Frequently Asked Questions
Server-side tracking, sGTM, cost and duration, and the GDPR questions buyers actually ask.
What is server-side tracking, explained simply?
+
Server-side tracking moves the measurement of conversions from the visitor's browser to your own server. Instead of the browser sending data directly to Meta, Google or TikTok (where ad blockers, Safari ITP and iOS restrictions cut it off), the event first hits a server container you control. From there it is sent to the platforms via their APIs (Meta CAPI, Google Ads Enhanced Conversions, GA4 Measurement Protocol). The result: fewer blocked events, more reliable attribution, and full control over what data leaves your infrastructure.
What is the difference between server-side tracking, server-side tagging and sGTM?
+
Server-side tracking is the broader practice of measuring on your own server instead of in the browser. Server-side tagging usually refers to running that logic inside a server-side Google Tag Manager container (sGTM) - a variant of GTM where tags execute in a container on your infrastructure rather than in the user's browser. sGTM is the most common implementation of server-side tracking, but not the only one: events can also be forwarded to the platform APIs directly from your backend. We build both, on infrastructure you keep.
What is the difference between Consent Mode and server-side tracking?
+
Consent Mode v2 is a consent signal: it tells Google in real time whether a user has agreed and thereby controls which data is collected and whether conversions are modelled. Server-side tracking is an architecture: events run through your own server container instead of straight from the browser, which makes them more resilient against ad blockers and ITP and gives you data sovereignty. The two complement each other. Consent Mode governs the whether, server-side governs the how and where. Only together do you get a legally sound and technically complete setup.
Do I need sGTM if I only use GA4?
+
Not strictly - but it pays off earlier than most people think. If you spend meaningful ad budget, suffer from ad blockers and iOS signal loss, or need reliable conversion data for bidding, a server container measurably recovers signal and improves Event Match Quality. If you use GA4 purely descriptively without performance marketing, client-side tracking with correct Consent Mode is often enough. In a free initial consultation we answer exactly this question honestly - instead of selling you infrastructure you do not need.
Does server-side tracking work against ad blockers?
+
Largely, yes. Ad blockers and tracking-prevention features target known third-party domains and browser-side scripts. Because server-side tracking sends events from your own first-party domain (for example a tracking subdomain) and from your server, it is not caught by the typical blocklists in the same way. Ad blocker usage in Germany sits around 49 percent (Europe's highest), so this is where most of the recovered signal comes from. It is not a magic bypass, but it recovers a large share of events client-side tracking loses.
Should I self-host sGTM, use Stape, or Google Cloud Run?
+
This is the core question of any server-side project, and there is no blanket answer. Seven points are worth comparing: contracting party, region, cost model, operational effort, scaling, degree of control, and the scope of the privacy and transfer review required. Google Cloud Run bills variably per request, Stape starts at a fixed monthly price and takes operations off your hands, and your own infrastructure costs a fixed amount but demands maintenance in-house or under an agreement. We assess traffic volume, privacy requirements and your in-house know-how and recommend the architecture that fits.
How do I migrate from client-side to server-side without opening a measurement gap?
+
With parallel operation instead of a hard cutover. We run client-side and server-side tracking in parallel for a while, reconcile the data volumes per event, and only switch over when the deviation is explainable and stable. That way no measurement gap is opened on purpose: the old path stays active until the new one is verified, and a rollback point is agreed. A simple migration is realistic in 2 to 4 weeks; complex setups with many platforms take 6 to 12 weeks.
What does a server-side setup cost and how long does it take?
+
Project cost depends on the number of platforms, the migration scope, and the hosting architecture, which is why we work with individual quotes rather than flat prices. On duration there are reliable benchmarks: simple setups go live in 2 to 4 weeks, complex migrations take 6 to 12 weeks. Ongoing hosting costs differ significantly by architecture - Cloud Run around 120 to 300 USD per month variable, Stape from 20 EUR fixed, own infrastructure predictable by server class. The cleanest entry point is a free initial consultation, where we map your scope and the concrete effort together.
How quickly will I see results?
+
Most clients see a significant improvement in conversion data in their ad platforms within 48 hours of going live. The full impact on campaign performance shows after 2-4 weeks, once algorithms start optimizing based on complete data.
Do you also offer ongoing monitoring and maintenance?
+
Yes. A server container is not a set-and-forget system: platform APIs change, consent setups break silently, event parameters go stale. On request we take over hosting, updates, monitoring, and alerting so tracking gaps surface before they distort your bidding. If you prefer to run it yourself, we hand over the fully documented system - our role ends when you are confident, not when a contract runs out.
