Ad pixels & conversions
Running ads on Google, Meta (Facebook and Instagram) or TikTok? Send them the moments that matter on stoneswap.studio — new sign-ups, leads, purchases and finished designs — so each platform can measure your campaigns and optimise for the people who actually use your visualizer. Everything is set up by your team in the portal: Developers → Analytics & pixels. No code on your side.
Two ways in — pick one per platform
| Server-side (recommended) | In the browser | |
|---|---|---|
| How it works | Our server sends each conversion straight to your ad account (GA4 Measurement Protocol, Meta Conversions API, TikTok Events API) | The platform’s own tag runs on your visitors’ devices |
| Cookies | None — nothing runs in the visitor’s browser | Yes — the platform’s cookies (_ga, _fbp, _ttp and others) |
| Consent notice | Never | A small Allow / Decline bar for visitors in the consent zone (or everyone, if you choose) |
| What is measured | The four conversions | Page views and the four conversions |
| Retargeting audiences of site visitors | No | Yes |
| Who is counted | Visitors outside the consent zone, and customers who ticked the opt-in — never a browser that sends Global Privacy Control | Visitors who chose Allow (in the zone) or did not opt out (elsewhere) — never a browser that sends Global Privacy Control |
| Matching to a person | IP address and browser, plus hashed email and phone when your Contact details rule allows | The platform’s cookies |
| Ad blockers and browser tracking protection | Not affected | Can block or shorten it |
| Google Ads click attribution | No — GA4 reports only (see Google Ads below) | Yes, with the Google Ads tag |
Pick server-side unless you specifically need retargeting audiences built from site visitors. Each platform has exactly one mode — Off, Server-side or In the browser — so a conversion is never counted twice.
The four conversions
Each has a switch on the Conversions card (all on by default); a switch applies to both ways in. This is what each platform calls them:
| Moment | Meta | TikTok | |
|---|---|---|---|
| New sign-upAn account becomes active (email verified, or Google / Facebook sign-in). Once per person. | sign_up |
CompleteRegistration |
CompleteRegistration |
| Lead or formAn estimate or dealer request, the sign-up gate’s form, or the free-credit project form. | generate_lead |
Lead |
Lead |
| PurchaseA customer buys a design pack on your visualizer — with the amount and currency. | purchase |
Purchase |
Purchase |
| Design completedA design made on your website is ready — with the products in it. | design_completed |
CustomizeProduct |
ViewContent |
Meta’s CustomizeProduct and TikTok’s ViewContent are standard events, so both platforms
can optimise on a finished design. Server-side, someone who fills in the sign-up form produces a lead at once and
a sign-up when their account becomes active. Never sent: anything that happens on an in-store kiosk, and designs
made through the Render Engine API. The moments above are the server-side ones; in the browser a few are counted
differently (see In-the-browser set-up).
Server-side set-up
Sign in at stoneswap.studio/portal as an owner or admin and open Developers → Analytics &
pixels. Tokens and secrets are stored encrypted; after saving you only ever see their last four characters.
Paste a new one to replace it, or press Remove to clear it. Choosing Off pauses a platform and
keeps its IDs and token, so you can turn it back on later.
Google (GA4)
- Find your Measurement IDIn Google Analytics: Admin → Data streams, open the web
stream for stoneswap.studio (create one if you have none). Copy the Measurement ID — it starts with
G-. - Create an API secretOn the same stream page: Measurement Protocol API secrets → Create. Name it (for example “StoneSwap visualizer”) and copy the secret value.
- Paste both in the portalOn the Google card choose Server-side, paste the Measurement ID and the API secret, and press Save changes.
- Send a test eventWe send the test to Google’s validation server, which checks the event’s shape and says so. That test is never recorded, so it does not appear in GA4, and Google cannot tell us whether the secret is right. The secret is confirmed when your first real conversion appears in GA4 → Reports → Realtime. Until then, Delivered in Recent conversions only means Google accepted the request — Google answers the same way when the secret is wrong.
