Privacy

Hashing

In short

Hashing turns data like email addresses into a fixed string using a one-way function (e.g. SHA-256), so the original can't be calculated back from it.

Also known as: SHA-256, hash function, hash value

Hashing is a method that turns any data into a fixed-length string, the hash, using a mathematical one-way function. The same input always produces the same hash, but you can't directly calculate the input back from the hash. In marketing, SHA-256 is the standard for sending customer data to ad platforms.

Example

With SHA-256, the email address max@example.com becomes a 64-character hexadecimal value. Change even a single character, like Max@example.com with a capital M, and you get a completely different hash.

hash = SHA-256(normalized value)

How hashing is used in tracking

Ad platforms like Meta, Google Ads, TikTok and LinkedIn hash their users' email addresses and phone numbers the same way. When you send a hashed email through the Conversion API, the platform can compare it with its own hashes and attribute the conversion to the right account – without the plain-text address ever being sent. Meta measures how well this matching works with Event Match Quality.

Normalizing before hashing

For matching to work, the data must be formatted consistently before hashing:

  • Email: trim spaces, lowercase everything.
  • Phone number: digits only, with country code, no leading zero (15551234567).
  • Names: lowercase, remove spaces.

Hashing in lead generation

In lead generation, you have exactly the data that matters for good matching: email, phone number and name from the form. When you later send deals from your CRM back as offline conversions, they're matched through these hashed values too.

The LeadMetrics Conversion API hashes email, phone number and name with SHA-256 before sending them to Meta, Google Ads, TikTok or LinkedIn.

Common mistakes

  • Not normalized: Capital letters or spaces lead to a different hash – and no match.
  • Double hashed: If an already hashed value is hashed again, it's useless to the platform.
  • Mistaking hashing for anonymization: Hashed customer data is still personal data and needs a legal basis.

Ready for better tracking?

Try LeadMetrics free for 10 days and see which campaigns actually drive revenue.
Start a 10 day trial

Frequently asked questions

No. Encrypted data can be decrypted with the right key. Hashing is a one-way function: you can't directly calculate the original from the hash. You can only check whether a known value produces the same hash.

Related terms

All terms