Skip to content
Server-Side Tracking

Server-Side Tracking:
the next stage after a sound web foundation

A share of your conversions never reaches your ad platforms: ad blockers, iOS/ATT and Safari cut the browser-side signal. How large that share is depends on your consent rate, browser mix and platform setup. Server-side tracking reduces part of that loss through first-party transport and server-side processing. It does not repair a broken measurement model.

Measure your own gap before you buy infrastructure

Compare orders and revenue from your shop against the purchases Analytics actually recorded. That number, not an industry average, decides whether server-side is worth it for you.

Built in customer-controlled accounts · container, configuration and documentation handed over

The right order

Server-side is not step one.

If events, consent, conversion actions, values or transaction IDs are wrong in the browser, a server container only forwards bad data more reliably. FW Delta therefore builds the web tracking foundation first and extends it afterwards without duplicated work.

Measurement plan
Web events
Consent
Conversion actions
IDs and deduplication
Testing
SaaS Tracking Graveyard

GA360 ($150K/year), Segment (acquired by Twilio), and similar tools are inside the SaaS Graveyard risk zone. 665+ analytics and marketing tools have been shut down. Acquisitions shift roadmaps. Funding dries up. The platform you built your attribution on can vanish - or price you out. CMOs who own their tracking infrastructure never face that risk.

Definition

What is Server-Side Tracking?

Server-side tracking is the practice of measuring conversions on your own server instead of in the visitor's browser. Where client-side tracking sends data straight from the browser to Meta, Google or TikTok - where ad blockers, Safari ITP and iOS restrictions intercept it - server-side tracking routes the event through a server container you control first, then forwards it to the platforms through their official APIs.

1. Browser
Conversion happens
2. Your server container
first-party, in Germany
3. Platforms
Meta CAPI, GA4, Google Ads

And what is server-side GTM (sGTM)?

Server-side GTM is a variant of Google Tag Manager in which the tags run not in the user's browser but in a server container on your own infrastructure. Instead of the device sending data directly to Meta, Google and others, the event first goes to your server container - and from there, in a controlled way, to the platforms.

The difference sounds technical but it is economically decisive: the data path runs over your own subdomain, is more robust against ad blockers and iOS signal loss, and you control which data ever leaves the building. This container is the heart of modern server-side tracking - where it runs and how it is wired decides both data quality and legal exposure.

A note on terms: server-side tagging refers specifically to that sGTM container, while server-side tracking is the broader practice (pixel, CAPI or API forwarding to your server). We build both, on infrastructure you keep.

Signal Loss 2026

Why client-side tracking no longer measures in 2026

Four forces strip data from browser-based tracking before it ever reaches your dashboard. These are not edge cases - they are the default for most of your traffic.

Ad blockers (~49% in Germany)

Ad blocker usage in Germany sits around 49 percent - the highest in Europe. Every blocked script is a conversion your client-side pixel never records.

iOS App Tracking Transparency

Only about 25 percent of users opt in to ATT, so roughly 75 percent block cross-app tracking. On iOS-heavy traffic, platform attribution runs 25 to 40 percent incomplete.

Safari ITP & cookie decay

Safari's Intelligent Tracking Prevention caps client-side cookies at 7 days (often 24 hours). Attribution windows collapse and returning users look like new ones.

Third-party cookie phase-out

The browser ecosystem keeps tightening third-party cookies. First-party, server-side collection is the only durable foundation left for measurement.

Measure your own gap, not an industry average. How much server-side recovers depends on consent rate, browser mix, purchase cycle and platform. Before a project we put the measured conversions next to the shop or CRM records. That difference is the only figure worth acting on.

How server-side recovers the signal, technically

We move the collection out of the browser. A dedicated endpoint operates inside the first-party context of your domain - an A record on your own subdomain instead of a third-party script. To ad blockers that traffic is not a known tracker; to Safari it is traffic from the site the user is actually on.

The event is then enriched, hashed and forwarded server-to-server. The browser is no longer the weakest link in the chain, because it is no longer the link that talks to the platforms.