- Mark the key eventsOnce the first ones arrive, mark
sign_up,generate_lead,purchaseanddesign_completedas key events in GA4 (Admin → Data display → Events). - Contact detailsTo let Google use hashed email and phone, switch on Admin → Data collection → User-provided data collection in GA4 — otherwise Google ignores them.
Meta (Conversions API)
- Find your Pixel IDIn Meta Events Manager open Data sources and select your pixel (dataset). The Pixel ID is the long number shown with it.
- Generate an access tokenOn the pixel: Settings → Conversions API → Set up manually → Generate access token. You need developer access to the business; Meta creates the system user for you. Copy the token.
- Paste both in the portalOn the Meta card choose Server-side, paste the Pixel ID and the access token, and press Save changes.
- Test with a test codeIn Events Manager open Test events and copy the test code
(
TESTfollowed by digits). Paste it into Test event code, save, and press Send a test event — it appears on Meta’s Test events tab. Without a test code, the test counts as a real Lead in your reports. Clear the code when you are done: while it is set, every event goes to the Test events tab. - Verify your domainIn Meta Business settings, Brand safety → Domains, add stoneswap.studio and verify it with the DNS TXT record Meta gives you. Events name the page they happened on, and Meta expects that domain to be verified.
TikTok (Events API)
- Find your pixel codeIn TikTok Ads Manager: Tools → Events → Web events. The pixel
code is shown under your pixel’s name — usually 20 capital letters and digits, like
CUSG5HBC77UD11VVRQEG. - Generate an access tokenOpen the pixel (Manage), go to Settings and press Generate Access Token. You need Admin or Operator access to the ad account; the token works only for that account’s pixels.
- Paste both in the portalOn the TikTok card choose Server-side, paste the pixel code and the access token, and press Save changes.
- Test with a test codeOn the pixel open Test events, copy the test event code, paste it into Test event code, save, and press Send a test event. Clear the code when you are done.
Contact details
Contact details help a platform match a conversion to a person. They are hashed (scrambled) with SHA-256 after each platform’s own clean-up rules, and each platform receives a different set:
- Meta: email, phone, first and last name, city, region, postal code and country — all hashed.
- TikTok: email, phone, first and last name and postal code hashed; city, region and country in plain lower case (TikTok’s rule).
- Google: email and phone, hashed.
Each server-side card has a Contact details choice:
| Choice | What it does |
|---|---|
| Only with the customer’s opt-in Recommended | Contact details go only for customers who ticked the optional box on your sign-up gate. While this is on, the box’s sentence gains an advertising clause (below). |
| Always | Contact details go with every conversion that is sent. For brands whose lawyer says so. |
| Never | No contact details: only an anonymous customer id, the IP address and the browser — plus, for Meta and TikTok, the address of the page. |
Canada’s privacy regulator has said that sharing customers’ email addresses with an ad platform needs their express opt-in, and European law says the same — which is why the opt-in is the default. With it, the gate’s optional tick reads:
“Also send me news and offers from StoneSwap and stoneswap.studio, and let StoneSwap measure its advertising with partners such as Meta, TikTok and Google using my contact details (e-mail, phone, name and area). You can turn this off any time with the Unsubscribe link in our e-mails.”
The box is never pre-ticked. Only a tick given with that sentence counts — an older tick for news and offers alone does not unlock contact details, and a later “no” on any form withdraws it.
What we send — and what we never send
- Every conversion: the event name and time, an event id (the same on every retry, so the platform never counts it twice), the visitor’s IP address and browser, as the platforms require, and an anonymous customer id — hashed for Meta and TikTok; for Google, our opaque customer id and a stable pseudonymous client id. Meta and TikTok also get the address of the page it happened on (no query string).
- Purchases add the amount, currency, order id and the pack bought. Designs add the products in them (catalog ids, names and brand). Leads tell Google which form it was.
- Contact details, only as your Contact details choice allows — the per-platform list is above.
