What is server-side tracking?
Server-side tracking sends your store's events to GA4 or Meta through a server, not straight from the shopper's browser. It can recover events that ad blockers drop. It does not label untagged visits, skip consent or show which channel caused a sale.
By Joris van Huët, Founder & CEOUpdated 7 min read
Run the numbers for your store: the free server-side tracking ROI calculator.
Server-side tracking means your store's events reach Google or Meta through a server, not straight from the shopper's browser. Usually a server you control receives each event first, or your store's server sends the order itself. It can recover events that ad blockers drop. It cannot tell you which channel caused a sale.
In the usual setup, every tag runs in the shopper's browser and posts its own data to its own vendor. Google's docs describe it as a container in the page sending data to several collection servers. Server-side tracking moves some of that work off the page.
It comes in two shapes, and plenty of stores end up running both.
- A server container. The browser sends one stream of events to a tagging server you run, usually on Google Cloud through Google Tag Manager. That server passes the data on to GA4, Google Ads or other tools. Google says only you can see the data on that server until you send it elsewhere.
- Server to server. Your store's own systems report the event straight to the platform. On Shopify, the Enhanced and Maximum data-sharing levels add Meta's Conversions API, which sends the purchase between Shopify's and Meta's servers. GA4's version is the Measurement Protocol, which Google says should add to your tags, not replace them.
Why bother? Google lists faster pages, because fewer tags run in the browser, and tighter control over what each vendor receives. Shopify's help adds the reason most stores actually care about: data sent from server to server can't be blocked by browser-based ad blockers.
What one store's data shows
One store's anonymised GA4 export, 1 January 2024 to 21 August 2026. It holds shares of revenue only: no ad spend, no order counts.
| What the export shows | Share of revenue | Source cell |
|---|---|---|
| Direct, in last click, first click and touched views | 57.7% | Channels sheet, Direct row |
| Paid Social, in all three views | 0.0% | Channels sheet, Paid Social row |
| Journeys with 1 touch (0.5 days to buy) | 79.5% | Journeys sheet, 1 touch row |
| Journeys with 2 or more touches | 20.6% | Journeys sheet, 2 to 3, 4 to 9 and 10+ rows added |
On the Channels sheet, Direct holds 57.7% of revenue in all three views. GA4 files a visit as Direct when no source survives the trip. Google's help names untagged links and ad blockers among the usual causes. Server-side tracking can only touch the second one. A server forwards what the browser handed it, so an email click without tags reaches your server just as anonymous.
Paid Social reads 0.0% in every view on the Channels sheet. Switching on Meta's Conversions API would not move that row. The Conversions API reports purchases to Meta, for Meta's own reports. GA4 files a Meta ad click under Paid Social when it arrives with a social source and a paid medium.
On the Journeys sheet, journeys with 1 touch hold 79.5% of revenue and took 0.5 days to buy. For this store, most revenue rests on a single recorded visit. If a blocker hides that visit, the sale loses its whole trail, not a slice of it. Journeys of 2 or more touches hold 20.6% on the Journeys sheet, about a fifth.
What the export cannot show is how many events never arrived at all. It holds shares of the revenue GA4 recorded, not the gap to your real order count. Your Shopify orders set against GA4's purchases show that gap, and the first step below starts there.
Why does the usual answer mislead?
The usual pitch says server-side tracking fixes your data. It fixes delivery, which is a smaller promise. Three things tend to fall out of the sales talk.
Consent travels with the data. Google's consent mode adds each visitor's choice to the request the server receives. Google's server tags then adjust what they send. In basic consent mode, a visitor who declines gets no Analytics cookies set or read, in the browser or on the server. Meta says its Conversions API is not designed to get around privacy rules in Europe such as the ePrivacy Directive.
Better delivery means more credit for the platform. Meta says the Conversions API can carry extra customer details that raise matched events. Its Events Manager help adds that better matching may increase the conversions Meta reports. Those recovered purchases are real, yet Meta still credits them by its own attribution rules. A bigger Meta number after the switch shows better plumbing, not better ads.
It costs money and upkeep. Google's Cloud Run guide puts each tagging server at about $45 a month and recommends at least 2. Its overview page asks for at least 3, at $30 to $50 per server. Google's own pages disagree, so budget for the bigger number. Until you map your own subdomain, the server runs in a third-party context and can only set JavaScript cookies.