  • Ad block recovery: server-to-server instead of a blockable browser script
  • Cookie lifetime up to 2 years instead of 7 days under Safari ITP
  • iOS/ATT recovery: the event originates in your backend, not in the restricted browser
  • PII hashing (SHA-256) before anything is transmitted to a platform
Architecture
Bare Metal (Hetzner AX)
Orchestration
Docker Swarm
Data pipeline
Node.js event loop
Data path
First-party subdomain

What the browser does not report
nobody optimises either

Browser-side measurement remains necessary but is increasingly incomplete. How large the gap is for you is decided by consent rate, browser mix and platform setup, not by an industry average.

The Mathematics of Your Loss

Step 1: The Invisible Conversions

You generate 100 conversions per month. But iOS users (40% of your mobile audience) aren't tracked. Ad blockers cut another 25%. Safari deletes cookies after 7 days.

→ Only 70 conversions appear in your dashboard
Step 2: The Algorithms Go Blind

Meta, Google, TikTok – their algorithms optimize based on the data they see. When a meaningful share of your conversions is missing, they learn the wrong patterns. They scale the wrong ads. They target the wrong audiences.

→ Your ROAS decreases even though your campaigns work
Step 3: The Death Spiral

You see poor performance. So you test new creatives. New audiences. Higher bids. You spend more – based on data that's wrong. The algorithms get confused. Performance gets worse.

→ You waste budget solving a problem you can't see
The Result
CAC reported too high
because part of the completions never arrive
by how much only shows in a reconciliation against shop or CRM records
Bidding learns from the wrong signal
because it optimises on an incomplete picture
the effect depends on budget, purchase cycle and campaign type

The Three Fatal Assumptions

"Google Tag Manager tracks everything?"

Yes – in the browser. But Apple blocks it on iOS. Ad blockers cut it off. Safari deletes its cookies after 7 days. You only track what gets through. Not what happens.

→ 30-40% data loss
"My numbers are roughly correct?"

"Roughly" means: Your algorithms optimize on wrong data. Every campaign decision is based on incomplete information. You scale what doesn't work. You pause what works.

→ Wasted budget
"This only affects small brands?"

No. The more ad spend, the higher the loss. At $60,000 monthly budget, that's $18,000 spent based on false data. Every. Month.

→ $216,000 risk per year
2026 Standard

When server-side pays off, and when it does not

Server-side complements browser-side measurement where ad budget, data gap and infrastructure needs justify the extra effort. With a small budget and a clean web foundation, often it does not.

Worth it when

meaningful ad spend depends on the signal, several platforms offer server-side APIs, or first-party infrastructure is a stated goal.

Not worth it when

the web setup has not been repaired yet, ad spend is small, or the remaining gap after the web foundation is already acceptable.

How we decide

from your own baseline: orders against measured purchases, consent rate, browser mix and platform count. Not from an industry average.

The Solution

Server-Side Tracking reduces part of that loss.
And you own the system.

Your server reduces browser-related signal loss and forwards permitted events to Meta, Google and TikTok in a controlled way, without the detour through third-party cookies.

Your conversion happens. No matter if iOS user, ad blocker, or Safari. Your backend registers the event – not the browser.

Your server sends data directly. Meta CAPI, Google Enhanced Conversions, TikTok Events API – they get precise, complete data. Directly from your infrastructure.

The algorithms see the truth. They optimize based on complete data. Your ROAS increases. Your CAC decreases. Your campaign decisions are based on facts.

Conversion happens
Purchase, Lead, Signup
Your Server
registers & processes
Meta CAPI
Conversions API
Google Ads
Enhanced Conversions
TikTok API
Server Events
GA4
Measurement Protocol

Why Own Server-Side Tracking Is the Only Option

Absolute Control

You decide what data is collected, how it's processed, where it goes. No black box. No vendor setting limits. Your infrastructure, your rules.

