Skip to content

Contact data ​

This page is for the administrator. Contact data is a person's name, email address and phone number. It can pass through the server in three ways, and each one is closed until you open it:

  • Reading leads: the people who filled in a lead form are handed to the AI client that asks, or pushed to your own system. See Leads and Lead delivery.
  • Sending conversions: rows from your own records go to an advertising platform, to say which leads became customers.
  • Uploading customer lists: rows from your own records go to an advertising platform, to become an audience.

The last two are described for the marketer in Conversions and customer lists.

Read this before you open a switch

Each switch lets people's details leave your records for a platform or an AI client. Your own privacy policy has to say so first, and you answer for the lists that your people upload. See the privacy policy and the terms.

The rules that always hold ​

  • Every capability has its own switch, off by default. Opening one opens nothing else.
  • Only people with write access can read leads or send contact data. The administrator gives it on Users, with May write: see Users and access.
  • Hashed on the server. An email, a phone number or a name is tidied by the rules of the platform it is going to and hashed with SHA-256 before it is sent, wherever that platform takes a hash.
  • Nothing is stored. A row is read, hashed, sent and dropped.
  • Where it goes is fixed. Contact data goes to the platform that the person connected. Leads can also go to the one lead webhook that you set. No request can name another place.
  • Every send is previewed first. Nothing leaves until the person confirms. See How it keeps you safe.

The switches ​

There are nine, on three pages. All start off.

Meta ​

On Meta app, under Meta Ads. Press Save below them. Meta Ads itself has to be on.

SwitchWhat it allowsAt sign-in
Allow reading leadsReading the leads of a Page's lead forms.Adds a permission. People who are already connected reconnect to grant it.
Allow sending conversions to a pixelSending conversions from your records to a pixel of the ad account: Meta's lead ids, and people's emails, phones, names and places, hashed first.Nothing new.
Allow customer lists as audiencesMaking a customer-list audience, adding people to it, taking them out or replacing them. Each person accepts Meta's Custom Audience terms for the ad account themselves.Nothing new.

Meta decides whether your app may use a permission: see Meta.

Google ​

On Safety limits, under Google Ads limits. Press Save limits.

SwitchWhat it allowsAt sign-in
Let a call read the leads of Google lead formsReading the leads of an account's lead forms, for the 60 days that Google keeps them.Nothing new.
Allow uploading offline conversions to GoogleSending conversions from your records to a conversion action: click ids, and people's emails, phones and names, hashed first.Adds the Data Manager permission.
Allow Customer Match lists on GoogleMaking a Customer Match list, adding people, taking them out or replacing them. Each request states the people's consent and accepts Google's Customer Match terms.Adds the Data Manager permission.

Before you open either of the last two:

  1. In the Google Cloud project of your OAuth client, enable the Data Manager API.
  2. Open the switch and save.
  3. Tell everyone who is connected to reconnect on Google connection. Their Google Ads tools keep working meanwhile; only the uploads wait for the new permission.

See Google.

LinkedIn ​

On LinkedIn app, under LinkedIn Ads. Press Save. The Advertising API has to be on.

SwitchWhat it allowsLinkedIn product
Leads: ask for r_marketing_leadgen_automationReading the leads of an ad account's lead gen forms.Lead Sync API
Conversions: ask for rw_conversionsSending conversions from your records: emails and names hashed first, with a company, a job title and a country as they are where given.Conversions API
Matched audiences: ask for rw_dmp_segmentsMaking audiences and filling lists: companies as they are, and people as hashed emails, with a name, a job title and a company as plain text where given.Matched Audiences API

Do not open one before LinkedIn has approved the product

Each of these is a separate product that you apply for in LinkedIn's developer portal, and each adds its own permission to the sign-in. LinkedIn refuses the whole sign-in for a permission that the app does not have, so nobody could connect at all. LinkedIn decides the approval. See LinkedIn.

Once a product is approved and its switch is open, people who are already connected reconnect on LinkedIn connection to grant it.