- Never: a readable email, phone or name, photos or designs, project details, budgets or street addresses.
- Meta always receives Limited Data Use (Meta applies it where US state privacy laws require). Google receives, for visitors from the European Economic Area, the UK and Switzerland, a consent signal: ad user data granted only for customers who opted in, ad personalisation always denied.
Who is sent — the consent zone
Server-side conversions go out for:
- visitors outside the consent zone, and
- customers who ticked the opt-in with the advertising clause, wherever they are —
- and never when the browser sent the Global Privacy Control signal (we remember it for that customer).
The consent zone is the European Economic Area (the EU plus Iceland, Liechtenstein and Norway), the United
Kingdom, Switzerland and Quebec — plus any visitor whose location we cannot tell. The location comes from the
visitor’s connection when they last used your visitor pages; a conversion with no such visit on record goes out
only for a customer who opted in. Anything held back is still listed in Recent conversions as
Skipped with the reason — consent zone, no opt-in, location unknown, no opt-in,
gpc or no browser context — so you can see why a number is lower. The Ask everyone setting of the
browser notice does not change this rule.
When it arrives, and the log
- Conversions go out within about a minute. A failure is retried 1 min, 5 min, 30 min, 2 h and 6 h later (6 attempts), then marked failed. A conversion older than 7 days is never sent.
- A conversion with no visit on record is Skipped for every platform
(
no browser context) unless the customer opted in. For a customer who opted in it is sent, except to Meta: Meta refuses website events that name no browser, so Meta alone marks it Failed asno browser context— typically when Meta was switched on after the customer’s last visit. - The Recent conversions card shows the last deliveries: when, platform, event, status, the platform’s response code and the error. Nothing about the customer is shown there.
| Error | What to do |
|---|---|
token rejected (190) (Meta) · token rejected (40104) (TikTok) | The token expired or was revoked. Generate a new one and paste it. |
permission denied (Meta) · no permission for this pixel (40001) (TikTok) | The token belongs to another business or ad account than the pixel. Generate it from the pixel’s own account. |
vendor not ready: missing … | An ID or token was removed after the conversion was queued. Paste it again. |
vendor not in server mode any more (paused) | The platform was switched off or to the browser before the conversion went out. Nothing to fix. |
too old | The conversion waited more than 7 days. Platforms refuse old events. |
token rejected (HTTP 401) or (HTTP 403) (TikTok) | TikTok refused the token without saying why. Generate a new token from the pixel and paste it. |
secret unreadable — save the token again | The stored token or API secret could not be opened. Paste it again and press Save changes. |
Meta rejected the event HTTP 400 (…) · TikTok rejected the event data (40002) | The platform refused this event’s data; retrying cannot help. Send the error, with Meta’s fbtrace code, to [email protected]. |
no browser context (Meta, failed) | A customer who opted in but has no visit on record, which Meta refuses (above). Nothing to fix. |
stored payload unreadable | The queued conversion could not be read back, so it was not sent. Tell [email protected] if you see it. |
Google Ads
With server-side Google: mark the events as key events in GA4, then import them into Google Ads (Goals → Conversions → New conversion action → Import → Google Analytics 4 properties). Be aware of the limit Google documents: events sent from a server are counted and reported, but Google Ads cannot tie them to an ad click, because that link lives in the browser tag’s cookies. GA4 also shows their traffic source as (not set). A cookie-free way to credit Google Ads clicks exists through Google’s Data Manager API; we have not built it yet — ask us if you need it.
With Google in the browser: add your Google Ads tag (AW- followed by
digits) and, for each conversion you want in Google Ads, its conversion label. Find both in Google Ads:
open the conversion action, then Tag setup → Install the tag yourself. The event snippet shows
send_to: 'AW-123456789/AbC-D_efG-h12_34-567' — the part after the slash is the label.
