HeySignal
A team.blue BRAND
Server-side Consent aware Fully automated

Track
everything.
Ask first.

HeySignal is server-side tracking that enforces consent in the pipeline and runs itself. No pixels, no leaks, no babysitting.

✱ LIVE IN ~10 MINUTES ✱ ONE CNAME ✱ ONE SNIPPET ✱ ZERO CONFIG
The pipeline
01Captureevery event, server-side
02Consentenforced in the stream
03Enrichfirst-party context
04Deliverto every destination
Signals delivered
3,118,472 ▲ 21.4%
CONSENT RATE 94.2% ✓ — AUTOMATION 100%
The problem

Your ad platforms report half the truth.

Declined consent, ad blockers, and Safari's cookie caps mean a large share of your real conversions never reach Google, Meta, and friends. They optimise on what they can see — and bill you on what they can't.

20–40%

of Google Ads conversions can be invisible on Safari-heavy traffic — attribution cookies die before customers convert.

7 days

is all Safari ITP gives a JavaScript-set cookie. 24 hours if it carries a click ID. Your 10-day customer journey doesn't fit.

1 in 3

browsers runs an ad blocker that eats third-party pixels. First-party server-side traffic walks straight past them.

How it works

One gate. Three moves.

Consent is signed into every event, verified at the EU edge, and enforced per destination. No demo theater. This is the paper trail of one event:

01 · Signed at the source

One sealed unit

The SDK reads consent from your CMP and signs event, consent state and clock together. HMAC-SHA256. Change one bit of any of them and the signature dies.

eventpurchase
consentanalytics · marketing
clock2026-07-21T10:32:04Z
signaturehmac-sha256 · 8f3a2c…41e1
SEALED IN THE BROWSER
02 · Verified at the edge

The verdict

Recomputed and compared in constant time, on EU soil, before anything else runs. Five-minute replay window. 24-hour consent freshness. Ambiguity is denial.

200 Proof verified.
Consent proof ID persisted to the audit log.
403 No valid proof. Dropped.
SIGNATURE_INVALID · STALE_CONSENT · CONSENT_MISSING
03 · Delivered where allowed

The delivery record

One verified event fans out. Every destination re-checks its own consent categories before delivery. "Yes to analytics" is not "yes to everything".

GA4 delivered · analytics
META CAPI withheld · needs marketing
TIKTOK withheld · needs marketing
WEBHOOK delivered · signed
DEDUPLICATED · RETRIED · LOGGED
»■ = CAPTURED. CONSENTED. DELIVERED. DONE.
Built in

Everything the browser
can't be trusted with.

One source of truth on the server. No browser noise, no ad-blocker holes, no lost events.

Destinations

Every platform. A single stream.

Native server-side connectors with per-destination consent gates, PII rules, and automatic deduplication.

Google Analytics 4LIVE

Measurement Protocol v2 with proxy mode for clean cross-path data.

Meta CAPILIVE

Conversions API with pixel bridging — browser and server events dedupe automatically.

Google AdsLIVE

Data Manager API delivery with extended attribution windows via server-set cookies.

TikTok Events APILIVE

Server-side events with hashed identifiers and shared event-ID dedup.

Snapchat CAPILIVE

Conversions API v3 with consent gating per event.

Pinterest CAPILIVE

Conversions API v5, PII always hashed in the connector.

ALSO SPEAKS: SEGMENTRUDDERSTACKWEBHOOK
Setup

Live in ~10 minutes.

Four steps. No engineers harmed. If you can add a DNS record and paste a snippet, you can run server-side tracking.

012–5 MIN

Point one CNAME

Add data.yoursite.com to your DNS. That's your first-party tracking domain.

021–2 MIN

Paste the snippet

One ~900-byte script in your <head>. It patches pixel queues before they load.

031 MIN

Connect your CMP

The SDK detects your banner and listens for consent events. Automatically.

041–2 MIN

Verify & go

Fire a page view, watch it land in GA4 real-time. Done. Page views and pixel bridging need zero rules.

Guides for: Shopify WordPress WooCommerce Google Tag Manager Custom HTML / SPA
The product

Already a product. Not a promise.

This is the dashboard as it runs today: the gate in the interface, delivery and consent per destination, failures separated from blocks. Blocked is by design. Failed is red. Nothing else shouts.

app.heysignal.com / sites / demo.heysignal.com / analytics
✱ SCREENS FROM THE CURRENT BUILD, DEMO DATA ✱ THIS TOOL EXISTS TODAY ✱ SEE IT LIVE ON A DEMO →
The receipts

Numbers, not vibes.

The Consent Gap Dashboard shows what your platforms see, what they miss, and what your ad spend really returns — computed from anonymous, differential-privacy-protected counts. No personal data, ever.

Consent rate
62%

Share of visitors who accepted marketing consent — trended against last period.

Revenue gap (est.)
€10,000

Estimated revenue tied to declined visitors, invisible to your platforms.

True ROAS
4.35×

Google reports 4.00×. Adjusted for the consent gap, your real return is higher — and provable.

Recovery forecast
+€350/mo

Modelled gain per platform if you lift consent by 10% — after honest discounts.

ⓘ ESTIMATES, NOT ACCOUNTING — BUILT FROM ANONYMOUS HOURLY COUNTS + A DELIBERATELY CONSERVATIVE 35% BEHAVIOURAL DISCOUNT. DIRECTIONALLY RIGHT, PRIVACY-SAFE.
FAQ

Questions people actually ask.

Is HeySignal a server-side GTM host?

No. HeySignal is its own pipeline: SDK or GTM proxy in, consent-verified edge in the middle, direct platform APIs out. You can keep GTM through our proxy, or skip GTM entirely and use tracking rules. Either way, consent enforcement is ours, not a container setting.

Which CMPs does it work with?

CookieFirst and iubenda have first-class adapters today, and a custom hook covers any other CMP that exposes consent state. The edge also reads supported consent cookies server-side for proxy decisions.

What happens to events without consent?

They are refused at the edge with a typed reason, before any processing or forwarding. Denied events feed anonymous, differentially private Consent Gap statistics: no identifiers, hour-rounded timestamps, nothing personal. We never "recover" or quietly forward them.

Do you restore deleted cookies like some competitors?

No. We extend identifier lifetimes server-side only while the matching consent is granted. A cookie a user cleared without marketing consent stays gone.

Where does my data live?

On European infrastructure only: Bunny.net edge (EU points of presence) and OVHcloud Postgres and Valkey in France and Germany.

What does it cost?

Early access is open now and pricing ships with general availability. Talk to us and we'll be straight with you.

Stop reporting
half your results.

One CNAME, one snippet, and every consented conversion reaches every platform. Automatically.

HEYSIGNAL ✱ A TEAM.BLUE BRAND ✱ EU-SOVEREIGN INFRASTRUCTURE