How HonestTag delivers conversions server-side
By the HonestTag team ยท Published August 23, 2026
HonestTag's supported delivery destinations are Google Ads, Meta, Klaviyo, Microsoft Advertising, TikTok, Google Analytics 4, Pinterest, Snapchat, Reddit and OpenAI Ads. Google delivery runs through Google's Data Manager API into the HonestTag conversion actions in the one ad account you selected. Email and phone sent for ad matching are SHA-256 hashed before they leave HonestTag. Not hashed: ad click IDs, the IP address and user agent Shopify recorded for the order, Meta's own fbp and fbc values, our random visitor ID, sent to Meta as its external ID (when an order has no visitor ID, Meta gets a SHA-256 hash of the Shopify customer ID instead, or the hashed email when there is neither), and Klaviyo's profile lookup, described below (section B3 of our privacy policy lists what each destination receives). Global Privacy Control and Do Not Track signals drop the pixel beacon, so no visitor record is made; they do not by themselves block an order from being delivered. Every delivery leaves a per-order proof you can open.
From order to delivered conversion, step by step
- Capture. A shopper arrives from a Google ad and the URL carries a click id (
gclid,gbraid, orwbraid). The store's first-party pixel records it against a random visitor id, subject to the consent handling in section B4 of our privacy policy. - Match. The shopper orders. Shopify sends the order webhook, HonestTag joins the order to the visitor record, and classifies the customer as new or returning against the store's own order history.
- Consent check. Before anything is sent, the recorded consent state is applied. The rules are stated exactly in the section below; an order those rules block is dropped, not sent.
- Deliver. HonestTag sends one request to Google's Data Manager API, carrying one event for each applicable HonestTag conversion action (a new-customer purchase reaches the base purchase action and the new-customer variants): the click id and, where available, hashed customer identifiers, the order value and currency, a timestamp, an order-scoped transaction id, and the recorded consent signals.
- Prove. A per-order proof record is written that you can open in the app.
What leaves our systems, and what never does
Customer identifiers sent to Google for matching are hashed with SHA-256 before they leave HonestTag, in memory, at delivery time. Raw email addresses and phone numbers are not placed in attribution keys or delivery queues, and are never sent to Google in the clear by this delivery path. What Google receives is the click id, hashed identifiers where available, order value, currency, timestamps, a transaction id, and consent signals, plus whether the buyer is new or returning if you turn that on. What it does not receive: raw contact details, your customer list, or anything about any other store.
Everything is bound to the single ad account you selected. HonestTag never shares conversion data across merchants, never builds cross-store profiles, never sells it, and never uses it to train models.
Consent handling, stated exactly
- Global Privacy Control and Do Not Track signals at our pixel endpoint are honored: the pixel event is dropped and no visitor record is created. They do not by themselves block an order from being delivered (see the points below).
- An explicit refusal reported through Shopify's Customer Privacy API stops the pixel at the source: no visitor record is created and no ad click is tied to the shopper. For EU, EEA, UK and Swiss orders that also blocks delivery (next point). Elsewhere, the order itself can still be delivered on the identifiers it carries, such as a hashed email.
- For EU, EEA, UK, and Swiss orders: a conversion with no visitor record is blocked and no identifiers are sent, unless you turned that gate off in the app because you collect consent somewhere else. Where a visitor record exists, a conversion with an explicit grant carries that grant as Google Consent Mode v2 signals, as does a conversion where your Shopify privacy settings require consent in the shopper's region and Shopify reports it given; any other conversion is transmitted with its consent state marked unknown rather than claimed as granted.
- The per-order record shows the order's region, the consent state that was recorded, whether a grant is on record and what it rests on, so you can see what was applied, not take it on faith.
No double counting
Every event carries the order id as its transactionId. Google uses a unique transaction ID to minimize duplicate conversions (Google Ads Help). Reporting the order to several HonestTag actions still places it in each action once; those actions are separate lenses on the same order. The conversion actions page explains why they exist.
A bundle counts once. Shopify records a bundle sold through its bundles feature as the products inside it, each linked to the bundle. Where a platform receives the order's products (Meta, TikTok, Google Analytics 4, Pinterest, Snapchat, Reddit and OpenAI Ads), HonestTag sends the bundle as one product: the bundle's own product ID, the number of bundles bought, and a unit price equal to what the products inside it were priced at. Klaviyo's item count counts the bundle once. Products bought outside a bundle are sent as they are, and so are bundles an app builds from line-item properties instead of Shopify's bundles feature. The order value sent to every platform comes from the order's total (net of tax, and for Google Analytics 4 and Pinterest net of shipping too), never a sum of the products.
The per-order proof
Every delivery writes a record you can open from the order in the app: the platform it went to, the destination account, the delivery status, the event id, which events were sent (for example purchase, purchase_nc), and the timestamp. When a number in a dashboard looks wrong, you check the proof instead of guessing.
