Menu

Pixels, server events, and consent in a raise

Browser and server tracking both miss part of an offering. Measure the right events, respect consent, and reconcile to the intermediary's records.

By 5 min read

A browser pixel sees some of a raise. A server event can fill some gaps. Neither tells the whole story or overrides a visitor's privacy choice. The campaign needs a clean event plan, consent that actually governs collection, and a financial total from the intermediary. Without those three, an ad dashboard is an estimate that can look more certain than it is.

We are marketers, not privacy or securities counsel. The rules that apply depend on where visitors live, what data is collected, which parties receive it, and the offering itself. Have counsel review the implementation before the page goes live. The SEC legends on a testing-the-waters or live offering page are a separate obligation from notice and consent about tracking.

What each layer can see

A browser pixel runs in a visitor's browser. It can report a page view, form submission, or other action on a page where it is installed, subject to the person's settings and the site's consent controls. It can miss an event when a browser blocks tracking, a visitor declines consent, a page closes early, or the action happens on the intermediary's site. An issuer cannot assume its code runs on a portal page.

A server event is sent by a system the issuer or intermediary controls. It can report that a lead was stored or an investment status changed without requiring a confirmation page to load in the browser. It still needs a lawful basis and permission to share the data. It cannot recover a visitor's unobserved ad click or turn an unmatched investor into a known campaign conversion. “Server-side” means a different delivery path, not a way around consent.

The FTC has warned that pixels can disclose sensitive information to third parties. An investment interest or transaction is financial information. Build the measurement plan so the ad system gets the minimum event needed for campaign decisions, not the investor file.

Name the events before mapping them

Use three stages, each with one clear definition:

  • Interest recorded. Someone submitted a nonbinding testing-the-waters indication. Capture its source and timestamp. Its indicated amount is an expression of interest, not revenue.
  • Investment started. Someone entered the intermediary's transaction flow. Capture this only if the intermediary can expose it reliably. A click on “Invest” on the issuer's page is a click, not a started investment.
  • Investment completed. The intermediary reached the agreed transaction state. Define whether that means committed, funded, or final after the cancellation period, and reflect later changes.

Keep the event name, time, amount, currency, and unique event ID consistent across systems. If the same event is sent from the browser and the server, use the same ID so it can be deduplicated. Otherwise a single reservation can become two “conversions.” For the portal boundary, see cross-domain-tracking-for-a-raise.

Do not send an individual's investment amount to an ad network merely because the event format has a value field. Decide whether an aggregate or limited value is enough, whether the destination permits it, and whether privacy counsel approves it. Hashing an email does not make its sharing automatically safe or anonymous. A hashed identifier may still be used to match a person. Keep names, contact details, bank information, identity documents, and investor eligibility information out of advertising events unless a specific lawful need has been established.

A consent banner is not a design decoration. It decides when nonessential tracking may run and records the choice. A visitor who declines may still reserve or invest, but the ad system may not receive an event for that action. The campaign must expect a gap between platform-reported conversions and the intermediary's records. Turning the pixel on before consent and hiding the explanation behind a banner does not cure the gap legally.

There is no single “US crowdfunding cookie banner” rule. State privacy laws, federal rules about unfair or deceptive practices, and laws that apply to international visitors can impose different notice, choice, and consent duties. For example, the UK's information regulator explains that nonessential cookies generally require informed consent before they are set. Counsel should decide the regions and uses that need opt-in, opt-out, or other controls. Keep the choice record with the version of the notice the visitor saw.

The securities legend answers a different question: what the issuer may say about an offer and whether money can be accepted. The privacy notice answers who collects the person's data and what they do with it. One cannot substitute for the other. See who-regulates-equity-crowdfunding for the wider set of regulators involved in a raise.

Reconcile before optimizing

At least weekly, compare the intermediary's investment ledger with the issuer's CRM and the ad platform's event count. Separate commitments, funded investments, cancellations, duplicates, and unattributed investors. Then calculate cost per completed investment from the campaign's actual spend and the intermediary's agreed completed count. Use platform data to compare creative and audience directionally, with the tracking limitations shown.

This matters when the dashboard says ten conversions but the portal has seven investments. Possible causes include duplicate browser and server events, a thank-you page firing on an incomplete commitment, attribution windows, consent gaps, cross-device behavior, or timing. Do not solve the discrepancy by picking the higher number. Trace sample IDs to the source.

The tech partner should be able to explain every event field and where it goes. The intermediary should be able to say which status it reports and how corrections arrive. Counsel should see the actual data flow and consent text, not just a list of vendors. The lead-funnel gives the campaign stages; the job here is to count each stage honestly.

FAQ

It depends on the tracking used and the laws that apply to your visitors. Nonessential advertising technologies may require consent in some places and other privacy choices elsewhere. Have privacy counsel review the actual page, scripts, notice, and visitor geography.

What is server-side tracking?

It is an event sent from a controlled server to another system, such as an ad destination. It can reduce dependence on a browser page view, but it still needs accurate event definitions, permission, and consent where required.

Why do my ad platform and portal report different numbers?

They count different events on different clocks. The ad platform may model or deduplicate attributed conversions; the intermediary records transaction states and later cancellations. Reconcile to the intermediary's ledger for the financial total.

Can I send investor data to ad platforms?

Do not send investor-identifying or sensitive financial data by default. Minimize fields and get legal review of the purpose, consent, contracts, and destination. Hashing an identifier does not remove those duties.

What conversion event should a raise optimize on?

Completed investments, once there are enough reliable events to make that practical. Before then, earlier stages can guide testing, but label them as reservations or starts. Never report them as money raised.

technologyanalyticscompliance

Published .

Written by

Bryce W Jones

Founder and CEO of HookVerb, an equity crowdfunding consultancy in San Diego. Marketer and engineer, more than a decade selling consumer products and securities to the public online; previously Head of Digital Technology at BOXABL.

More posts by Bryce

Related reading

  • Post

    Cross-domain tracking for a raise: follow the investment, not the click

    When an issuer's site sends a visitor to an intermediary, default analytics lose the transaction. Here is what to ask for and test before launch.

  • Post

    Who actually regulates equity crowdfunding?

    Not one regulator but several, each with a different job. A map of the SEC, FINRA, the states, the FTC, and the ad platforms, and what each can do to a raise.

  • From the wiki

    Server-side tracking

    What server-side tracking is, how it differs from a browser pixel, how duplicate events are removed, and what it can and cannot fix in an offering's measurement.

  • From the wiki

    Lead funnel

    What a lead funnel is and the stages HookVerb manages between the first click and the sales conversation.

  • From the wiki

    Cost per investor

    What cost per investor means in an equity crowdfunding raise, how to calculate it from spend and the intermediary's ledger, and how it differs from cost per reservation.

  • From the wiki

    Cross-domain tracking

    What cross-domain tracking is, why an offering's analytics lose the visitor at the funding portal, and the ways an issuer and an intermediary can join the records.