Server-Side Tracking That Survives Browser Restrictions
We build first-party GTM server containers that keep your conversion data flowing after ITP, ad blockers, and cookie consent have taken their cut.
Get My Free Tracking Audit →Not ready to write it all out? Book a 15-minute discovery call →
Your Tags Are Losing Data
Your browser-side tags are losing data and you can see it in the gap between your platform's reported conversions and what actually landed in your order table.
Safari's Intelligent Tracking Prevention caps first-party cookies set via JavaScript at seven days. Firefox blocks known trackers outright. A meaningful share of your traffic runs an ad blocker that never lets `gtm.js` load in the first place. Every one of those sessions is a purchase your ad platform never learns about — which means it never learns what a buyer looks like, which means your bidding algorithm optimises against an incomplete picture.
Server-side tagging moves the collection layer off the user's browser and onto infrastructure you control. Events are captured first-party, enriched server-side, and forwarded to each destination from your own endpoint. Cookies are set via HTTP headers instead of JavaScript, so they survive.
This is not a plugin you install. It is data architecture, and it breaks in quiet, expensive ways when it is done casually.
What We Build
Server Container Architecture
A production GTM server container sized to your traffic, on Google Cloud Run or your own infrastructure.
- Cloud Run deployment with autoscaling and cost ceilings
- Self-hosted option on your VPS for full data control
- Custom subdomain on your root domain for true first-party context
- SSL, DNS, and health-check configuration
- Preview and staging environments separated from production
First-Party Data Layer
A clean, complete dataLayer is the foundation. Most audits we run find it broken before anything else.
- Full WooCommerce e-commerce dataLayer: view_item, add_to_cart, begin_checkout, purchase
- Consistent, validated item schema across every event
- User-scoped identifiers for logged-in customers
- Multi-currency and multi-region handling
- Form and lead events for non-transactional funnels
Destination Tagging
- GA4 via server container with unified session handling
- Meta Conversions API with deduplication
- Google Ads Enhanced Conversions
- Microsoft Ads UET
- Custom HTTP destinations to your own CRM or warehouse
Identity & Matching
- SHA-256 hashing of email, phone, and name before transmission
- Stable `external_id` generation and persistence
- FBC / FBP capture and server-side forwarding
- GCLID and click-ID persistence beyond browser cookie limits
Validation
- Event-level reconciliation against your order database
- Deduplication verification in each platform's diagnostics
- Consent-state testing across granted, denied, and partial scenarios
- Documented handover so your team can maintain it
How We Work
Step 01 — Audit
We map every event currently firing, compare against your order data, and quantify what you are losing.
Step 02 — Architecture
We design the container topology, hosting model, and cost forecast before writing anything.
Step 03 — Build
Container deployment, dataLayer implementation, tag configuration, consent wiring.
Step 04 — Validate
Side-by-side reconciliation until server-side and platform-reported numbers agree.
Step 05 — Handover
Full documentation, container export, and a walkthrough with your team.
What Happens Next
Step 01 — You hear back within 24 hours.
A real reply from the person who would do the work, not an autoresponder or a junior scheduling a call about a call.
Step 02 — We look before we talk.
Send us access or a URL and we review your actual setup first, so the conversation starts with findings instead of discovery questions.
Step 03 — 30 minutes, findings first.
We walk you through what we found and what it is costing. You get that regardless of whether you hire us.
Step 04 — A written scope, or an honest no.
If it is a fit, you get scope, timeline, and cost in writing. If it is not, we say so and point you somewhere better.
No retainer required. No minimum term. No obligation at any step.
CAPI Event Coverage
Full Meta Conversions API with server-side deduplication, external_id matching, and Consent Mode — zero data loss post-iOS.
Is This Right For You?
We would rather tell you now than after an invoice. Here is who this work pays off for, and who it does not.
A good fit if:
- You are doing €25,000+ per month in online revenue, where a few percent of recovered attribution is real money
- You are running paid media and the reported numbers do not match your bank
- You sell across more than one market, currency, or storefront
- You have a developer or agency who can act on what we find
- You want to own the implementation afterwards, not rent it
Probably not a fit if:
- You are early stage and validating the product — fix demand first, measure it later
- You want someone to manage ad spend day to day; we build the measurement layer, we are not a media buying agency
- You need it live this week; proper implementation has a validation phase and we will not skip it
- You want the cheapest quote — we are not it, and the cheapest tracking build usually gets rebuilt
Most engagements start from €1,500. We confirm scope and cost in the discovery call, before anything is committed.
Tell us about your setup. We respond within 24 hours.
Not ready to write it all out? Book a 15-minute discovery call →
Common
Questions
No, and any agency telling you it does is selling you a compliance problem. Server-side tagging changes where data is processed, not whether you need permission to process it. We build every container with Consent Mode v2 wired in, so denied consent means signals only — never identifiable data.
Hosting is usage-based. On Google Cloud Run, cost scales with request volume and container instances. We forecast your monthly spend during the architecture phase using your actual traffic, and configure autoscaling ceilings so it cannot run away. You approve the number before we deploy.
No. We run the server container in parallel with your current client-side setup, reconcile the two, and only cut over once numbers agree. Nothing is switched off until the replacement is proven.
Yes. We deploy server containers on your own VPS or private cloud using Docker for clients who need data to stay within specific infrastructure. We size the instance and configure monitoring as part of the build.
Most server-side builds run three to five weeks end to end. The container deployment itself takes days; the time goes into the dataLayer work and the validation phase, where we reconcile server-side events against your order table until the numbers agree. Complex multi-market setups take longer, and we tell you which category you are in after the audit rather than quoting a timeline before we have seen your stack.
Implementation typically starts around €1,500 for a single-market setup and scales with the number of storefronts, destinations, and the state of your existing dataLayer. Separately, hosting the container costs a usage-based monthly amount that we forecast from your actual traffic before deployment. We give you both numbers in writing after the audit, and you approve them before any work starts.
Often not, and we will say so. The work has a fixed cost regardless of your revenue, so the return depends on how much data you are actually losing and what that data is worth. Below roughly €25,000 per month in online revenue, the payback period usually stretches past a year. Above it, recovered attribution tends to cover the build within a quarter. The audit gives you the number for your situation.
A plugin fires tags from the visitor's browser, so it inherits every browser restriction — ITP cookie limits, ad blockers, consent denials. Server-side tracking moves collection onto infrastructure you control, sets cookies via HTTP headers instead of JavaScript, and forwards enriched events to each destination from your own endpoint. They solve different problems. A plugin is configuration; this is data architecture.
Yes, and if you have an in-house developer comfortable with GTM and cloud infrastructure, that is a reasonable path — the documentation is public and the tooling is not exotic. Where teams typically get caught is deduplication, identity persistence, and consent forwarding, which fail silently and look correct in the interface. If you want to try it in-house, the audit will still tell you what is currently broken.
It usually makes it faster. Moving tag execution off the browser removes third-party JavaScript from the main thread, which is often the largest contributor to poor interaction responsiveness on e-commerce sites. The server container adds latency to the data pipeline, not to page rendering. Your visitors do not wait for it.
Ready to Build Something That Works?
Book a free 30-minute strategy audit. No pitch deck, no pressure — just an honest look at your setup and what to fix first.
Not ready to write it all out? Book a 15-minute discovery call →
