What the pixel captures
Core user events
The pixel records standard browser events to build a picture of session activity:- Page load / view — Recorded when a page finishes loading
- Page unload — Recorded when a visitor navigates away from a page
- Session start — Recorded at the beginning of each new session
- Scroll — Recorded when a visitor scrolls on a page
- Click — Recorded when a visitor interacts with page elements
- Form submit — Recorded when a form is submitted
Ad auditing signals
Beyond core events, the pixel captures signals specifically used for auditing and fraud detection:- Ad performance metrics — Impressions, clicks, session duration, and bounce status. Sessions lasting 10 or more seconds are classified as True Visitors.
- Attribution parameters — UTM parameters (
utm_source,utm_medium,utm_campaign,utm_term,utm_content) and ad-platform click identifiers (for examplegclidfrom Google,fbclidfrom Meta) read from the landing page URL. These let the pixel match a visit back to the campaign that generated it. - Fraud detection signals — Signals used to identify bot traffic, click farms, invalid clicks, ad stacking, and out-of-geo ad delivery. See Fraud categories you’ll see in the dashboard.
Full list of data fields collected
The pixel collects the following fields — and only these fields.Session and event identifiers
Anonymous identifiers used to stitch events from the same visit together. They cannot be linked back to an individual and are not shared across sites.Technical and browser signals
Low-resolution device and browser characteristics used to identify automated traffic and bots. None of these fields are combined into a fingerprint or used to track visitors across other websites.Session outcome
Page and referrer
Attribution parameters
UTM parameters and ad-platform click identifiers (gclid, fbclid, msclkid, ttclid, and other supported network click IDs) captured from the landing page URL to link the visit back to the campaign that generated it.
Approximate location
The pixel derives country, region, and city from the request only for fraud detection (for example, identifying out-of-geo delivery). No exact IP address or street-level location is stored.What the pixel does NOT collect
- Names, email addresses, phone numbers, or any other personal identifiers
- Payment details or account credentials
- Exact IP addresses or precise geolocation data
- Third-party cookies or cross-site tracking data
- Device or browser fingerprints used to identify visitors across other websites
How your ad-account data is handled
Ad Pay Protection also connects to your Meta and Google ad accounts through their official OAuth flows, so it can compare what the platform reported against what the pixel observed on your site.- Read-only access. Dash.fi requests only the permissions needed to read campaign, ad, and spend data. We never edit your campaigns, adjust budgets, or post on your behalf outside of submitting refund claims you’ve opted into.
- Scope is limited to your advertising data. Campaign metadata, ad performance metrics, spend, and refund/credit records — not end-customer data from your ad-platform audiences.
- Revocable at any time. You can disconnect an ad account from your Dash.fi dashboard, which revokes the OAuth token immediately.
Fraud categories you’ll see in the dashboard
Each invalid click flagged in your dashboard is tagged with the specific pattern that triggered it, so you can see exactly why we’ve classified it as invalid:- Bot Detection — Automated, non-human traffic
- Automation Signatures — Scripted browsers and headless automation
- Zero Second Click — Clicks that bounce before any real page interaction
- Out of Geo Refund — Clicks delivered outside the campaign’s targeted geography
- Platform Spoofing — Traffic misrepresenting its device or platform
- Device Type Diversity / Device Fingerprint Diversity — Patterns consistent with click farms
- Bounced Overcharge / Bounced Refund — Charges for clicks that never produced a landed session
- HFC Overcharge / HFC Refund / HFC Refund And Overcharge — High-frequency click patterns eligible for refund
How data is stored and retained
Server infrastructure and security
Your data is stored and processed on secure, enterprise-grade infrastructure:- Hosting: Google Cloud Platform (GCP) — US-Central1 region (Oregon, USA)
- Data in transit: Encrypted using industry-standard TLS
- Data at rest: Encrypted at the storage layer
- Audit logs: Immutable, blockchain-based audit trail
- Log integrity: Tamper-proof — audit records cannot be altered after creation
Compliance and certifications
Dash.fi Ad Pay Protection meets the requirements of major data protection frameworks:GDPR and CCPA compliance
GDPR and CCPA compliance
Ad Pay Protection is fully compliant with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). No PII is collected, and cookie-less tracking eliminates the need for cookie consent banners related to the pixel.
DPF Certification
DPF Certification
Dash.fi holds Data Privacy Framework (DPF) certification, covering data transfers between the EU, UK, and United States.
Data Protection Officer and EU representation
Data Protection Officer and EU representation
A Data Protection Officer (DPO) has been appointed. EU representative and lead supervisory authority appointments are in place as required by GDPR.
Data subject rights (Access, Correction, Erasure, DSAR)
Data subject rights (Access, Correction, Erasure, DSAR)
Procedures are in place to handle data subject access requests (DSARs) and to fulfill rights of access, correction, and erasure in accordance with GDPR and CCPA requirements.
Business Continuity and Disaster Recovery
Business Continuity and Disaster Recovery
Business Continuity and Disaster Recovery (BCDR) plans are documented and tested on an annual basis to ensure data availability and system resilience.
How Ad Pay Protection helps your business
- Detects invalid traffic (IVT) and ad fraud — Identifies bot traffic, click farms, ad stacking, and other forms of fraud that inflate your ad costs without delivering real results.
- Recovers overcharges — Typical advertiser accounts show 5–30% in overcharges from platforms like Google and Meta. Ad Pay Protection identifies these discrepancies and submits refund claims on your behalf.
- Self-service monitoring — Track ad performance, fraud signals, and pending refund claims directly from your Dash.fi dashboard at app.dash.fi.
For questions about data handling, privacy compliance, or to submit a data subject access request, contact support@dash.fi.