Building in public. Early access opens to the waiting list first. Join

Server-side conversion tracking for Meta

Every conversion, proved end to end.

wesaw recovers the conversions your pixel loses, sends them to Meta's Conversions API, and shows you the full path of each one: captured, enriched, pushed, deduplicated. Black box out, glass box in.

Shopify and WooCommerce. No credit card, nothing to install yet.

Interface illustration. The product is in build; numbers shown are structure, not results.

[ The leak ]

Your pixel stopped seeing a large share of your buyers. Nobody sent you a notice.

iOS 14.5 made tracking opt-in. Safari's ITP caps first-party cookies at seven days, and at 24 hours when the link carries a click ID. Third-party cookies are done. None of that broke your store, it broke the report you make decisions on. Meta optimises on the signal it receives, so the campaign that looks flat may be the one that pays.

  • 7 days Safari's cap on a first-party cookie set in JavaScript.
  • 24 hours The same cap when the visitor arrives with a click identifier.
  • 04 → 14 parameters Match parameters on a server event, before and after enrichment. Measured on our own dataset.

How it works

Three steps, and you can watch each one.

[01] Capture

Collected on your own domain.

The tracking endpoint runs on a subdomain you own, t.yourstore.com, pointed at us by CNAME. Not a shared vendor domain that browsers and blockers already know. Your first-party context stays first-party.

Visitor t.yourstore.com CNAME wesaw

[02] Enrich

Fourteen match parameters instead of four.

The browser knows the advertising identity: fbc, fbp, external_id. The order webhook knows the person: name, city, postcode, country. Meta deduplicates on event_id, it does not merge the two. So we carry the browser identity through to the server event, hash it server-side, and send one complete event instead of two half ones.

  • em
  • ph
  • client_ip
  • client_ua
  • fn
  • ln
  • ct
  • st
  • zp
  • country
  • db
  • fbc
  • fbp
  • external_id

0414

[03] Verify

Open the event, see the whole trip.

Captured at 14:22:07. Enriched with eleven parameters. Pushed to the Conversions API, HTTP 200, response id fbtr_…. Deduplicated against the browser event on the same event_id. When something fails, you see which step and why, not a silent gap in a chart.

  1. Captured 14:22:07.412
  2. Enriched 14:22:07.588
  3. Pushed 14:22:08.104
  4. Deduplicated 14:22:08.106

[ On the record ]

Four things we refuse to do, and what we do instead.

  • No canvas or WebGL fingerprinting.

    Identity is a first-party identifier issued by your own domain, plus what your store already knows about the order. If a visitor clears it, it is gone. That is the point.

  • No third-party cookies.

    Nothing we set is readable by anyone but your domain.

  • No broad Shopify scopes.

    We ask to read orders, and to place a web pixel. We publish the list and the reason for each one, and we do not ask to edit orders or read your customer history.

  • No personal data leaving your perimeter unhashed.

    Email and phone are normalised and SHA-256 hashed on our servers before anything is sent to Meta. Never in the browser.

We are not making privacy compliance claims on this page. Those need a lawyer's signature, and we will publish them when they have one.

Honestly

Where this sits.

Where this sits. The pixel alone Enterprise attribution suites wesaw
Recovers signal lost to ITP and opt-out No Yes Yes
Per-event proof of what was sent No Partial, buried in exports Yes, one click per event
Collection domain Shared or vendor-owned Varies Your own subdomain, by CNAME
Setup Built in Implementation project, often paid Self-serve, no manual review to wait for
Multi-touch attribution modelling No Yes Not doing it
Built for Everyone Teams with an analyst Merchants spending 3k to 50k a month

If you need multi-touch modelling across five channels, buy one of those suites. We are building the Meta channel done properly, and the proof that it is.

Selling software instead of products?

A trial that converts three weeks after the click is the hardest thing to attribute, and it is the same pipeline. Stripe and Paddle are on the map, behind Shopify. Tell us in the form and we will keep you posted.

Questions

The six things people ask first.

Is this live today?

No. The Meta pipeline is running end to end on our own test store, the merchant dashboard is being built. The waiting list is how you get in first, in order.

What will it cost?

We have not set a price. We will not surprise the waiting list with one either: you will get the number before you get access.

Will it double-count against my pixel?

No. Browser and server events carry the same event_id, which is what Meta deduplicates on. Keeping your pixel is the intended setup, not a conflict.

Do I have to change my consent banner?

No. We read the consent state your storefront has already collected and record it on every event. An explicit refusal stops the event.

What is the CNAME for?

So collection happens on a subdomain of your own store rather than a domain shared with hundreds of other merchants. You add one DNS record; we handle the certificate.

Which platforms?

Meta first, and only Meta until it is excellent. Google and TikTok after. Shopify first on the store side, WooCommerce next.

See what your pixel is missing, first.

Join the waiting list. You will get the build notes as they happen, and access in the order you signed up.

Platform

One email when there is something real to say. Unsubscribe in one click.