What can server-side tracking not tell you?
Think of it as a better postal service, not a better detective. It gets more letters delivered and reads none of them.
- Which channel caused a sale. It delivers events more reliably and does not judge them. GA4 still hands out credit by its own attribution rules.
- Where an untagged visit came from. A link with no UTM parameters reaches your server with no source to pass on.
- Much about visitors who said no. When consent is denied, Google's tags store no cookies and send only a minimum of information, through cookieless pings.
What to do this week
- Count the gap before you buy a fix. In Shopify, go to Analytics > Reports, click Orders and open Orders over time for last month. In GA4, select Reports, then Engagement > Events, and read the purchase row's event count for the same dates. Pass: GA4 sits close to Shopify, month after month. Fail: GA4 misses a large or growing share, which is the gap server-side delivery can narrow.
- Check how your store talks to Meta. In Shopify, go to Sales channels > Facebook & Instagram, click Settings, then Data sharing settings. Pass: the level reads Enhanced or Maximum, so purchases also travel server to server. Fail: it reads Standard, which is the Meta pixel alone, and an ad blocker can silence it.
- Find out what fills your Direct row. In GA4, select Reports, then Acquisition > Traffic acquisition, and note Direct's row. Then click your latest email, bio and text links and check each one keeps its UTM tags. Pass: the links arrive tagged, so blockers are the likelier leak and a server can help. Fail: the tags are missing, which you fix with tags, not servers.
Check the homework. Your GA4 Attribution paths export already holds the evidence. Causality Engine reads that one file and shows what each channel caused next to what last-click gave it, in 1 to 2 minutes, for €99 once (excluding VAT), refundable within 30 days. Check the homework
Sources, 1 October 2026: An introduction to server-side tagging (Google); Server-side tagging (Google); Set up server-side tagging with Cloud Run (Google); Custom domain configuration (Google); Implement consent mode with server-side Tag Manager (Google); Measurement Protocol (Google); Facebook data sharing (Shopify); About Conversions API (Meta); View server event details in Meta Events Manager (Meta); [GA4] Understand (direct) / (none) traffic (Google); Default channel group (Google); Consent mode on websites and mobile apps (Google); Order reports (Shopify); Events report (Google); [GA4] Traffic acquisition report (Google)
Related answers
Frequently asked questions
Does server-side tracking get around cookie consent?
No. Google's consent mode passes each visitor's choice to the server container, and Google's server tags adjust what they send. Meta says its Conversions API is not designed to get around privacy rules such as Europe's ePrivacy Directive. You still need a consent banner that works.Is Meta's Conversions API a form of server-side tracking?
Yes, the server-to-server kind. On Shopify, the Enhanced and Maximum data-sharing levels add it next to the Meta pixel, and the purchase then travels between Shopify's and Meta's servers. It feeds Meta's reports, not GA4's channels.How much does server-side tagging cost to run?
Google's Cloud Run guide puts each tagging server at about $45 a month and recommends at least 2. Its overview page says $30 to $50 per server and at least 3. Logging, heavy traffic and someone's time to maintain it come on top.
Go deeper: Causal attribution, explained.
Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.
Keep reading
Terms in this article
- AnalyticsAnalytics is the systematic computational analysis of data. It reveals customer behavior and measures campaign performance.
- AttributionAttribution identifies user actions that contribute to a desired outcome and assigns value to each. It reveals which marketing touchpoints drive conversions.
- CausalityCausality is the relationship where one event directly causes another, essential for identifying specific actions that drive desired outcomes in marketing.
- ConversionConversion is a specific, desired action a user takes in response to a marketing message, such as a purchase or a sign-up.
- First-Party CookieA First-Party Cookie is a cookie set by the website a user visits. These cookies provide essential website functionality, such as remembering user preferences and login information.
- Google AdsGoogle Ads is an online advertising platform where advertisers bid to display ads, service offerings, and product listings.
- Google Tag ManagerGoogle Tag Manager is a tag management system that allows you to update tracking codes and related code fragments on your website or mobile app.
- UTM ParametersUTM Parameters are URL tags marketers use to track campaign effectiveness across traffic sources. They provide data for accurate campaign tracking and attribution in analytics platforms.