"Accepted" is not the same as "processed", so we check twice
Google's Data Manager API acknowledges a delivery in two stages: it first accepts the batch, then processes the rows inside it later. A delivery marked ok in HonestTag means Google accepted it. HonestTag keeps the accepted request's id and checks Google's row-level processing status afterward. A full rejection is re-marked failed and raises an alert. A partial rejection is marked partial and stays delivered because at least one action landed. We do not leave a fully rejected delivery marked ok on the strength of acceptance alone.
Refunds: adjustments, refund events and records
When you refund an order, HonestTag sends a Google Ads or Microsoft Advertising conversion adjustment for every action that order was reported to: a full refund retracts the conversion, a partial refund restates its value. Google Analytics 4 receives a refund event for the same transaction ID, and Klaviyo receives a Refunded Order event. HonestTag does not send Meta, TikTok, OpenAI Ads, Pinterest, Snapchat or Reddit a refund or retraction event; it records those refund outcomes in order proof instead.
Order edits and post-purchase upsells
A post-purchase upsell adds products to the order the customer just placed, so it reaches HonestTag as an edit to that order, the same as an edit you make in the Shopify admin. When an edit changes the order's value, HonestTag restates the Google Ads and Microsoft Advertising conversions to the new value, up or down. Google Analytics 4 and Klaviyo take a correction only as a refund, so they receive one only when the value goes down. When an edit raises the value, they keep the value sent at purchase time, and order proof shows them as not adjusted with the reason. Other destinations keep the value sent at purchase time.
TikTok purchase delivery and reporting
HonestTag sends server-side purchases through TikTok Events API after the merchant connects TikTok and configures a pixel. A successful TikTok response proves the batch was accepted, not that each event was processed. Each event carries an order-scoped event id. TikTok deduplicates a browser pixel event and an Events API event that share the same pixel, event name and event_id; its cookie-based deduplication applies only to Events API events sent without an event_id, and HonestTag always sends one. So HonestTag's standard CompletePayment event is off by default and turns on only when the merchant chooses HonestTag as the purchase source.
HonestTag's new-customer, returning-customer and first-click new-customer TikTok events are custom events for reporting and audiences. We do not claim those custom events drive Smart Performance bidding. Spend and reporting reads use the merchant's connected TikTok account where supported.
Pinterest connects on its Setup card with a conversion access token and the ad account ID from Pinterest Ads Manager (Ad Account Overview, Conversions, Conversions API, Set up API, Conversion access token). When you save, HonestTag sends one test event, which Pinterest does not process for reporting or optimization, and stores nothing unless Pinterest accepts it. Each purchase then goes to that ad account as one checkout event with your Shopify order ID, the order value without tax and shipping, the currency and the products, matched on SHA-256 hashes of the buyer's email and phone and of HonestTag's visitor ID, the Pinterest click ID when the visit came from a Pinterest ad link, and the IP address and user agent Shopify recorded on the order. Pinterest reports whether it processed each event, and a rejected event is marked failed in order proof.
Pinterest removes a duplicate when both copies carry the same event ID and event name, and no browser tag can send the ID HonestTag uses. So the card asks you to confirm that HonestTag is the only thing sending Pinterest checkout events for the store (turn checkout events off in the Pinterest app for Shopify or any other tag first). A conversion access token can only send events, so HonestTag does not read Pinterest spend and the Mirror does not show Pinterest claims.
Snapchat
Snapchat connects on its Setup card with a Conversions API token and the ID of your Snap Pixel. You generate the token in Snap Ads Manager (Business Details, Conversions API Tokens); only an Organization Admin can see that section. When you save, HonestTag sends one test event to Snap's validation endpoint and stores nothing unless Snap accepts it. Each purchase then goes to that pixel through Snap's Conversions API as one PURCHASE event with your Shopify order ID, the order value without tax, the currency and the products (product ID, quantity and unit price), matched on SHA-256 hashes of the buyer's email and phone and of HonestTag's visitor ID, the Snapchat click ID (ScCid) when the visit came from a Snapchat ad link, and the IP address and user agent Shopify recorded on the order. HonestTag marks a Snapchat purchase delivered when Snap answers VALID for it. Snap does not accept an event more than 7 days old.
Snap treats two copies of a purchase as one when they carry the same event ID (within 48 hours) or the same order reference (within 30 days), and no browser tag can send the event ID HonestTag uses. So the card asks you to confirm that HonestTag is the only thing sending Snapchat purchase events for the store (turn purchase events off in any other Snapchat integration, Snap Pixel or tool first). A Conversions API token can only send events, so HonestTag does not read Snapchat spend and the Mirror does not show Snapchat claims.
