Event mapping
Preserve advertising context
visitorId as the order’s top-level SideShift identity. Send the returned context unchanged as the optional advertising object on the Orders API request:
advertising, not the entire order body. Its visitorId is 1–64 characters. landingUrl must be the original HTTPS landing URL, at most 4,096 characters, with no fragment or URL credentials. Preserve advertising click parameters. capturedAt is an ISO UTC timestamp. Do not fabricate either identity when context is unavailable.
Eligible delivery currently requires a connected destination, a positive USD order, a purchase no more than 28 days old and valid advertising context captured within 28 days before purchase, and a non-sample, non-cancelled order. That advertising context window does not extend SideShift’s seven-day creator attribution window. Delivery is asynchronous. Refunds update SideShift commission accounting; they are not emitted as an invented advertising refund event.
Consent and customer matching
The optional SDK loads only after consent. Explicit customer-matching fields on supported browser calls may be forwarded to the advertising destination:email, first_name, last_name, name, phone, external_id, city, state, postal_code, and country. These are not stored in SideShift’s generic browser-event properties. Supply them only when your consent and data-use permissions allow it; they are not required for independent SideShift attribution.
The current advertising SDK is served from https://t.whop.tw/s.js. A restrictive CSP must allow its required script and event connections. The provider may appear in browser network tools or authorization screens even though installation and setup use SideShift.
Automatic form, iframe, link, and URL-identity collection are disabled by this wrapper. One managed destination is bound to a store; this is not arbitrary multi-account event fan-out. Revoking SideShift consent stops SideShift’s forwarding, but does not control a separate SDK independently installed by your site.