Pushing leads ​

A tenth switch decides whether leads may be sent on by themselves to your own system. It is on Lead delivery, and each platform's switch for reading leads still has to be on as well. See Lead delivery.

Data folders ​

A person can give the rows of an upload in the conversation, but then the AI client has seen them, and a request carries at most 2,000. A data folder is the better way: a folder on the server that holds CSV files meant for upload. The AI client names a file's path, the server reads the file where it lies, and the rows never pass through the conversation. A file may hold up to 500,000 rows.

No folder is open on a new installation. To open one:

  1. Open Server.
  2. Under Data folders, type one folder on each line.
  3. Press Save folders.

It takes effect at once. The page shows On beside the heading when at least one folder is named. To close them all, empty the field and save.

What the server holds a data folder to:

  • The folder must exist, and you give its full path.
  • Never a whole drive or a home folder. Those are refused.
  • A file is read only when it really lies inside a data folder. A path that leaves the folder, through .. or a link, is refused.
  • The file is never copied, and never joins the media library.

The folders can also be named with the environment variable NAMA_MCP_DATA_DIR. It then wins over what is saved, and the page says so. See Settings.

TIP

Name a folder that holds only exports meant for upload, and remove a file once it has been sent. Anyone with write access can ask for any CSV file in it to be uploaded, where the switch for that upload is open.

Why a data folder is never a media folder ​

A media folder holds what may be posted in public. A data folder holds files of customers, which must never be posted. So the server keeps them apart:

  • a data folder may not be a media folder;
  • neither may lie inside the other;
  • the same holds between a data folder and the media library.

This is checked when you save either list and again every time a file is read. If the two overlap, the read is refused until you separate them. Media folders are on Meta app: see Media.

What is hashed and what goes plain ​

"Hashed" means that the server sends the SHA-256 of the value and not the value. The platforms disagree about how a value is tidied before hashing, so the server follows each platform's own rules. A hash made for one platform is not valid for another.

ValueMeta (conversions and lists)Google (conversions and lists)LinkedIn conversionsLinkedIn contact list
EmailHashedHashedHashedHashed
PhoneHashedHashedNot takenNot taken
First and last nameHashedHashedHashedPlain
City, stateHashedNot takenNot takenNot taken
Postal codeHashedPlainNot takenNot taken
CountryHashedPlainPlainPlain
Company, job titleNot takenNot takenPlainPlain

Also sent as they are, because they are not a person's details: Meta's lead id, Google's click id, your own order or event id, and the rows of a LinkedIn company list.

Things to know:

  • A person can send hashes that they made themselves. The server then checks only that each value is a SHA-256 hash and passes it on. Plain details then never reach the AI client.
  • A phone number needs its country code. A number written without one is used only when the request gives the country's dialling code.
  • What goes plain to LinkedIn is optional. Leaving the name, company and job title columns out of a file sends hashed emails alone.
  • A hash is still personal data. The server treats it like the value: it is never logged and never shown.

What is never stored ​

The server keeps no table, file or log line that holds:

  • a lead, or any answer from a lead form;
  • a row of an upload: a name, an email, a phone number;
  • a hash of any of those;
  • a copy of an uploaded file, or its name.

What it does keep:

KeptWhereWhat it holds
A row for each read of leadsThe activity logThe Page or account, the form, and how many leads.
A row for each uploadThe activity logHow many rows went in, how many were sent or left out and why, the target's id, a file's fingerprint and size, the consent that was stated.
How far each person has exported each formThe server's databaseA time and lead ids. Never an answer.
How far each lead feed has sent each formThe server's databaseThe same.

A refusal names a row by its number and says what was wrong with it. It never repeats the value.

The marks go when the person disconnects that platform or their user is deleted. See Activity log and History and retention.

What the server cannot promise

The server keeps nothing, but a lead that is read on request, and a row that is given in the conversation, pass through the AI client. What the AI client and its provider keep is theirs to say. A file in a data folder and values that are hashed beforehand avoid this for uploads.