The code
Paste it once, before </head>, in every page. It creates a small queue and loads the real script without blocking anything.
<!-- SendApp Pixel · SendApp Pixel -->
<script>
(function (w, d) {
if (w.sendapp) return;
var f = w.sendapp = function () { f.q.push(arguments); }; f.q = [];
// the link code leaves the address bar before any other script can read it
try { var u = new URL(location.href), q = u.searchParams, p = {}, k = ["sa", "sa_debug", "sa_picker"], m = 0;
for (var i = 0; i < 3; i++) if (q.has(k[i])) { p[k[i]] = q.get(k[i]); q["delete"](k[i]); m = 1; }
if (m) { f.p = p; history.replaceState(history.state, "", u.toString()); } } catch (e) {}
var s = d.createElement("script"); s.async = true;
s.src = "https://app.sendapp.ai/px/v1/p.js";
d.head.appendChild(s);
})(window, document);
sendapp("init", "pk_...");
</script>The pk_ key is public: on its own it only lets a browser send events to that site, from the allowed addresses. It is not the API key of the account.
Content Security Policy: add the SendApp host to script-src and connect-src.
WordPress
- Download the plugin sendapp-pixel.zip and upload it in Plugins → Add new → Upload plugin.
- Activate it, open SendApp in the WordPress menu and paste the public key and the secret of the site.
- The plugin writes the code in the head of every page and reads the consent through the WP Consent API (Complianz, CookieYes, Cookiebot and others).
Without the plugin: paste the code in the «header code» field of the theme or of a plugin like WPCode.
WooCommerce
With the same plugin: product viewed, added to cart, checkout started and purchase are reported by themselves. Every order is also confirmed from your server, signed with the secret of the site: the revenue in SendApp is the real one, refunds included.
PrestaShop
- Download the module sendapppixel.zip and upload it in Modules → Module Manager → Upload a module.
- Press «Configure», paste the public key and the secret.
- The module uses the hooks displayHeader, displayOrderConfirmation and the order validation: product, cart, checkout and purchase, confirmed from the server.
Shopify
The Shopify checkout is closed: checkout and purchase events can be read only from «Customer events» (Web Pixels API).
- Online store → Themes → Edit code → theme.liquid: paste the code before </head>.
- Settings → Customer events → Add custom pixel «SendApp Pixel»: paste the code shown in SendApp → Pixel → Sites → Code → Shopify, Permission: required for marketing and analytics.
Wix
Settings → Custom code → Add custom code (Premium plan with a connected domain). All pages · Load once · Head. Category: Advertising, so the Wix banner blocks it until the visitor accepts. Purchases: mark the confirmation page as a conversion in SendApp.
Webflow · Squarespace · Framer
Webflow: Site settings → Custom code → Head code, then Publish. Squarespace: Settings → Advanced → Code injection → Header. Framer: Site settings → General → Custom code → end of head. Framer changes page without reloading: the Pixel handles it by itself.
Google Tag Manager
Tags → New → Custom HTML with the code, trigger «Consent Initialization – All Pages». The Pixel reads the Consent Mode (gtag consent update) from the dataLayer by itself, and the GA4 e-commerce events (view_item, add_to_cart, begin_checkout, purchase).
React, Next.js, Vue, Nuxt
import Script from "next/script";
<Script id="sendapp-pixel" strategy="beforeInteractive">{`
(function(w,d){if(w.sendapp)return;var f=w.sendapp=function(){f.q.push(arguments)};f.q=[];
try{var u=new URL(location.href),q=u.searchParams,p={},k=["sa","sa_debug","sa_picker"],m=0;
for(var i=0;i<3;i++)if(q.has(k[i])){p[k[i]]=q.get(k[i]);q["delete"](k[i]);m=1}
if(m){f.p=p;history.replaceState(history.state,"",u.toString())}}catch(e){}
var s=d.createElement("script");s.async=true;s.src="https://app.sendapp.ai/px/v1/p.js";d.head.appendChild(s)})(window,document);
sendapp("init","pk_…");
`}</Script>Page views arrive by themselves (pushState, replaceState, popstate). Actions that are not clicks or forms: sendapp("track", "name", {value: 420}).
Commands
sendapp("init", "pk_…") | Starts the Pixel for that site. |
sendapp("consent", {analytics, marketing}) | Tells the Pixel what the visitor chose. With both false it deletes cookie and ids. |
sendapp("track", "name", {…}) | Records an action, with optional value, currency, order_id, items. |
sendapp("page") | Records a page view, for unusual routers. |
sendapp("identify", {email, ts, sig}) | Links the visitor to a contact after the login. Ignored without the marketing consent. |
sendapp("optout") | The visitor objects: cookie deleted, deletion requested, a technical cookie remembers it for 12 months. |
SendAppPixel.visitorId() | The visitor id, or null without consent. |
Verification mode: open any page with ?sa_debug=1 — the Pixel writes in the browser console every event it sends and why.
Consent
Without a choice in the banner nothing is written in the browser. The Pixel reads by itself: CookieYes, Cookiebot, Complianz, OneTrust, Iubenda, WP Consent API, Google Consent Mode, Shopify Customer Privacy. For a custom banner:
// when the visitor chooses in your banner
sendapp("consent", { analytics: true, marketing: false });
// when the consent is withdrawn
sendapp("consent", { analytics: false, marketing: false });CookieYes: in its Cookie Manager add the cookie _sa_vid under «Analytics». CookieYes hides the switch of a category without cookies, and the visitor could then only accept everything or refuse everything.
Signed identify
A customer area can identify the logged-in visitor with a signature computed on its own server: the identity then counts as verified.
<?php
$secret = getenv('SENDAPP_PIXEL_SECRET'); // SendApp → Pixel → Settings → Security
$email = strtolower(trim($customer->email));
$ts = time();
$sig = hash_hmac('sha256', $email . '|' . $ts, $secret);
echo '<script>sendapp("identify", ' . json_encode(['email' => $email, 'ts' => $ts, 'sig' => $sig]) . ');</script>';SendApp accepts the signature for one hour and only if the email matches a contact of the account.
Automations about browsing (pages, checkout left, purchase, return, interest) start only for a visitor known for certain: the link of a message, the WhatsApp code, a signed identify or an order confirmed by the shop. A number typed in a form, or an identify without signature, is only declared: it can start the automation of that form, nothing else.
Events from your server
Shop sales, management software, renewals, phone orders. Authentication like the other endpoints: X-API-Key. event_id makes a retry harmless.
curl -X POST https://app.sendapp.ai/api/pixel/events \
-H "X-API-Key: $SENDAPP_API_KEY" -H "Content-Type: application/json" \
-d '{"site":"pk_…","events":[{"name":"purchase","event_id":"shop-55120",
"occurred_at":"2026-09-24T16:42:10+02:00","contact":{"phone":"+393475550192"},
"value":420.00,"currency":"EUR","order_id":"55120"}]}'
# 202 {"accepted":1,"duplicates":0,"rejected":[]}Privacy: the Pixel never saves the full IP address, never builds a fingerprint of the browser and never links two different shops. The cookie _sa_vid lasts 6 months and is set only after the consent.
SendApp Pixel