Back to blog
AutomationSeptember 1, 2026

We Built a Privacy-First Data Stack for a Client Who Was Freaking Out About Cookies

Built privacy-first data stack for client freaking out about cookies.

We Built a Privacy-First Data Stack for a Client Who Was Freaking Out About Cookies

A general counsel called us last year. They'd just read about Google's third-party cookie deprecation timeline. Their legal team was also dealing with GDPR complaints about data sharing with Facebook. And their CMO was worried that retargeting audiences would shrink to nothing.

The directive: build a privacy-compliant, first-party data stack that doesn't depend on third-party cookies or pixel-based tracking. And do it before the next board meeting in [N] weeks.

What We Had to Replace

Their stack was typical for a [N]-year-old DTC brand:

ComponentStatusPrivacy RiskReplacement
Facebook pixel (browser)ActiveHigh (third-party cookie)Server-side CAPI
Google Analytics 4ActiveMedium (first-party, but shares data)GA4 with consent mode + server-side
Google Ads conversion tagActiveHigh (third-party)Server-side conversion tracking
Klaviyo trackingActiveMedium (loads third-party scripts)Server-side email events
HotjarActiveHigh (session recording, third-party)Self-hosted analytics
Ad platform pixels (TikTok, Pinterest, Snap)ActiveHighServer-side routing
Customer data in warehousePartialLow (first-party, controlled)Expand and enhance

The browser was loading [N] third-party scripts. The consent banner was blocking some, but not all. And the data flowing to Facebook included raw emails, phone numbers, and purchase history.

The 8-Week Build

Week 1: Consent Architecture

Before touching any tracking, we rebuilt consent management. The old way: one "Accept Cookies" button, no granular control, no server-side enforcement, banner loaded after pixels (race condition). The new way: granular consent (Analytics, Marketing, Functional, Personalization), server-side consent state (stored in first-party cookie, readable by backend), consent-aware event routing (no events fire before consent is collected), and consent logging (audit trail for GDPR "how did you get consent?" requests).

Week 2: Server-Side Event Collection

We built a first-party event collection API. Key decisions: first-party domain (events.[PROPERTY].com, same root domain, not third-party), no third-party scripts (all tracking happens via first-party API calls), consent-aware routing (events only route to destinations where user consented), and data minimization (only send data required for the specific destination).

Week 3: Identity Resolution (First-Party)

Instead of relying on Facebook/Google to match users, we built our own identity graph. Same email = same person. Same phone = same person. Shopify customer ID = master. Most recent verified email = fallback. The graph was built entirely from first-party data: email (hashed, never raw), phone (hashed, never raw), first-party cookie (our domain, not third-party), and device fingerprint (for probabilistic matching).

Week 4: Enhanced Conversions (Privacy-Safe)

For ad platforms that need matching, we used enhanced conversions. Facebook CAPI: send SHA-256 hashed email/phone (not raw), first-party cookie ID (not Facebook pixel ID), and event data without PII. Google Ads: use Google Click ID stored in first-party cookie, send hashed email for Customer Match, and use consent mode (send pings without cookies if no consent).

Week 5: Data Warehouse as CDP

We expanded the warehouse to be the central customer data platform. Unified customer profile with total purchases, total revenue, first and last purchase dates, first and last touch channels, segments (VIP, At Risk, New, Regular), and privacy flags (consent analytics, consent marketing, consent date, data processing basis).

Week 6: Reverse ETL (Privacy-Compliant)

We used Hightouch to sync segments to ad platforms: Facebook (hashed emails only, no raw PII), Google (Customer Match with hashed emails), Klaviyo (first-party email list, user consented to marketing), and internal tools (full profile, legitimate interest basis). Each sync included data processing basis, consent timestamp, opt-out mechanism, and audit trail.

Week 7: Testing and Validation

We ran a comprehensive privacy audit: third-party scripts on site (from [N] to 0), raw PII sent to ad platforms (from yes to no, hashed only), consent granularity (from none to 4 categories), server-side consent enforcement (from no to yes), data retention policy (from none to [N] days, auto-delete), GDPR deletion request handling (from manual to automated API endpoint), and cookie banner load order (from after pixels to before everything).

Week 8: Documentation and Handoff

We documented the privacy policy (updated to reflect first-party data practices), cookie policy (granular, per-category explanations), data processing agreement (for each ad platform: what we send, why, how long), GDPR response runbook (how to handle deletion requests, data exports, consent changes), and marketing team guide (what data is available, what requires consent, how to use segments).

The Results

MetricBeforeAfter
Third-party cookies[N]0
First-party data collectionPartialComplete
Retargeting audience size[N][N] (-[PCT]%, but accurate)
Facebook match rate[PCT]%[PCT]% (lower, but privacy-safe)
GDPR compliance riskHighLow
Customer trust (NPS)[N][N] (+[PCT]%)
Data team controlLowHigh (own the pipeline)

The retargeting audiences shrank by [PCT]%. But the remaining audience was higher quality (people who actually consented to marketing). The CAC on retargeting campaigns improved by [PCT]% because we stopped wasting budget on people who didn't want to be tracked.

What We Learned

First-party data is smaller but better. You lose the "spray and pray" retargeting, but you gain precision. The people who consent to marketing are more likely to convert.

Consent is a feature, not a bug. When we made their consent banner clear and granular, consent rates actually increased. Users trust transparent companies.

Hashing is not enough. SHA-256 hashing is deterministic — same email always produces same hash. For true anonymization, we added salt to hashes for non-essential data sharing.

The warehouse is the CDP. You don't need Segment or mParticle if you have a warehouse, dbt, and reverse ETL. And you own the data.

Legal and marketing need to collaborate. The legal team defined the privacy requirements. The marketing team defined the use cases. The data team built the bridge. All three were in the same room for the entire 8 weeks.

Bottom Line

This client went from a third-party cookie dependency to a first-party data foundation in 8 weeks. Their marketing is now privacy-compliant, their data is under their control, and their customers trust them more.

The retargeting audiences are smaller, but the business is stronger. And when Google finally kills third-party cookies, they'll be ready.