Privacy Policy
Google + Meta Ads Conversion Tracking
Last updated: 30 July 2026
This Privacy Policy explains how Unwired Logic K.K. ("Unwired Logic", "we", "us") handles information in connection with Google + Meta Ads Conversion Tracking (the "Service"). It applies specifically to the Service and is separate from our general website privacy policy.
The Service is delivered as integrations (add-ons) for business platforms - such as Storeganise, Zendesk, Pipedrive, and respond.io - and uploads offline conversion events (for example, a lead or a completed sale/move-in) from a connected platform to the operator's own Google Ads and/or Meta (Facebook) advertising accounts, so the operator can measure the ad performance that drives their conversions. The Google account access described below is the same regardless of which platform the events come from.
Who this involves
- Operator - the business that enables the Service on a supported platform and connects its own Google Ads and/or Meta ad accounts.
- Visitors/customers - people who interact with the operator on its connected platform and become leads or customers.
Information we access and process
1. Google account access (service account). To connect Google Ads, the operator creates a Google service account in Google Cloud and adds it as a user on their own Google Ads account, then provides the service-account key to the Service. The Service uses that key to authenticate to Google's Data Manager API and upload conversion events to the operator's chosen Google Ads account. We do not receive a Google OAuth token, and we do not read the operator's campaigns, settings, or account list - the access is used solely to upload conversions. Access to the connected business platform is separate and is described under Platform access.
2. Meta account data. When an operator connects Meta, we store the Meta Pixel ID and Conversions API access token the operator provides, and use them only to send conversion events to the operator's Meta account.
3. Conversion and attribution data (processed on the operator's behalf). To build conversion events, the Service processes advertising-attribution data associated with the operator's leads/customers, such as ad click identifiers (e.g., Google gclid/gbraid/wbraid, Meta fbclid), UTM campaign parameters, landing-page URL, event type, timestamp, and conversion value. To help the ad platforms match a conversion to the original click, contact identifiers (email and phone) are hashed (SHA-256) before transmission to both Google (Data Manager API) and Meta (Conversions API). Contact identifiers are never transmitted in the clear.
How we use the information
We use the information only to:
- authenticate to the operator's connected Google Ads and Meta accounts, and
- upload offline conversion events to those accounts on the operator's behalf.
We do not use it for advertising to you, profiling, resale, credit assessment, or training machine-learning/AI models, and we do not access Google Ads data for any purpose other than the conversion uploads described above.
Our access to your Google Ads account
The service account operates as a user on the operator's own Google Ads account, with only the access the operator grants it. The Service uses it exclusively to upload conversion events through Google's Data Manager API. We do not read the operator's campaigns, reports, billing, or other account data, we do not use the access for advertising, and it is not read by humans except with the operator's consent, for security/debugging, or as required by law.
Platform access
What the Service reads from, and writes to, the connected business platform depends on that platform. The Google and Meta access described above is the same in every case.
Zendesk
- Authorization. An operator administrator grants the Service access to their Zendesk account through Zendesk OAuth, with the scopes
users:read,users:write,tickets:readandtickets:write. The resulting token is stored per operator and encrypted at rest. The granting user is the acting agent: actions the Service takes in Zendesk are attributed to them. - What we read. The Zendesk user and ticket custom fields the operator maps in the app - ad click identifiers, UTM parameters, landing URL and capture timestamp on the user; order id, order amount, currency and pipeline stage on the ticket - together with the ticket requester's email and phone. Email and phone are hashed with SHA-256 before transmission to Google or Meta and are never sent in the clear.
- What we write. The identifier returned by Google or Meta for each uploaded conversion is written onto the Zendesk user record, and a private comment is added to the order ticket, as a visible record of what was uploaded. Duplicate suppression is handled separately, by our own internal conversion log - see Storage and security.
- Inbound requests. Zendesk notifies the Service by webhook. Every inbound request is signature-verified with a per-installation secret before it is processed.
- Who can configure it. The configuration screen inside Zendesk is restricted to the email addresses listed in the app's Administrators setting.
- How to revoke. Click Revoke in the app's Zendesk access section, or uninstall the app from Zendesk Admin Center. Either removes the stored Zendesk token.
A fuller description of the Zendesk integration is on its integration details page.
Storage and security
- Google service-account keys, Meta access tokens, and other secrets are encrypted at rest with field-level encryption (AWS KMS) in addition to storage-level encryption, and are stored per operator.
- We keep one record per conversion in our own datastore, so a conversion is never uploaded twice. Each record holds the platform account or tenant identifier (for Zendesk, the subdomain), the ad click identifier or the ticket id and pipeline stage the conversion relates to, which flow and ad platform it targeted, its status, timestamps, and the identifier the ad platform returned. This datastore is encrypted at rest with AWS KMS and has point-in-time recovery enabled. Records are retained for as long as needed to prevent duplicate uploads and are not deleted when an operator disconnects or uninstalls the Service.
- Data is hosted on Amazon Web Services (region: US East, N. Virginia) and transmitted over TLS.
- Access is restricted to the automated service and authorized Unwired Logic personnel for support, security, and debugging.
Sharing and sub-processors
We do not sell personal information. We share data only:
- with Google (Data Manager API) and Meta (Conversions API) to deliver the conversion uploads the operator requested;
- with Amazon Web Services, our hosting sub-processor; and
- where required by law.
Retention and deletion
We retain an operator's connected-account credentials and configuration for as long as the Service remains connected. When an operator disconnects the Service, uninstalls it, or requests deletion, we delete the associated service-account key, cached access tokens, and configuration. Operators can also revoke the Service's access at any time by removing the service account from their Google Ads account's users or deleting its key in Google Cloud, and by revoking the Meta access token in Meta Events Manager.
Your choices
- Disconnect or uninstall the Service from your platform's add-on/integration settings.
- Revoke Google access by removing the service account from your Google Ads account's users or deleting its key in Google Cloud; revoke Meta access in Events Manager.
- Contact us to request access to, or deletion of, data we hold about your connection.
Children
The Service is a business tool and is not directed to children.
Changes
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Unwired Logic K.K.
2-2-15 Hamamatsucho, Minato-ku, Tokyo 105-0013, Japan
Email: support@unwiredlogic.com