Privacy-first lead tracking: which data is enough under GDPR and CCPA
For businesses and agencies that want reliable lead attribution without building a database of personal data. Learn which marks are actually needed to tie a lead to a campaign and report results to Google and Meta, and where the honest limits are.
What it does
Many lead tracking setups collect everything “just in case”: names, phone numbers, emails, IP addresses, sometimes a browser fingerprint. Every extra field is a liability. It has to be protected, disclosed in the privacy policy, handed over or deleted on request, and explained if it leaks. Europe's GDPR makes data minimization a core principle: personal data should be adequate, relevant and limited to what is necessary for the purpose. California's CCPA, as amended by the CPRA, likewise expects collection to be reasonably necessary and proportionate. Ask not what you could collect, but what the purpose requires.
For advertising measurement the purpose is narrow: know which campaign produced a lead, and tell the ad platform whether that lead turned out well. A short list of technical marks covers it: the channel (Telegram, WhatsApp, call, email or form), the page and its language, the time, the UTM tags, Google's click IDs (gclid, gbraid, wbraid) and Meta's click marks (fbc, fbp). With these you can calculate cost per lead, per interview and per hire by campaign, and send results to Google by gclid and to Meta by fbc. The candidate's name and number already live in the chat or call log; copying them into analytics adds risk without adding insight.
Be honest about the limits. Under GDPR, online identifiers such as click IDs and cookie values can still be personal data, so a minimal setup reduces risk but is not automatically anonymous. Cookie and consent rules for your site and for ad pixels still apply where you operate, your privacy policy should describe the tracking, and data should be kept only as long as it is useful. A retention period that matches the longest conversion window you rely on is a sensible default. This is general guidance, not legal advice; check the rules for your jurisdiction with a qualified adviser.
AdAce Ads was built around this minimal set. The lead tracking script stores only technical marks: the channel, the page address and page language, UTM tags, Google click IDs (gclid, gbraid, wbraid) and Meta click marks (fbc, fbp). It does not store names, phone numbers, emails, IP addresses or a browser fingerprint, and leads are deleted after 90 days. When a lead is marked “interview” or “hired”, Google receives an offline click conversion by gclid, and Meta receives an Interview or Hire server event with the fbc click mark and a hashed lead id, never personal data. The workspace emergency switch pauses sending.
There is a trade-off, and it is worth stating plainly. Ad platforms match events better when you send hashed emails or phone numbers, which is how Meta's advanced matching and Google's enhanced conversions work. A setup based on click marks alone has a lower match rate, and leads without a click ID cannot be credited to an ad at all. For many lead businesses that is a fair price: you still get campaign-level costs and quality feedback for ad clicks, and you hold far less data that could be lost, requested or misused.
Why it helps
- Attribution and quality feedback without a database of personal data.
- Less to protect, disclose and delete on request.
- Lead records are deleted automatically after 90 days.
- Conversions sent to Google and Meta carry click marks, not contact details.
How to set it up
- List what your current lead tracking stores and remove the fields the purpose does not need.
- Install the lead tracking script from “Analytics” → “Leads” on the client's site.
- Update the site's privacy policy and consent settings to describe the tracking, following local rules.
- Mark lead statuses in Telegram or in the service within the 90-day retention period.
- Remember the emergency switch: it pauses sending conversions to Google and Meta for the whole workspace.
Good to know
- Click IDs and cookie values can count as personal data under GDPR; minimization lowers risk but does not replace consent where consent is required.
- Matching by click marks alone gives a lower match rate than hashed contact details.
- This article is general information, not legal advice.



Try it on your own accounts
Create a workspace, connect Google or Meta in a couple of clicks and see your accounts clearly. Changes follow your approvals or the policy you configure.
Create your workspace