Contact data
This page is for the administrator. Contact data is a person's name, email address and phone number. It can pass through the server in three ways, and each one is closed until you open it:
- Reading leads: the people who filled in a lead form are handed to the AI client that asks, or pushed to your own system. See Leads and Lead delivery.
- Sending conversions: rows from your own records go to an advertising platform, to say which leads became customers.
- Uploading customer lists: rows from your own records go to an advertising platform, to become an audience.
The last two are described for the marketer in Conversions and customer lists.
Read this before you open a switch
Each switch lets people's details leave your records for a platform or an AI client. Your own privacy policy has to say so first, and you answer for the lists that your people upload. See the privacy policy and the terms.
The rules that always hold
- Every capability has its own switch, off by default. Opening one opens nothing else.
- Only people with write access can read leads or send contact data. The administrator gives it on Users, with May write: see Users and access.
- Hashed on the server. An email, a phone number or a name is tidied by the rules of the platform it is going to and hashed with SHA-256 before it is sent, wherever that platform takes a hash.
- Nothing is stored. A row is read, hashed, sent and dropped.
- Where it goes is fixed. Contact data goes to the platform that the person connected. Leads can also go to the one lead webhook that you set. No request can name another place.
- Every send is previewed first. Nothing leaves until the person confirms. See How it keeps you safe.
The switches
There are nine, on three pages. All start off.
Meta
On Meta app, under Meta Ads. Press Save below them. Meta Ads itself has to be on.
| Switch | What it allows | At sign-in |
|---|---|---|
| Allow reading leads | Reading the leads of a Page's lead forms. | Adds a permission. People who are already connected reconnect to grant it. |
| Allow sending conversions to a pixel | Sending conversions from your records to a pixel of the ad account: Meta's lead ids, and people's emails, phones, names and places, hashed first. | Nothing new. |
| Allow customer lists as audiences | Making a customer-list audience, adding people to it, taking them out or replacing them. Each person accepts Meta's Custom Audience terms for the ad account themselves. | Nothing new. |
Meta decides whether your app may use a permission: see Meta.
Google
On Safety limits, under Google Ads limits. Press Save limits.
| Switch | What it allows | At sign-in |
|---|---|---|
| Let a call read the leads of Google lead forms | Reading the leads of an account's lead forms, for the 60 days that Google keeps them. | Nothing new. |
| Allow uploading offline conversions to Google | Sending conversions from your records to a conversion action: click ids, and people's emails, phones and names, hashed first. | Adds the Data Manager permission. |
| Allow Customer Match lists on Google | Making a Customer Match list, adding people, taking them out or replacing them. Each request states the people's consent and accepts Google's Customer Match terms. | Adds the Data Manager permission. |
Before you open either of the last two:
- In the Google Cloud project of your OAuth client, enable the Data Manager API.
- Open the switch and save.
- Tell everyone who is connected to reconnect on Google connection. Their Google Ads tools keep working meanwhile; only the uploads wait for the new permission.
See Google.
LinkedIn
On LinkedIn app, under LinkedIn Ads. Press Save. The Advertising API has to be on.
| Switch | What it allows | LinkedIn product |
|---|---|---|
Leads: ask for r_marketing_leadgen_automation | Reading the leads of an ad account's lead gen forms. | Lead Sync API |
Conversions: ask for rw_conversions | Sending conversions from your records: emails and names hashed first, with a company, a job title and a country as they are where given. | Conversions API |
Matched audiences: ask for rw_dmp_segments | Making audiences and filling lists: companies as they are, and people as hashed emails, with a name, a job title and a company as plain text where given. | Matched Audiences API |
Do not open one before LinkedIn has approved the product
Each of these is a separate product that you apply for in LinkedIn's developer portal, and each adds its own permission to the sign-in. LinkedIn refuses the whole sign-in for a permission that the app does not have, so nobody could connect at all. LinkedIn decides the approval. See LinkedIn.
Once a product is approved and its switch is open, people who are already connected reconnect on LinkedIn connection to grant it.
