Give It Your Variable. Get Ready Code for Each Platform’s Rules.
Every ad platform wants customer data cleaned in its own way before it is hashed. Tell this free hashing code generator where your email, phone or address value lives and it writes a GTM SHA-256 hash variable for each one, a single Custom HTML tag that pushes all hashes to the dataLayer, and plain JavaScript. Use it to hash email for Meta CAPI, to build enhanced conversions hashing code for Google, and for TikTok, Pinterest, Snapchat, LinkedIn and Microsoft.
Tick your fields, name your variables and choose your platforms. The code updates as you type.
Tick what you have. Then say where each value comes from: a GTM variable name, a dataLayer key such as user_data.email, a JavaScript expression, or the CSS selector of a form field.
Type a made-up sample to see what each selected platform would receive. The result comes from the same functions that are printed in your code, so it shows exactly what the code will produce. Nothing you type here leaves your browser.
The code is written in your browser. We keep a simple log of the options chosen: the platforms, the fields and the source types. Your variable names, your code and the test values you type are not logged and stay in your browser.
Your own variables, filled into code that formats each value the way the platform asks, then hashes it.
One per field and format. Each returns the hash straight away and needs nothing else.
Reads every field, hashes it and pushes one dataLayer event with a clear object per platform.
When two platforms want the same format, they share one variable, named after both.
E.164 with a “+” for Google, TikTok and Microsoft. Digits only for Meta, Pinterest and Snapchat.
Type a sample and see the formatted value and the hash per platform, from the same functions as your code.
Field by platform: the format rule, hashed or plain, and the exact parameter name.
Numbered steps, the trigger to create and every Data Layer Variable to add.
The rules, your variables and the code in one workbook for your notes or your developer.
Three steps. The code is written in your browser.
Email, phone, name, address, date of birth, gender or customer ID. Say where each value comes from.
Pick one or several. The generator works out which fields share a format.
Take the GTM variables or the single tag, test a sample value, then check it in GTM Preview.
A SHA-256 hash turns a value such as an email address into a fixed string of 64 letters and numbers. Ad platforms compare your hash with the hashes of their own users. If the two match, the conversion is matched to a person.
The catch is that one changed character gives a completely different hash. [email protected] and [email protected] do not match. So each platform publishes rules for cleaning a value before it is hashed, and the rules are not the same. Meta wants a phone number as digits only with the country code. Google wants the same number in E.164 format with a “+” in front. Google removes the dots from Gmail addresses. Microsoft removes dots and “+suffixes” from every address.
Often you do not. The Google tag, the Meta Pixel, the TikTok Pixel, the Pinterest JavaScript tag and Microsoft’s UET tag can take a plain value and hash it for you in the browser. You need your own hashing code when you build the payload yourself: Conversions API and Events API calls, server-side setups that expect hashed keys, offline uploads, and custom tags or templates that do not hash. The tool shows what each platform you pick does for you.
A GTM SHA-256 hash variable is a Custom JavaScript variable that reads your value, formats it and returns the hash. A Custom JavaScript variable must return its answer straight away, and the browser’s built-in hashing answers later, so each variable carries its own small SHA-256 function. The code is written in ES5, the older JavaScript style, because Custom JavaScript variables and Custom HTML tags are checked against it.
The Custom HTML tag is the other route. It uses the browser’s built-in hashing when it is available and pushes one event, such as user_data_hashed, that your other tags can use as a trigger.
No. Hashing is not anonymisation. A hashed email still points to one person, and the platform can match it. It is still personal data, so you still need consent or another legal basis to collect and send it, and your tags should respect the visitor’s consent choice.
