This policy explains what personal data Pixel Relay handles, why, and what we do to keep it to a minimum. Pixel Relay was built to send Meta less about people, so we hold ourselves to the same standard.
1. Who we are
Pixel Relay (pixelrelay.co) is operated by Webook. You can reach us about anything in this policy at info@weboook.co.uk.
2. Our role
We handle personal data in two different capacities:
- As a controller for this website, for the accounts of people who use the Pixel Relay dashboard, and for business contact with our customers.
- As a processor for our customers, when visitors to a customer's website generate events that pass through the relay. The customer (the website owner) decides which events are sent and to which Meta Pixel, and is the controller of that data. Our Data processing addendum sets out the terms.
If you visited a website that uses Pixel Relay and have a question about your data, please contact that website's owner first. We will help them answer you.
3. This website
pixelrelay.co does not run analytics, advertising pixels or any third-party tracking. When you visit:
- Our web server records standard request logs (IP address, time, page requested, browser user agent) for security and troubleshooting. These are kept for a limited period and are not used for profiling.
- We set only the cookies needed to run the site securely; see the Cookie policy.
- Fonts are loaded from Bunny Fonts (fonts.bunny.net), which states that it does not log IP addresses or set cookies.
- If you send the Request access form, we store your name, email address and message, plus any company, website, type of business and number of sites you give us. We don't store your IP address. To stop abuse, the form is rate limited by a keyed hash of your IP address that is kept in our cache for up to one hour. The enquiry is emailed to our team and shown to our staff in the dashboard.
- If you email us, we keep the message and your contact details for as long as needed to deal with your enquiry and any business relationship that follows.
Legal basis: our legitimate interests in running a secure website and answering enquiries.
4. Dashboard accounts
Accounts are created by our team; there is no public sign-up. For each account we hold:
- Name, email address, role and the websites the account can access.
- A password, stored only as a one-way hash.
- Two-factor authentication secrets and recovery codes, if enabled, stored encrypted.
- Active session records (session ID, IP address, browser user agent and last activity time), which expire when you sign out or after a period of inactivity.
Legal basis: performance of our contract with the customer the account belongs to, and our legitimate interest in keeping the service secure. We delete an account's data when the account is removed.
5. Events we relay for customers
A customer's website loads a small script from Pixel Relay that sends events (for example a page view or a lead) to the relay. The script sets no cookies of its own. An event can contain:
- The event name, the page URL and the referring page.
- The visitor's IP address and browser user agent, as seen by our server.
- Meta's own browser identifiers (
_fbpand_fbccookie values, or afbclidfrom the page URL) if Meta has already set them on that site. - Optional details the website chooses to send, such as email address, phone number, first and last name or a customer ID, and other event data (for example a value or currency).
What we change before anything is sent to Meta
- Query strings are removed from page URLs.
- Health-related terms, and any terms the customer blocks, are replaced with a neutral word in the page path and in text event fields.
- Email, phone, name and customer ID fields are SHA-256 hashed, the way Meta requires.
- The visitor's IP address and user agent are only forwarded if the customer turns that on for the site. The source domain can be masked.
What we store
To show customers delivery status and analytics we keep a log of each event containing only sanitised values: the cleaned page URL, the referring host name (not the full referrer), the site's own host name, a keyed hash of the IP address (it cannot be reversed without our secret key and is used only to count unique visitors), the browser user agent, event names, sanitised event data, whether personal details were present (not the details themselves) and Meta's response. We never store a raw IP address, a raw page URL, a full referrer or the personal details a site sends.
For short links we record the time of each click, a keyed hash of the IP address, the browser user agent and the referring host name.
6. Who receives data
- Meta Platforms receives the sanitised events, sent to the Meta Pixel the customer has configured. Meta processes that data under its own Business Tools Terms and privacy policy, as agreed between Meta and the customer.
- Brevo (Sendinblue SAS) sends our emails, including the enquiries you send through the Request access form.
- Hostinger International Ltd provides the servers Pixel Relay runs on, located in the United Kingdom.
- Professional advisers, or authorities where the law requires it.
We do not sell personal data, and we do not use relayed event data for our own purposes. Meta may transfer data outside the UK; this is covered by Meta's own transfer safeguards.
7. How long we keep it
| Data | Kept for |
|---|---|
| Event logs and short-link clicks | 90 days, then deleted automatically |
| Daily event counts (no personal data) | For as long as the customer's site is on Pixel Relay |
| Dashboard accounts | Until the account is removed |
| Session records | Until sign-out or expiry |
| Enquiries sent through the Request access form | Two years after we last dealt with the enquiry, then deleted automatically (sooner if you ask) |
| Business correspondence and invoices | As long as the law requires (usually six years for accounting records) |
8. Security
All traffic is encrypted with TLS and HTTPS is enforced. Meta access tokens are encrypted at rest, passwords are hashed, two-factor authentication is available for every account and access is limited by role and by site. Event endpoints only accept requests from each site's allowed domains and are rate limited. Application logs are kept at warning level so routine requests are not written to them.
9. Your rights
Under UK GDPR you can ask to access, correct or delete your personal data, to restrict or object to how we use it, and to receive a copy in a portable format. Email info@weboook.co.uk and we will reply within one month. Because event logs hold only hashed IP addresses, we may not be able to match them to you; the website you visited is best placed to help with those.
You can also complain to the Information Commissioner's Office at ico.org.uk, although we would appreciate the chance to put things right first.
Pixel Relay is a business service and is not directed at children.
10. Changes
We will update this page when our practices change and show the date at the top. Material changes are also sent to customers by email.