Skip to main content
Dash.fi Ad Pay Protection is built on a privacy-first foundation. The pixel uses cookie-less tracking and collects no personally identifiable information (PII) — no names, emails, phone numbers, or exact location data are ever captured. The system is fully compliant with GDPR and CCPA, and only collects the behavioral and technical signals needed to detect ad fraud and audit your campaign spend.

What the pixel captures

Core user events

The pixel records standard browser events to build a picture of session activity:
  • Page load / view — Recorded when a page finishes loading
  • Page unload — Recorded when a visitor navigates away from a page
  • Session start — Recorded at the beginning of each new session
  • Scroll — Recorded when a visitor scrolls on a page
  • Click — Recorded when a visitor interacts with page elements
  • Form submit — Recorded when a form is submitted

Ad auditing signals

Beyond core events, the pixel captures signals specifically used for auditing and fraud detection:
  • Ad performance metrics — Impressions, clicks, session duration, and bounce status. Sessions lasting 10 or more seconds are classified as True Visitors.
  • Attribution parameters — UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and ad-platform click identifiers (for example gclid from Google, fbclid from Meta) read from the landing page URL. These let the pixel match a visit back to the campaign that generated it.
  • Fraud detection signals — Signals used to identify bot traffic, click farms, invalid clicks, ad stacking, and out-of-geo ad delivery. See Fraud categories you’ll see in the dashboard.

Full list of data fields collected

The pixel collects the following fields — and only these fields.

Session and event identifiers

Anonymous identifiers used to stitch events from the same visit together. They cannot be linked back to an individual and are not shared across sites.

Technical and browser signals

Low-resolution device and browser characteristics used to identify automated traffic and bots. None of these fields are combined into a fingerprint or used to track visitors across other websites.

Session outcome

Page and referrer

Attribution parameters

UTM parameters and ad-platform click identifiers (gclid, fbclid, msclkid, ttclid, and other supported network click IDs) captured from the landing page URL to link the visit back to the campaign that generated it.

Approximate location

The pixel derives country, region, and city from the request only for fraud detection (for example, identifying out-of-geo delivery). No exact IP address or street-level location is stored.

What the pixel does NOT collect

The following data types are never collected by the Ad Pay Protection pixel under any circumstances:
  • Names, email addresses, phone numbers, or any other personal identifiers
  • Payment details or account credentials
  • Exact IP addresses or precise geolocation data
  • Third-party cookies or cross-site tracking data
  • Device or browser fingerprints used to identify visitors across other websites

How your ad-account data is handled

Ad Pay Protection also connects to your Meta and Google ad accounts through their official OAuth flows, so it can compare what the platform reported against what the pixel observed on your site.
  • Read-only access. Dash.fi requests only the permissions needed to read campaign, ad, and spend data. We never edit your campaigns, adjust budgets, or post on your behalf outside of submitting refund claims you’ve opted into.
  • Scope is limited to your advertising data. Campaign metadata, ad performance metrics, spend, and refund/credit records — not end-customer data from your ad-platform audiences.
  • Revocable at any time. You can disconnect an ad account from your Dash.fi dashboard, which revokes the OAuth token immediately.

Fraud categories you’ll see in the dashboard

Each invalid click flagged in your dashboard is tagged with the specific pattern that triggered it, so you can see exactly why we’ve classified it as invalid:
  • Bot Detection — Automated, non-human traffic
  • Automation Signatures — Scripted browsers and headless automation
  • Zero Second Click — Clicks that bounce before any real page interaction
  • Out of Geo Refund — Clicks delivered outside the campaign’s targeted geography
  • Platform Spoofing — Traffic misrepresenting its device or platform
  • Device Type Diversity / Device Fingerprint Diversity — Patterns consistent with click farms
  • Bounced Overcharge / Bounced Refund — Charges for clicks that never produced a landed session
  • HFC Overcharge / HFC Refund / HFC Refund And Overcharge — High-frequency click patterns eligible for refund
Each flagged click also carries a risk level and reason code so you can drill into the audit log and see the evidence behind the classification.

How data is stored and retained


Server infrastructure and security

Your data is stored and processed on secure, enterprise-grade infrastructure:
  • Hosting: Google Cloud Platform (GCP) — US-Central1 region (Oregon, USA)
  • Data in transit: Encrypted using industry-standard TLS
  • Data at rest: Encrypted at the storage layer
  • Audit logs: Immutable, blockchain-based audit trail
  • Log integrity: Tamper-proof — audit records cannot be altered after creation

Compliance and certifications

Dash.fi Ad Pay Protection meets the requirements of major data protection frameworks:
Ad Pay Protection is fully compliant with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). No PII is collected, and cookie-less tracking eliminates the need for cookie consent banners related to the pixel.
Dash.fi holds Data Privacy Framework (DPF) certification, covering data transfers between the EU, UK, and United States.
A Data Protection Officer (DPO) has been appointed. EU representative and lead supervisory authority appointments are in place as required by GDPR.
Procedures are in place to handle data subject access requests (DSARs) and to fulfill rights of access, correction, and erasure in accordance with GDPR and CCPA requirements.
Business Continuity and Disaster Recovery (BCDR) plans are documented and tested on an annual basis to ensure data availability and system resilience.

How Ad Pay Protection helps your business

  • Detects invalid traffic (IVT) and ad fraud — Identifies bot traffic, click farms, ad stacking, and other forms of fraud that inflate your ad costs without delivering real results.
  • Recovers overcharges — Typical advertiser accounts show 5–30% in overcharges from platforms like Google and Meta. Ad Pay Protection identifies these discrepancies and submits refund claims on your behalf.
  • Self-service monitoring — Track ad performance, fraud signals, and pending refund claims directly from your Dash.fi dashboard at app.dash.fi.
For questions about data handling, privacy compliance, or to submit a data subject access request, contact support@dash.fi.