Pushing leads
A tenth switch decides whether leads may be sent on by themselves to your own system. It is on Lead delivery, and each platform's switch for reading leads still has to be on as well. See Lead delivery.
Data folders
A person can give the rows of an upload in the conversation, but then the AI client has seen them, and a request carries at most 2,000. A data folder is the better way: a folder on the server that holds CSV files meant for upload. The AI client names a file's path, the server reads the file where it lies, and the rows never pass through the conversation. A file may hold up to 500,000 rows.
No folder is open on a new installation. To open one:
- Open Server.
- Under Data folders, type one folder on each line.
- Press Save folders.
It takes effect at once. The page shows On beside the heading when at least one folder is named. To close them all, empty the field and save.
What the server holds a data folder to:
- The folder must exist, and you give its full path.
- Never a whole drive or a home folder. Those are refused.
- A file is read only when it really lies inside a data folder. A path that leaves the folder, through
..or a link, is refused. - The file is never copied, and never joins the media library.
The folders can also be named with the environment variable NAMA_MCP_DATA_DIR. It then wins over what is saved, and the page says so. See Settings.
TIP
Name a folder that holds only exports meant for upload, and remove a file once it has been sent. Anyone with write access can ask for any CSV file in it to be uploaded, where the switch for that upload is open.
Why a data folder is never a media folder
A media folder holds what may be posted in public. A data folder holds files of customers, which must never be posted. So the server keeps them apart:
- a data folder may not be a media folder;
- neither may lie inside the other;
- the same holds between a data folder and the media library.
This is checked when you save either list and again every time a file is read. If the two overlap, the read is refused until you separate them. Media folders are on Meta app: see Media.
What is hashed and what goes plain
"Hashed" means that the server sends the SHA-256 of the value and not the value. The platforms disagree about how a value is tidied before hashing, so the server follows each platform's own rules. A hash made for one platform is not valid for another.
| Value | Meta (conversions and lists) | Google (conversions and lists) | LinkedIn conversions | LinkedIn contact list |
|---|---|---|---|---|
| Hashed | Hashed | Hashed | Hashed | |
| Phone | Hashed | Hashed | Not taken | Not taken |
| First and last name | Hashed | Hashed | Hashed | Plain |
| City, state | Hashed | Not taken | Not taken | Not taken |
| Postal code | Hashed | Plain | Not taken | Not taken |
| Country | Hashed | Plain | Plain | Plain |
| Company, job title | Not taken | Not taken | Plain | Plain |
Also sent as they are, because they are not a person's details: Meta's lead id, Google's click id, your own order or event id, and the rows of a LinkedIn company list.
Things to know:
- A person can send hashes that they made themselves. The server then checks only that each value is a SHA-256 hash and passes it on. Plain details then never reach the AI client.
- A phone number needs its country code. A number written without one is used only when the request gives the country's dialling code.
- What goes plain to LinkedIn is optional. Leaving the name, company and job title columns out of a file sends hashed emails alone.
- A hash is still personal data. The server treats it like the value: it is never logged and never shown.
What is never stored
The server keeps no table, file or log line that holds:
- a lead, or any answer from a lead form;
- a row of an upload: a name, an email, a phone number;
- a hash of any of those;
- a copy of an uploaded file, or its name.
What it does keep:
| Kept | Where | What it holds |
|---|---|---|
| A row for each read of leads | The activity log | The Page or account, the form, and how many leads. |
| A row for each upload | The activity log | How many rows went in, how many were sent or left out and why, the target's id, a file's fingerprint and size, the consent that was stated. |
| How far each person has exported each form | The server's database | A time and lead ids. Never an answer. |
| How far each lead feed has sent each form | The server's database | The same. |
A refusal names a row by its number and says what was wrong with it. It never repeats the value.
The marks go when the person disconnects that platform or their user is deleted. See Activity log and History and retention.
What the server cannot promise
The server keeps nothing, but a lead that is read on request, and a row that is given in the conversation, pass through the AI client. What the AI client and its provider keep is theirs to say. A file in a data folder and values that are hashed beforehand avoid this for uploads.