a Zendesk user, and goes on to place an order, the app reports that outcome back to the ad platform so campaigns can be optimised on real business results rather than clicks.
It runs in two flows:
- New and updated users. When a Zendesk user is created or updated and carries an ad click identifier, the app uploads a lead conversion.
- Order tickets. As an order ticket moves through its pipeline stages - New, Attempting, Order placed, Cancelled, Won, Lost - the app uploads the conversion the operator mapped to that stage.
Each conversion is uploaded at most once, because the Service keeps its own internal conversion log of what has already gone out. The identifier the ad platform returns is also written back into Zendesk, as a visible record of what was uploaded.
Access the app requires
Zendesk
An OAuth grant from an operator administrator, with the scopes users:read, users:write, tickets:read and tickets:write. The token is stored per operator and encrypted at rest. The granting user is the acting agent, so anything the app writes is attributed to them - use a dedicated service account where possible.
Google Ads and Meta
A Google Cloud service-account key added as a user on the operator's own Google Ads account, and/or a Meta dataset id with a Conversions API access token. Both are provided by the operator and used only to upload conversions.
Data read from Zendesk
Only the fields the operator maps in the app:
- On the user: ad click identifier, UTM source, medium and campaign, Google
gbraidandwbraid, landing URL, and the timestamp the attribution data was captured. - On the order ticket: order id, order amount, currency, and pipeline stage.
- Identity: the requester's email and phone, which are hashed with SHA-256 before being sent to Google or Meta. They are never transmitted in the clear.
Data written back to Zendesk
- The conversion identifier returned by Google or Meta, on the Zendesk user record.
- A private comment on the order ticket recording the conversion that was uploaded.
Each conversion is uploaded at most once because the Service keeps its own internal conversion log; the write-back above is not the deduplication mechanism, but a visible record of what was sent.
Security
- Credentials and configuration are encrypted at rest with field-level AWS KMS encryption, in addition to storage-level encryption, and are stored per operator. Secrets are never displayed again after saving.
- Inbound Zendesk webhooks are signature-verified with a per-installation secret before processing.
- The configuration screen inside Zendesk is restricted to the email addresses in the app's Administrators setting.
- All traffic uses HTTPS / TLS. Hosting is on Amazon Web Services.
Revoking access
Click Revoke in the app's Zendesk access section, or uninstall the app from Zendesk Admin Center. Either removes the stored Zendesk token. Google and Meta access is revoked separately, by removing the service account from the Google Ads account or deleting its key in Google Cloud, and by revoking the access token in Meta Events Manager.
Contact
Unwired Logic K.K.
2-2-15 Hamamatsucho, Minato-ku, Tokyo 105-0013, Japan
Email: support@unwiredlogic.com