Reference

CRM Sync — Migration Guide: CSV & Legacy Tools → Connected Streams

For: Marketing ops, analytics teams, and CRM administrators planning the transition Date: 2026-05-18


The Problem

Your team is likely still using some combination of these workflows:

Each of these workflows has a common flaw: no consent enforcement, no audit trail, and no automatic propagation when something changes. If a customer asks to be deleted, you have to manually find and remove their data from every spreadsheet, every CRM, every analytics platform. If consent changes, the CSV you exported yesterday is already stale.

Google, Shopify, and regulators are all moving to enforce this. The deadlines are not future — most have already passed.


What's Already Changed

ChangeWhenImpact
Universal Analytics stopped processing dataJuly 2024UA-shaped exports contain no new data. Any workflow built on UA goals, custom dimensions, or page-view conversions is dead.
Google requires consent_mode v2 in EEAMarch 2024Ads campaigns without the four new consent signals lose remarketing and conversion tracking
Shopify Customer Privacy API required for new apps2025-2026Apps that don't implement consent signaling will be rejected from the App Store
Google Merchant Center moving to server-side feeds2025-2026CSV product feeds are being deprecated for most categories
GDPR enforcement increasing for "consent laundering"2026 onwardImporting contacts without verifiable consent is a regulatory target

What Needs to Migrate

Google Analytics: Page Views → Events

Google Analytics 4 fundamentally changed how conversions work. This affects every tool that reports on conversions:

Old Way (Universal Analytics)New Way (GA4)What Breaks
Track conversions by URL path (/thank-you)Track conversions by event name (purchase, sign_up)Any tool that counts conversions by page URL stops working
Set conversion value once (static)Value is on each event (dynamic)CSV-imported static goal values don't exist anymore
Session-based attribution (last click)Event-based, data-driven attributionCRM systems importing UA session data need to import GA4 event data instead
2 consent signals (basic/advanced)4 consent signals (ad_storage, analytics_storage, ad_user_data, ad_personalization)Consent banners must emit all four signals or lose ad functionality
Old WayNew WayWhy
OneTrust sets a cookie in the browserCRM Sync stores consent in the database (Xano)Cookies get cleared. Server-side consent persists.
Consent state lives in the browser onlyConsent state is verified on the server before any data is sentAn AI agent or automated system can check consent via API — you can't check a cookie from a server
Consent changes don't propagateConsent change → all connected platforms notified in the same requestWhen a customer opts out of marketing, Klaviyo, HubSpot, and GA4 all know immediately
No audit trail of consent changesEvery consent change logged with timestamp, source, and which systems were notifiedRequired for GDPR Art. 15 (right of access) and Art. 30 (records of processing)

Note: CRM Sync doesn't replace your consent banner (OneTrust or similar). It replaces the server-side consent enforcement that your banner doesn't provide. Your banner tells the browser what's allowed. CRM Sync tells the server what's allowed.

Customer Data: CSV Export/Import → Connected Streams

Old WayNew WayWhy
Export customers.csv from ShopifyReal-time webhook + sync every 15 minutesMax data staleness = 15 minutes, not hours/days
Upload CSV to HubSpot / Salesforce / KlaviyoConnected stream pushes data when it changesNo manual step, no stale data, no duplicate contacts
No consent check on CSV importEvery data push checks consent before sending"Consent laundering" (importing contacts without verified consent) is a growing regulatory target
No record of what was sent whereEvery outbound push logged per platformYou can answer "which systems have this customer's data?" instantly
No deletion propagationGDPR deletion handler removes data from all connected systemsCustomer requests deletion → all platforms notified automatically

Impact on Specific Tools

Matrixify (formerly Excelify)

What it does: Bulk import/export Shopify data via CSV/Excel.

What to keep: Product bulk operations (that's PIM Sync's domain, not CRM Sync).

What to replace: Customer data exports and imports. Matrixify CSVs have no consent enforcement, no audit trail, and customer PII sitting in your Downloads folder. Replace with CRM Sync's authenticated API endpoints that check consent before every data transfer.

What to keep: The consent banner UI that customers see and interact with.

What to augment: Server-side consent enforcement. OneTrust manages the user experience. CRM Sync manages the truth — storing consent in the database, checking it before every data push, and logging every change.

HubSpot / Salesforce / Klaviyo CSV Imports

What to replace: All CSV-based customer imports. Each platform gets a connected stream through CRM Sync that:

Google Merchant Center CSV Feeds

What to replace: Manual CSV product feeds. Use Shopify's Google & YouTube channel (server-side sync) or CRM Sync's connected stream infrastructure for custom feeds.

UA Goal-Based Reporting (Looker, Tableau, Custom Dashboards)

What to replace: Any dashboard that queries Universal Analytics goal data. There is no migration path — UA goals are structurally incompatible with GA4. Dashboards must be rebuilt on GA4 event data.


Decision Matrix

Legacy ToolKeep / Replace / AugmentRationale
MatrixifyReplace (for customer data)No consent enforcement, PII in CSVs. Keep for product bulk ops only.
OneTrustAugmentKeep the banner. Add server-side consent enforcement via CRM Sync.
HubSpot CSV ImportReplaceUse connected stream. Consent-gated, logged, deduplicated.
Salesforce Data LoaderReplaceUse connected stream. No flat-file PII.
Klaviyo CSV List ImportReplaceUse connected stream. Email consent verified per subscriber.
Google Merchant CSV FeedReplaceUse Shopify's Google channel or Content API.
UA Goal-Based ReportingReplaceRebuild on GA4 events. No migration path.
Shopify Customer CSV ExportReplaceUse authenticated API endpoint. No PII in downloads.

Implementation Timeline

PhaseTimelineWhat Happens
Phase 1Week 1-2Upgrade consent banner to GA4 consent_mode v2. Add audit logging. Rate limit auth endpoints.
Phase 2Week 3-4Build connected stream infrastructure. Add per-platform sync logging. UCP dashboard shows sync history.
Phase 3Week 5-8Connect enterprise platforms (Salesforce, Klaviyo, HubSpot, Braze, Attentive).
Phase 4Week 9-10Deprecate CSV imports. Archive UA references. Complete compliance certification.

The Bottom Line

Organizations still using CSV workflows for customer data are accumulating compliance debt with each passing month. The page-view conversion schema is already dead. The consent requirements are already enforced. The question is not whether to migrate, but how much process debt to carry forward.

CRM Sync replaces manual, file-based, consent-blind data handoffs with authenticated, logged, consent-aware connections — and every new platform you add inherits the same protections automatically.


Technical reference: FEATURE-SPEC-UA-MIGRATION.md