Do I need technical knowledge?
+
Day to day, very little. Updates are automated and monitoring reports outages. It is not maintenance-free though: server updates, changes to platform APIs and new consent requirements remain work, either for you or under a maintenance agreement. Documentation and a walkthrough are part of the handover.
What if I want to expand the system later?
+
You own the code. You can add any platform, define custom events, implement new tracking logic – either yourself, with any developer of your choice, or with us. There are no technical limits. Optional maintenance packages available, but not required.
Is server-side tracking GDPR-compliant and do I still need a consent banner?
+
Yes, you still need a consent banner. Server-side tracking is not a consent bypass. Under the GDPR and the German TDDDG, accessing or storing information on a user's device still requires consent, and server-side tagging does not create a legal basis on its own. What server-side tracking does give you is control: first-party data handling, IP anonymization, PII hashing and EU data residency. It makes your setup more privacy-robust and easier to document - it does not let you track users who refused consent. (Factual guidance, not legal advice.)
Is conversion tracking allowed without consent?
+
Generally no. As soon as tracking accesses information stored on a user's device or stores information there (cookies or comparable identifiers), Section 25 of the German TDDDG requires active consent. This applies to classic conversion tracking via Google Ads or the Meta Pixel and to most server-side setups alike. Exceptions are narrow (strictly necessary operations). Fully consent-free measurement is realistically only conceivable with strongly data-minimising, cookieless methods such as a suitably configured Matomo instance, and even that is a case-by-case assessment. This is a professional opinion, not legal advice.
What legal basis does conversion tracking need in Germany?
+
Two levels have to be kept apart. Access to the end device, meaning setting and reading cookies and identifiers, falls under section 25 TDDDG and as a rule requires consent. The subsequent processing of personal data falls under the GDPR and needs its own legal basis. On top of that come a privacy policy naming the services and purposes, and per service the appropriate agreement, depending on whether processing on behalf or joint controllership applies. This is a technical assessment and does not replace legal advice.
Which agreements do I need with Google and Meta?
+
That depends on the specific service and the specific processing. Google and Meta provide their own terms for their advertising products, which depending on the constellation reflect processing on behalf or joint controllership; with Google the Data Processing Terms sit in the account, while Meta uses its own controller terms for conversions data. Which role applies in your case and which agreement follows from it belongs in your data protection documentation and should be settled with your legal advisers. We implement the technical side.
What does the TDDDG change for my tracking?
+
The TDDDG (the German Telecommunications Digital Services Data Protection Act) replaced the TTDSG on 13 May 2024 and is the authoritative German law for cookie consent. It requires consent before any access to the device and complements the GDPR. Violations can be fined up to 300,000 euros (cortina-consult.com). In practice this means the banner must sit in front of every consent-requiring tag, and consent must be passed cleanly to all downstream tools at a technical level.
How much conversion data do I lose to the cookie banner?
+
In Germany, realistically around 40 percent of users reject cookies. Without countermeasures, roughly 30 to 50 percent of conversion data is then missing in GA4 and the ad platforms (konzept54.de). This gap optimises your bidding algorithms on a distorted basis, so you pay twice: once in data protection exposure and once in wasted ad budget. Consent Mode v2 plus server-side recovers part of it in a legally compliant way.
Is the EU-US data transfer (Data Privacy Framework) safe?
+
Since the adequacy decision of July 2023, transfers to the US under the EU-US Data Privacy Framework are in principle possible again where the recipient is certified. The framework is, however, considered unstable: privacy advocates such as noyb have already announced a challenge along the lines of Schrems II, a possible Schrems III (jentis.com, taggrs.io). Anyone who wants to reduce the residual risk keeps as many processing steps as possible inside the EU, which is exactly where German infrastructure comes in.
Is this secure and built for GDPR compliance?
+
The processing layer we build runs on Hetzner data centres in Nuremberg or Falkenstein. Data sent onward to connected platforms such as Google, Meta or TikTok leaves that layer by design, according to the integrations you choose. Hetzner is - ISO 27001 certified, redundant power supply, physical security at the highest standard. IP anonymization, PII hashing (SHA-256), Consent Mode v2 integration, SSL/TLS 1.3. You have full control over every data point and a setup that is straightforward to document for your data protection officer. Compliance still depends on your consent banner and legal basis - we build the technical foundation, not the legal opinion.
Why not just use a SaaS tool?
+
Because then you're dependent. Monthly costs that never end. No control over the infrastructure. And when the vendor raises prices, kills features, or decides your industry isn't profitable anymore, you're back to square one. With your own server-side tracking, you own the system. You decide what happens. Forever.