Reddit connects on its Setup card with a conversion access token and the ID of your Reddit Pixel. Both are in Reddit Ads Manager's Events Manager; you generate the token under Conversions API, Generate Access Token. A business admin can create the token, and Reddit says it cannot be retrieved later, so copy it before you leave that page. HonestTag checks the token with Reddit before it saves anything; the check sends no event. Each purchase then goes to that pixel through Reddit's Conversions API as one PURCHASE event with HonestTag's event ID, your Shopify order ID, the order value, the currency, the item count and the products, matched on SHA-256 hashes of the buyer's email and phone and of HonestTag's visitor ID, the Reddit click ID when the visit came from a Reddit ad link, and the IP address and user agent Shopify recorded on the order. Reddit says events must be sent within seven days after they occur.
Reddit removes a duplicate purchase when both copies carry the same conversion ID, and no browser tag can send the event ID HonestTag uses. So the card asks you to confirm that HonestTag is the only thing sending Reddit purchase events for the store (turn purchase events off in the Reddit Pixel or any other Reddit integration first). A conversion access token can only send conversions, so HonestTag does not read Reddit spend and the Mirror does not show Reddit claims.
Google Analytics 4 and Klaviyo
Google Analytics 4 connects on its Setup card with the Measurement ID of your web data stream and a Measurement Protocol API secret you create for HonestTag. Each purchase goes to that stream as a purchase event with your Shopify order ID as the transaction ID, plus a custom event saying whether the buyer was new or returning; each refund goes as a refund event. Google Analytics does not return an error for a wrong API secret, and its validation server does not check the secret, so HonestTag sends one test event, ht_setup_check, when you save, and the card tells you where to look for it. Google Analytics deduplicates purchase events with the same transaction ID; HonestTag's transaction ID is your Shopify order ID, so any other tag sending purchases to the same stream should use the same ID.
Klaviyo connects on its Setup card with a private API key. In Klaviyo, create it under Settings, API keys, Create Private API Key: choose Custom Key and give it read access to Accounts and full access to Events and Profiles (the accounts:read, events:write and profiles:write scopes). A Full Access Key also works. Each purchase goes to Klaviyo as a Placed Order event and each refund as a Refunded Order event, matched on HonestTag's visitor ID or Klaviyo's own click ID. On Truth+ and higher plans HonestTag also sends the order's email address to your Klaviyo account once, unhashed, to find the shopper's existing profile, and keeps only the profile ID Klaviyo returns. Klaviyo confirms that it received an event, not that it finished processing it.
Both count toward your plan's simultaneous-delivery limit, and both rank after your ad platforms, so connecting one on a full plan never takes an ad platform's slot.
Point of sale, subscription renewals and other sales channels
HonestTag sends ad platforms the purchases made on your storefront. An order that came from somewhere else was not brought by an ad click on your storefront, so it is kept out unless you change that on the Sales channels page in the app. Every one of these orders still counts in your store's own numbers.
- Always sent: your online store, and a headless or Hydrogen storefront.
- Kept out: draft orders and orders whose source is iphone or android, unless phone and draft order matching is on for your store (the Sales channels page says so), which sends such a sale only to the platform of the buyer's own first ad click.
- Kept out unless you switch them on: other apps and sales channels, such as a marketplace, a social shop or an app that creates orders. Switch one on only when it sells on your own site, such as Shopify's Buy Button; it is then sent like an online store order.
- Point of sale and subscription renewals are kept out unless you switch them on, and are never sent as a website purchase. They go only to a platform that documents a source for them: Snapchat receives both as
OFFLINE, and Reddit receives point-of-sale orders asPHYSICAL_STORE. Google Ads, Meta, TikTok, Pinterest, Microsoft Advertising, OpenAI Ads, Google Analytics 4 and Klaviyo are not sent them, except on a store where HonestTag has turned on Meta and Google for these orders; the Sales channels page says which applies to your store. There, Meta receives point-of-sale orders asphysical_storeand renewals assystem_generated, once your Meta dataset takes offline events, and Google Ads receives one only when the buyer's email or phone matches their own earlier visit that had a Google ad click in the 90 days before the order, as an offline conversion on that click (an in-store sale asIN_STORE, a renewal asOTHER). A renewal is never sent as a new customer. A later refund on one of these orders is not sent to any platform.
The first order of a subscription is a checkout on your online store, so it is sent like any other purchase. A renewal is created automatically, and HonestTag recognizes it by Shopify's subscription order source, or by the app that created it where the app documents that (Recharge and Bold do). On a store with Meta and Google turned on for these orders, an order another app created is also a renewal when it carries a subscription plan, or a renewal tag Recharge, Skio or Ordergroove documents if the tag is already there when HonestTag reads the order: those apps add their tags after the order is created, so a tag alone is often missing.
The free plan never delivers
The free tier (the Mirror) is read-only. It compares platform-claimed numbers to your store truth and never writes to your ad platforms; conversion delivery is a paid-plan feature.