A quick guide. The tool’s rules table has the format for every field.
| Platform | Does the browser tag hash plain values? | You hash yourself for | Phone format |
|---|---|---|---|
| Google Ads | Yes. The Google tag and GTM user-provided data | The sha256_ keys, server and custom setups | E.164 with “+” |
| Meta | Yes. Pixel advanced matching | Conversions API | Digits only, with country code |
| TikTok | Yes. Pixel identify | Events API | E.164 with “+” |
| Yes, for email in the JavaScript tag | Image tag and Conversions API | Digits only, with country code | |
| Snapchat | Check Snapchat’s help page | Conversions API | Digits only, with country code |
| Check LinkedIn’s help page | Conversions API (email) | No phone field | |
| Microsoft Ads | Yes. UET formats and hashes email; phone must already be E.164 | Offline conversion uploads | E.164 with “+” |
Stop rewriting the same hashing variable for every client and platform.
Get the exact format per platform without reading seven sets of documentation.
Hand over a clear setup: the code, the variables to create and the rules behind them.
Understand what your tracking sends before you hire someone to build it.
33 free tools for tracking, analytics, advertising and SEO. No login needed.
Validate GA4 event names and parameters against Google’s rules before you publish.
Open the GA4 event checker →Get GTM listener code for HubSpot, GoHighLevel, iframe and native forms that pushes a clean dataLayer event.
Open the listener generator →Build ready-to-paste dataLayer code for GA4 ecommerce and lead events.
Open the dataLayer generator →Build and validate a Conversions API event with hashed user data and a matching pixel call.
Open the CAPI builder →Hear from our clients. Loved by 600+ businesses worldwide.
“I had an excellent experience working with MD on my Google Ads account. Everything was set up perfectly and worked smoothly without any issues or troubleshooting needed. His expertise and attention to detail made the whole process effortless.”
“I worked with Niamul on multiple Google Analytics projects and was impressed by his expertise and precision. He has a strong grasp of tracking, reporting, and optimization, always ensuring accurate insights. He is proactive, reliable, and easy to collaborate with.”
“MD Niamul is extremely skilled. He fixed my Shopify, Google Analytics, and Google Ads conversion tracking perfectly. Everything works exactly as it should now, and he even added an extra data layer, which was very helpful. Outstanding service, fast delivery, and highly recommended.”
“Reliable, knowledgeable, and truly trustworthy. I’ve been working with Niamul for over a year, and he consistently delivers exceptional results across all analytics tasks. His expertise, communication, and commitment make him my go-to specialist for tracking, measurement, and data accuracy.”
“MD N delivered flawless Meta Pixel, CAPI, and server-side tracking. He understood our goals quickly, explained everything clearly, and ensured full transparency. Communication was smooth, updates were consistent, and the results improved our data accuracy and ad performance.”
Five-star reviews from businesses and agencies in the USA, Canada, UK and Australia.
Read All ReviewsYes. It is free with no login. The code is written in your browser.
Tick the field, type the name of your GTM variable and choose the platform. Copy the code from the GTM variables tab, then in Google Tag Manager go to Variables, New, Custom JavaScript, paste it and save it with the name shown.
Trim the spaces, make it lowercase, then hash it with SHA-256 and send it as em. For a phone number Meta wants digits only, with the country code and no leading zeros, sent as ph.
Lowercase and trim the email, and remove the dots before the @ on gmail.com and googlemail.com addresses. Phone numbers go in E.164 format with a “+”. First and last name are hashed. City, region, postcode and country are sent as plain text.
Usually not. Both can take plain values and hash them in the browser. You hash yourself for Conversions API and Events API payloads, server-side setups that expect hashed keys, offline uploads and custom tags that do not hash.
A Custom JavaScript variable in GTM must return its value straight away. The browser’s built-in hashing gives its answer later, so it cannot be used there. The Custom HTML tag does use the built-in hashing when it is available.
No. A hashed email is still personal data because it can be matched back to a person. You still need consent or another legal basis to send it.
The code spots a 64-character hash and passes it on unchanged, in lowercase. It never hashes twice, because a hash of a hash matches nobody.
No. Test values are worked out in your browser and are not stored, logged or sent. We only log which platforms, fields and source types were chosen.
I am MD Niamul, a conversion tracking and web analytics specialist and an official Stape partner. I set up enhanced conversions, Conversions API and server-side tagging, with customer data formatted and hashed correctly for each platform and tested end to end.