Skip to documentation
Browse 13 guides

User guide

Visitor intelligence and webhooks

Tailwin’s first-party pixel records privacy-bounded site activity, then optional server-side vendors can resolve a network to a company. Tailwin adds deterministic intent signal…

Updated September 28, 2026

On this page
  1. Install the pixel
  2. Consent connection
  3. What is recorded
  4. Company identification
  5. Intent and live status
  6. Send events to a CRM, Zapier, Make, or n8n
  7. Privacy operating rules
  8. Attribution foundation

Tailwin’s first-party pixel records privacy-bounded site activity, then optional server-side vendors can resolve a network to a company. Tailwin adds deterministic intent signals and can send company events to an authorized webhook.

Install the pixel

  1. Open Visitors for the correct organization and site.
  2. Copy the site’s pixel snippet or public pixel ID.
  3. Install it once in the site template or tag manager.
  4. Connect your consent manager as described below, then load the site in a fresh browser session and grant tracking consent.
  5. Confirm that a visit appears before enabling paid identification.

The pixel is for human visitor journeys. AI crawler tracking uses a separate server-side tracker.

The pixel waits until window.tailwinConsent is "granted". Set that value only when your consent manager has the visitor's applicable permission. When consent changes, set window.tailwinConsent to "granted" or "denied", then call window.dispatchEvent(new Event("tailwin:consent")). Denial stops collection and removes the browser visitor ID. Do Not Track and Global Privacy Control also stop collection. Older installations need this consent connection before the updated tracker sends events.

What is recorded

The pixel records bounded page and engagement events, including page views, dwell, telephone clicks, email clicks, and form-submission occurrence. It does not collect form field values and does not perform fingerprinting or session replay.

Tailwin hashes IP data used in the resolution path. Raw IP addresses are not emitted in outbound visitor webhooks.

Company identification

Identification adapters run asynchronously so a paid, slow lookup never blocks a visitor’s page. The configured chain can include IPinfo, Snitcher, Happierleads, OpenSend, and FullContact and stops at the first confident match.

Company-level identification is the default. Person-level contacts require both the organization’s visitor-contact consent and a webhook configured to include contacts. Keep that option off unless the legal basis and customer notice are in place.

Intent and live status

Intent is a deterministic 0–100 score derived from named paths and engagement signals. It is not a predictive model. The same event journey should produce the same score. A company is shown as live when its latest qualifying activity is recent; the interface states the threshold.

Open a company dossier to review its visits, pages, signals, first/last activity, and identification evidence before outreach.

Send events to a CRM, Zapier, Make, or n8n

  1. Create an HTTPS inbound URL in the destination.
  2. Open Visitors → Webhooks.
  3. Add the URL and choose whether authorized contacts may be included.
  4. Store the displayed signing secret securely.
  5. Verify X-Tailwin-Signature over the raw request body in the receiver.
  6. Test with a controlled company event.

Events include visitor.company_identified for the first match and visitor.company_returned for a known company that returns. Return events are throttled to avoid repeated notifications.

Webhook delivery failure does not undo identification. Review delivery status and retry behavior at the destination.

Privacy operating rules

  • Publish an accurate privacy notice before installing the pixel.
  • Honor applicable consent and opt-out requirements.
  • Do not enable person contacts by convenience.
  • Do not place field values or secrets in event metadata.
  • Revoke webhooks that are no longer owned by the customer.
  • Treat an identified company as a sales signal, not proof about a specific person.

Attribution foundation

Page activity carries an event ID so retries and matching server events count once. Query strings are removed from stored page paths; approved campaign and click-ID fields, including Dub click IDs, are retained separately. A form interaction is an activity signal, not proof of a confirmed lead or purchase.

The payment ledger foundation retains verified processor records and flags missing sales, currency mismatches and excessive adjustments. Live provider ingestion and unified revenue dashboards are still in development; pixel installation alone does not activate them.