In-the-browser set-up
Choosing In the browser first opens a warning, every time: the tag puts cookies on your visitors’ devices, visitors in the consent zone see an Allow / Decline bar, and a visitor who declines is never measured. Choose Keep it server-side or Turn on anyway. Then:
- Google: the Measurement ID (
G-…), and optionally the Google Ads tag and the four conversion labels. With GA4 alone, leave Google signals off in GA4 — or add the Google Ads tag — otherwise Google’s advertising requests are blocked by the site’s security policy (harmless, but noisy). - Meta: the Pixel ID. We load the pixel with automatic event collection off and without the no-script image, so nothing reaches Meta before a visitor allows it.
- TikTok: the pixel code.
The tags run only on the pages your customers use — the home page and dashboard, the design result page and shared designs. They never run on an in-store kiosk or the phone photo uploader a shopper opens from its QR code, nor on the portal, checkout, legal pages or these developer pages. They record page views, and the conversions fire from the browser under the names in the table above (Google Ads also gets its labelled conversion). In the browser the moments are what the visitor does on the page, so they differ from the server-side ones:
- New sign-up fires when the visitor sends the sign-up form — before their email is verified, and again if they send the form again.
- Lead or form fires for the estimate, find-a-dealer and free-credit project forms. The sign-up form counts as a sign-up only, not also as a lead.
- Purchase carries the amount and currency when the pack is paid on the visualizer’s own payment form. A purchase finished on Stripe’s hosted payment page is counted without an amount.
- Design completed fires when the result page shows the finished design.
The consent notice
When any tag that needs consent is on, your visitor pages show one compact bar at the bottom of the screen, for all of them together:
StoneSwap uses Google, Meta and TikTok to see how the studio is used and to measure its ads. Allow it? — Privacy
Two equal buttons: Decline · Allow. (The bar names only the platforms you turned on.)
- Who sees it — the Consent notice card: Only where the law requires it (recommended) shows it to visitors in the consent zone (the European Economic Area, the UK, Switzerland, Quebec and unknown locations); elsewhere the tags run without a bar. Ask everyone shows it to every visitor.
- Nothing loads before a choice. Ignoring the bar means nothing loads; Decline is as easy as Allow.
- Global Privacy Control counts as Decline, everywhere: no bar, nothing loads.
- Privacy choices — a link in the page footer (on the dashboard, in the menu) — shows the visitor’s current choice and lets them change it at any time.
- The choice is remembered for 180 days, then asked again. Adding a platform or changing an ID asks again.
Your privacy policy
The privacy page on stoneswap.studio updates itself: it names the platforms you turned on, what they receive and how to opt out. If you use your own legal text instead, add them yourself. The platforms’ terms require it, and ask for these links: Google — “How Google uses information from sites or apps that use our services” (policies.google.com/technologies/partner-sites); Meta — facebook.com/privacy/policy; TikTok — tiktok.com/legal/privacy-policy. The industry opt-out pages are optout.aboutads.info and youronlinechoices.eu. The platforms’ terms also rule out sending data about children or about health or finances.
This page is a summary of research, not legal advice. If your lawyer wants every visitor asked, choose Ask everyone; if they want no contact details shared, choose Never.
Questions
Why does Meta count fewer purchases than my payments?
Conversions are held back for visitors in the consent zone who did not opt in, and for browsers that send Global Privacy Control; kiosk activity is never sent; events older than 7 days are dropped; and a test code left in place sends everything to Meta’s Test events tab. Recent conversions shows each one with its status and reason.
Can I run a platform both ways?
No — one mode per platform. Running both would count every conversion twice.
What about iPhones and ad blockers?
Server-side conversions do not depend on cookies or on the visitor’s browser, so Safari’s tracking prevention and ad blockers do not stop them. Tags in the browser are limited by both.
Where does Microsoft Clarity fit?
Clarity is not an ad platform — it shows how people use your visualizer, and it can run without cookies. See Microsoft Clarity.
Questions: [email protected]. The StoneSwap Design Studio is operated by StoneSwap Inc. · Hamilton, Ontario. Google, Meta and TikTok are trademarks of their owners.