SendApp Pixel · installation guide

SendApp Pixel · installation guide

For whoever manages the website. The key of the site is in the email you received, or in SendApp → Pixel → Sites.

5 minutes waits for the cookie banner no full IP, no fingerprint

The code

Paste it once, before </head>, in every page. It creates a small queue and loads the real script without blocking anything.

HTML · before </head>
<!-- SendApp Pixel · SendApp Pixel -->
<script>
(function (w, d) {
  if (w.sendapp) return;
  var f = w.sendapp = function () { f.q.push(arguments); }; f.q = [];
  // the link code leaves the address bar before any other script can read it
  try { var u = new URL(location.href), q = u.searchParams, p = {}, k = ["sa", "sa_debug", "sa_picker"], m = 0;
    for (var i = 0; i < 3; i++) if (q.has(k[i])) { p[k[i]] = q.get(k[i]); q["delete"](k[i]); m = 1; }
    if (m) { f.p = p; history.replaceState(history.state, "", u.toString()); } } catch (e) {}
  var s = d.createElement("script"); s.async = true;
  s.src = "https://app.sendapp.ai/px/v1/p.js";
  d.head.appendChild(s);
})(window, document);
sendapp("init", "pk_...");
</script>

The pk_ key is public: on its own it only lets a browser send events to that site, from the allowed addresses. It is not the API key of the account.

Content Security Policy: add the SendApp host to script-src and connect-src.

WordPress

sendapp-pixel.zip
  1. Download the plugin sendapp-pixel.zip and upload it in Plugins → Add new → Upload plugin.
  2. Activate it, open SendApp in the WordPress menu and paste the public key and the secret of the site.
  3. The plugin writes the code in the head of every page and reads the consent through the WP Consent API (Complianz, CookieYes, Cookiebot and others).

Without the plugin: paste the code in the «header code» field of the theme or of a plugin like WPCode.

WooCommerce

With the same plugin: product viewed, added to cart, checkout started and purchase are reported by themselves. Every order is also confirmed from your server, signed with the secret of the site: the revenue in SendApp is the real one, refunds included.

PrestaShop

sendapppixel.zip
  1. Download the module sendapppixel.zip and upload it in Modules → Module Manager → Upload a module.
  2. Press «Configure», paste the public key and the secret.
  3. The module uses the hooks displayHeader, displayOrderConfirmation and the order validation: product, cart, checkout and purchase, confirmed from the server.

Shopify

The Shopify checkout is closed: checkout and purchase events can be read only from «Customer events» (Web Pixels API).

  1. Online store → Themes → Edit code → theme.liquid: paste the code before </head>.
  2. Settings → Customer events → Add custom pixel «SendApp Pixel»: paste the code shown in SendApp → Pixel → Sites → Code → Shopify, Permission: required for marketing and analytics.

Wix

Settings → Custom code → Add custom code (Premium plan with a connected domain). All pages · Load once · Head. Category: Advertising, so the Wix banner blocks it until the visitor accepts. Purchases: mark the confirmation page as a conversion in SendApp.

Webflow · Squarespace · Framer

Webflow: Site settings → Custom code → Head code, then Publish. Squarespace: Settings → Advanced → Code injection → Header. Framer: Site settings → General → Custom code → end of head. Framer changes page without reloading: the Pixel handles it by itself.

Google Tag Manager

Tags → New → Custom HTML with the code, trigger «Consent Initialization – All Pages». The Pixel reads the Consent Mode (gtag consent update) from the dataLayer by itself, and the GA4 e-commerce events (view_item, add_to_cart, begin_checkout, purchase).

React, Next.js, Vue, Nuxt

app/layout.jsx
import Script from "next/script";

<Script id="sendapp-pixel" strategy="beforeInteractive">{`
  (function(w,d){if(w.sendapp)return;var f=w.sendapp=function(){f.q.push(arguments)};f.q=[];
  try{var u=new URL(location.href),q=u.searchParams,p={},k=["sa","sa_debug","sa_picker"],m=0;
  for(var i=0;i<3;i++)if(q.has(k[i])){p[k[i]]=q.get(k[i]);q["delete"](k[i]);m=1}
  if(m){f.p=p;history.replaceState(history.state,"",u.toString())}}catch(e){}
  var s=d.createElement("script");s.async=true;s.src="https://app.sendapp.ai/px/v1/p.js";d.head.appendChild(s)})(window,document);
  sendapp("init","pk_…");
`}</Script>

Page views arrive by themselves (pushState, replaceState, popstate). Actions that are not clicks or forms: sendapp("track", "name", {value: 420}).

Commands

sendapp("init", "pk_…")Starts the Pixel for that site.
sendapp("consent", {analytics, marketing})Tells the Pixel what the visitor chose. With both false it deletes cookie and ids.
sendapp("track", "name", {…})Records an action, with optional value, currency, order_id, items.
sendapp("page")Records a page view, for unusual routers.
sendapp("identify", {email, ts, sig})Links the visitor to a contact after the login. Ignored without the marketing consent.
sendapp("optout")The visitor objects: cookie deleted, deletion requested, a technical cookie remembers it for 12 months.
SendAppPixel.visitorId()The visitor id, or null without consent.

Verification mode: open any page with ?sa_debug=1 — the Pixel writes in the browser console every event it sends and why.

Signed identify

A customer area can identify the logged-in visitor with a signature computed on its own server: the identity then counts as verified.

PHP
<?php
$secret = getenv('SENDAPP_PIXEL_SECRET'); // SendApp → Pixel → Settings → Security
$email = strtolower(trim($customer->email));
$ts = time();
$sig = hash_hmac('sha256', $email . '|' . $ts, $secret);
echo '<script>sendapp("identify", ' . json_encode(['email' => $email, 'ts' => $ts, 'sig' => $sig]) . ');</script>';

SendApp accepts the signature for one hour and only if the email matches a contact of the account.

Automations about browsing (pages, checkout left, purchase, return, interest) start only for a visitor known for certain: the link of a message, the WhatsApp code, a signed identify or an order confirmed by the shop. A number typed in a form, or an identify without signature, is only declared: it can start the automation of that form, nothing else.

Events from your server

Shop sales, management software, renewals, phone orders. Authentication like the other endpoints: X-API-Key. event_id makes a retry harmless.

cURL
curl -X POST https://app.sendapp.ai/api/pixel/events \
  -H "X-API-Key: $SENDAPP_API_KEY" -H "Content-Type: application/json" \
  -d '{"site":"pk_…","events":[{"name":"purchase","event_id":"shop-55120",
       "occurred_at":"2026-09-24T16:42:10+02:00","contact":{"phone":"+393475550192"},
       "value":420.00,"currency":"EUR","order_id":"55120"}]}'
# 202 {"accepted":1,"duplicates":0,"rejected":[]}

Privacy: the Pixel never saves the full IP address, never builds a fingerprint of the browser and never links two different shops. The cookie _sa_vid lasts 6 months and is set only after the consent.

SendApp Pixel