Where attribution tools get data: pixels, APIs, exports
Attribution tools get data by browser pixel, server-to-server call, platform API or analytics file, and each route loses something first. Comparing one week of orders across Shopify, GA4 and the tool shows your own gap.
€99 once, excl. VAT. Full refund within 30 days, no questions asked. You keep the read.
By Joris van Huët, Founder & CEOPublished 6 min read
Run the numbers for your store: the free customer journey credit calculator.
An attribution tool sees only what reaches it by one of four routes: a script in the browser, a server-to-server call, a pull from an ad platform's reporting API, or a file from your own analytics. Each route drops something first. WebKit's tracking prevention, which Safari applies, deletes script-written cookies after 7 days of no user interaction with the site and caps them at 24 hours when it detects link decoration. To see what your tool missed, count one week of orders in Shopify, in GA4 and in the tool, and split by browser.
What does a browser pixel collect, and what does it lose?
Shopify describes pixels as JavaScript code snippets that run on the online store and collect behavioral data, which it calls customer events. Three things can stand between that code and the tool:
- Consent. Shopify says its web pixel extensions honor the consent signals the visitor chose, so what a pixel can send depends on that choice.
- Storage rules. WebKit says its tracking prevention deletes all cookies created in JavaScript, and other script-writeable storage, after 7 days of no user interaction with the website, and caps the expiry of script-written cookies on a landing page at 24 hours when it detects link decoration.
- Delivery. Meta's documentation says the Conversions API lets you share website events that the Pixel may lose due to network connectivity issues or page loading errors.
One peer-reviewed measurement of the consent route exists, and it is narrow. Aridor, Che and Salz (RAND Journal of Economics, 2023) used data from an online travel intermediary and report that the GDPR's opt-in requirement resulted in a 12.5% drop in the intermediary-observed consumers, while the remaining consumers could be tracked for a longer period. It covers one travel intermediary and counts observed consumers, not orders, so it shows that the effect is real, not what it is for your store.
What changes when events go server to server?
A server call sends the event from your backend instead of the visitor's browser. It doesn't replace the pixel. Meta tells advertisers to use the Conversions API in addition to the Meta Pixel and to share the same events with both, a redundant setup, using the same event name and an event ID so the duplicate can be removed. Google says the same of its Measurement Protocol: its intent is to augment automatic collection through gtag, Tag Manager and Firebase, not to replace it. The page, last updated on 8 June 2026, adds that Google recommends building server-to-server event integrations on the Data Manager API.
A server event also needs a key to tie it to an ad click. Meta's documentation says you must provide at least one of its customer information parameters, and it describes the fbp and fbc values as cookies typically set in your site visitors' browsers. The server route still leans on the browser for part of its matching.
What do platform APIs and GA4 exports contain?
A platform API returns that platform's own credit. Meta's Ads Insights API returns actions under the attribution windows you request, such as 1-day click, 7-day click, 28-day click or 1-day view. Meta said the API would stop returning the 7-day view and 28-day view windows from 12 January 2026.
GA4 gives you two files: the BigQuery export of raw events, and the file you download from a report, which holds the aggregated rows the report shows. Google's BigQuery export page says BigQuery holds only the raw event data Google Analytics received, and that standard properties have a daily export limit of 1 million events. Its table of export types lists the daily export as last click observed, no modeling. GA4's reports can fill gaps left by denied consent with modeled data, but Google says that needs at least 1,000 events per day with analytics storage denied for at least 7 days, and at least 1,000 daily users with it granted on at least 7 of the previous 28 days.
What a file route avoids: another script on your storefront, another vendor receiving event-level data and an API token to maintain. What it can't avoid: anything GA4 never recorded.
Your store is the fourth source. An order exists in Shopify whether or not any script fired, so it is the count the other sources are checked against. Shopify's customer journey summary adds a first visit, a last visit and the moments between, using a 30-day attribution window.
No page read for this post gives a loss rate for ecommerce stores, for blockers or for Safari's storage limits. The only figure that matters is your own.
How do I check what my tool actually received?
- Pick one recent full week. Count Shopify orders for it, leaving out test and cancelled orders, in the store's time zone.
- Count GA4 purchases for the same dates. Check the property's time zone first: Google says export tables follow it.
- Count the purchases your attribution tool or ad platform reports for the same dates.
- Divide GA4's purchases and the tool's purchases by Shopify's orders. Then split GA4 and the tool by browser and by country.
Pass: the ratios are similar across browsers and countries, and the tool's ratio is close to GA4's. Fail: one browser's ratio is clearly lower than the others, which points at the browser route; one country's is lower, which points at consent; or the tool's ratio sits well below GA4's, which points at the tool's own collection. Fix the gap you can name before you read any channel numbers from that tool.
Sources, 30 September 2026: About web pixels (Shopify, 2026); CustomerJourneySummary (Shopify Admin GraphQL API, 2026); Tracking Prevention in WebKit (WebKit, 2026); The Effect of Privacy Regulation on the Data Industry: Empirical Evidence from GDPR (Aridor, Che and Salz, NBER Working Paper 26900, 2020; RAND Journal of Economics, 2023); Conversions API best practices and customer information parameters (Meta for Developers, 2026); Ads Insights API Metric Availability Updates (Meta for Developers, 16 October 2025); Measurement Protocol (Google for Developers, 2026); BigQuery Export and Behavioral modeling for consent mode (Google Analytics Help, 2026).
Related answers
Frequently asked questions
Does server-side tracking fix ad blockers and cookie limits?
Not fully. Meta tells advertisers to use its Conversions API in addition to the Pixel, not instead of it, and some of its matching keys are cookie values set in the browser. Server-side calls can share events the pixel may lose, but they still depend on what the browser kept.Why don't GA4 purchases match Shopify orders?
GA4 counts events its tag received from browsers, while Shopify records every order that was placed. Consent, browser storage rules, delivery errors and time zone settings can each open a gap. Count one week of each, split GA4 by browser and country, and the pattern shows which cause is yours.Is a GA4 export better than a pixel for attribution?
It avoids adding a script and another recipient of event data, but it holds only what GA4 recorded. Neither route is complete, so compare both with Shopify's order count.
Go deeper: Incrementality testing, explained.
Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.
Keep reading
Terms in this article
- AnalyticsAnalytics is the systematic computational analysis of data. It reveals customer behavior and measures campaign performance.
- AttributionAttribution identifies user actions that contribute to a desired outcome and assigns value to each. It reveals which marketing touchpoints drive conversions.
- Attribution WindowAttribution Window is the defined period after a user interacts with a marketing touchpoint, during which a conversion can be credited to that ad. It sets the timeframe for assigning conversion credit.
- Causal AttributionCausal Attribution uses causal inference to determine which marketing touchpoints genuinely cause conversions, not just correlate with them.
- ConversionConversion is a specific, desired action a user takes in response to a marketing message, such as a purchase or a sign-up.
- Customer journeyCustomer journey is the path and sequence of interactions customers have with a website. Customers use multiple devices and channels, making a consistent experience crucial.
- Google AnalyticsGoogle Analytics is a web analytics service that tracks and reports website traffic.
- Landing PageLanding Page: A single web page that appears after clicking a search result, marketing promotion, email, or online advertisement.