The site tag
Last updated September 28, 2026.
The site tag is a small script you add to your website. It remembers which ad or campaign brought a visitor. When that visitor buys or signs up, it sends us one record of the conversion, so your ad platforms learn which ads actually produce customers. It sends nothing while someone is only browsing.
This page is for the owner of a website deciding whether to install it. It covers what the tag does, what it collects, the cookies it sets, where the data goes, and what you need to tell your visitors.
What it does
On every page. The tag checks the page address for ad-click ids (the gclid, gbraid and wbraid Google adds, the fbclid Meta adds, the rdt_cid Reddit adds) and for campaign tags (utm_source, utm_campaign and the rest). It keeps what it finds in cookies on your own site, so an id that arrived on the first page is still there on the thank-you page. Nothing is sent at this point.
On a conversion. When a visitor buys, signs up, or submits a form you have chosen, the tag sends one record to us. If the conversion is a form, it also writes the same details into the form as hidden fields, so they reach your CRM along with the submission.
What a conversion record contains
- An event id, so the same conversion is never counted twice.
- The ad-click ids and campaign tags from the visitor's first visit and from their most recent one.
- The address of the page they first landed on and the page they converted on, with the query string removed.
- The email address and phone number the visitor entered, as SHA-256 hashes made in their browser. The plain email and phone never leave the page. On a page without https, where the browser cannot hash, they are left out.
- The value, currency and order id, if your site passes them.
- A random visitor id, kept in a cookie on your site. It is not tied to a name.
Our server also records the visitor's IP address and browser type from the request itself, because Meta and Google use them to match a conversion to an ad.
What it never does
- It sends nothing on a page view. It does not record browsing, clicks, scrolling or sessions.
- It never sends a plain email address or phone number.
- On a form, it reads only the email and phone fields, and only on forms you have turned on.
- It sets no third-party cookies and does no fingerprinting. Its cookies belong to your site and no other site can read them.
- It does not follow visitors to other websites.
- It does nothing at all for a visitor whose browser sends Global Privacy Control, or who has opted out on your site (see below).
Cookies
All first-party, set on your own domain, SameSite=Lax, secure on https.
Where the data goes
Conversion records are stored by Lee Flannery Consulting LLC, in a database hosted by Supabase. When you connect Meta, Google Ads or Google Analytics, we send each conversion to that platform. Depending on what the platform accepts, it carries the hashed email and phone, the ad-click ids, the IP address and the browser type. We send nothing to a platform you have not connected.
We process this data on your behalf and only for your account. We never use it for another client and never use it to train AI models. Records that never match one of your customers are deleted after 90 days. The rest are kept while we work together and for 90 days after, as set out in our privacy policy.
How visitors opt out
If a visitor's browser sends Global Privacy Control, the tag sets no cookies, adds no hidden fields and sends nothing. California treats that signal as a request not to sell or share personal data.
If your site has its own "Do not sell or share my personal information" link, have it call:
growth.optOut()
That deletes the tag's _gp_ cookies and keeps it off for that visitor for a year. growth.optIn() turns it back on, unless their browser sends Global Privacy Control.
What to tell your visitors
You are responsible for telling your visitors about the tag, as you would for any analytics or ad pixel. At a minimum, your privacy policy should say that you use a first-party script to measure which ads lead to purchases or sign-ups, and that hashed contact details from a conversion are shared with the ad platforms you use. If you have visitors in the EU or UK, cookies like these usually need consent before they are set, so load the tag through your consent tool. Check the wording with your own counsel.
Removing it
Delete the script tag, or the tag in Google Tag Manager, and it stops at once. Its cookies expire on their own within 90 days. To have the records it collected deleted, write to hello@tendgrowth.com and we will delete them within seven days.