HeySignal is server-side tracking that enforces consent in the pipeline and runs itself. No pixels, no leaks, no babysitting.
Declined consent, ad blockers, and Safari's cookie caps mean a large share of your real conversions never reach Google, Meta, and friends. They optimise on what they can see — and bill you on what they can't.
of Google Ads conversions can be invisible on Safari-heavy traffic — attribution cookies die before customers convert.
is all Safari ITP gives a JavaScript-set cookie. 24 hours if it carries a click ID. Your 10-day customer journey doesn't fit.
browsers runs an ad blocker that eats third-party pixels. First-party server-side traffic walks straight past them.
Consent is signed into every event, verified at the EU edge, and enforced per destination. No demo theater. This is the paper trail of one event:
The SDK reads consent from your CMP and signs event, consent state and clock together. HMAC-SHA256. Change one bit of any of them and the signature dies.
Recomputed and compared in constant time, on EU soil, before anything else runs. Five-minute replay window. 24-hour consent freshness. Ambiguity is denial.
One verified event fans out. Every destination re-checks its own consent categories before delivery. "Yes to analytics" is not "yes to everything".
One source of truth on the server. No browser noise, no ad-blocker holes, no lost events.
Consent is HMAC-signed into every event and verified at the edge. Tampering gets a 403, not a warning.
Cryptographic proofTraffic runs through your own subdomain via one CNAME. Ad blockers see first-party content and let it through. Attribution cookies re-issued server-side, past Safari's 7-day cap.
data.yoursite.comExisting Meta, TikTok, Snap, and Pinterest pixels are intercepted and tagged with a shared event ID. Server and browser events dedupe to one.
Zero double-countingPuts a euro figure on the conversions your platforms can't see, and forecasts what a better consent rate would recover. Estimates, honestly labelled.
See what you're missingMirror every event to a test destination and compare before you flip production. Migrate on proof, not hope.
Validate, then switchRuns exclusively on EU infrastructure. PII hashed with SHA-256 at the edge before delivery. Denied traffic never leaves the zone.
GDPR-nativeNative server-side connectors with per-destination consent gates, PII rules, and automatic deduplication.
Measurement Protocol v2 with proxy mode for clean cross-path data.
Conversions API with pixel bridging — browser and server events dedupe automatically.
Data Manager API delivery with extended attribution windows via server-set cookies.
Server-side events with hashed identifiers and shared event-ID dedup.
Conversions API v3 with consent gating per event.
Conversions API v5, PII always hashed in the connector.
Four steps. No engineers harmed. If you can add a DNS record and paste a snippet, you can run server-side tracking.
Add data.yoursite.com to your DNS. That's your first-party tracking domain.
One ~900-byte script in your <head>. It patches pixel queues before they load.
The SDK detects your banner and listens for consent events. Automatically.
Fire a page view, watch it land in GA4 real-time. Done. Page views and pixel bridging need zero rules.
This is the dashboard as it runs today: the gate in the interface, delivery and consent per destination, failures separated from blocks. Blocked is by design. Failed is red. Nothing else shouts.
| Destination | Sent | No consent | Failed | Success | p95 latency | Status |
|---|---|---|---|---|---|---|
| Google Analytics 4 | 8,412 | 1,188 | 96 | 98.9% | 212 ms | Healthy |
| Meta Conversions | 6,930 | 1,014 | 142 | 98.0% | 348 ms | Token expires in 3d |
| TikTok Events | 4,660 | 692 | 10 | 99.8% | 201 ms | Healthy |
| 1,080 | 94 | 0 | 100% | 188 ms | Shadow mode |
The Consent Gap Dashboard shows what your platforms see, what they miss, and what your ad spend really returns — computed from anonymous, differential-privacy-protected counts. No personal data, ever.
Share of visitors who accepted marketing consent — trended against last period.
Estimated revenue tied to declined visitors, invisible to your platforms.
Google reports 4.00×. Adjusted for the consent gap, your real return is higher — and provable.
Modelled gain per platform if you lift consent by 10% — after honest discounts.
No. HeySignal is its own pipeline: SDK or GTM proxy in, consent-verified edge in the middle, direct platform APIs out. You can keep GTM through our proxy, or skip GTM entirely and use tracking rules. Either way, consent enforcement is ours, not a container setting.
CookieFirst and iubenda have first-class adapters today, and a custom hook covers any other CMP that exposes consent state. The edge also reads supported consent cookies server-side for proxy decisions.
They are refused at the edge with a typed reason, before any processing or forwarding. Denied events feed anonymous, differentially private Consent Gap statistics: no identifiers, hour-rounded timestamps, nothing personal. We never "recover" or quietly forward them.
No. We extend identifier lifetimes server-side only while the matching consent is granted. A cookie a user cleared without marketing consent stays gone.
On European infrastructure only: Bunny.net edge (EU points of presence) and OVHcloud Postgres and Valkey in France and Germany.
Early access is open now and pricing ships with general availability. Talk to us and we'll be straight with you.
One CNAME, one snippet, and every consented conversion reaches every platform. Automatically.
HEYSIGNAL ✱ A TEAM.BLUE BRAND ✱ EU-SOVEREIGN INFRASTRUCTURE