Infinitely Expandable

New platform launches? Integrate it. Custom attribution model? Build it. Special events? Define them. You own the code – no technical limits, no additional fees.

Your Data, Your Property

Every data point belongs to you. Export what you want. Analyze how you want. Use the data for custom audience building, CRM enrichment, attribution modeling – anything is possible.

Performance Without Compromise

Dedicated Hetzner AX server in Germany. Sub-50ms response times. Availability targets are agreed per project. Automatic scaling. Your customers notice no difference – but your algorithms do.

The Core Decision

Hosting: own infrastructure, Stape or Cloud Run

Where your server container runs determines cost, privacy and control. There is no universally right answer - only the one that fits your traffic, your privacy requirements and your in-house know-how. This is the first and most important decision of any server-side project.

Maximum data sovereignty

Own infrastructure (Hetzner, DE)

Predictable, by server class

  • Contracting party and region freely chosen
  • ISO/IEC 27001:2022 certified data centres
  • Fixed server cost instead of per-request billing
  • High degree of control over the data path
  • Requires setup and ops know-how
  • We can run it managed for you
Fast start

Stape

From ~20 EUR fixed / month

  • Quick to set up
  • Low fixed cost at the start
  • Lots of sGTM tooling built in
  • An additional contracting party in the data path
  • Privacy and transfer review required
  • Less control over configuration and logs
Scales with volume

Google Cloud Run

~120 to 300 USD / month variable

  • Auto-scaling under high traffic
  • Native Google integration
  • Familiar toolset
  • Variable cost per request
  • Privacy and transfer review required
  • Monthly budget harder to plan

Cost benchmarks from public provider figures (Stape, Google Cloud Run). We recommend the architecture that fits you - not the one with the highest margin. In a free initial consultation we work out which one that is.

No Data Break

Migration from client-side to server-side

The most dangerous phase is the switch itself. Turn off client-side tracking before server-side measures cleanly, and you tear a gap into the data - and bidding optimises on gaps for weeks.

Our answer is parallel operation. Client- and server-side run at the same time for a while. We reconcile the volumes per event and document where they diverge and why. Only when the deviation is explainable and stable do we switch over in a controlled way, with a rollback point in place.

2-4 wks
Simple setup
6-12 wks
Complex migration
0
Tracking-gap days

We measure Event Match Quality, match rate and captured conversions before and after the switch, so the improvement is evidenced rather than promised. Afterwards you decide: a fully documented handover to your team, or ongoing monitoring, updates and maintenance by us.

In the Server Container

Platforms we connect

Three platforms form the core of almost every server container. We configure them including deduplication, event mapping and hashed first-party data.

GA4

Google Analytics 4

Server-side collection via the Measurement Protocol, robust against ad blockers, with correct consent behaviour and clean value mapping.

Meta CAPI

Meta Conversions API

Pixel and CAPI in parallel with correct deduplication via event_id. Additional parameters can raise Event Match Quality; by how much only the account shows after go-live.

Google Ads

Enhanced Conversions

Server-side Enhanced Conversions with hashed first-party data for more precise attribution and better Smart Bidding.

Beyond the core three we connect TikTok Events API, LinkedIn Conversions API and your CRM or data warehouse on request. Deeper dive: setting up the Meta Conversions API.

Honest GDPR Framing

Privacy-oriented conversion tracking, not a tracking bypass

Some vendors sell server-side tracking as a way around consent. It is not, and we will not pretend otherwise. What follows is how you measure completely while keeping a legal basis.

The tension: law versus complete data

The legal reality

Since 13 May 2024 the German TDDDG requires consent before any access to the device. Violations can be fined up to 300,000 euros.

Enforcement is real: in 2025 the French CNIL fined Shein 150 million euros and Google 325 million euros for cookies without consent.

The data reality

In Germany around 40 percent of users reject cookies. Without countermeasures, 30 to 50 percent of conversion data is then missing from your tools.

Your Smart Bidding then optimises on a distorted basis - and burns ad budget on the wrong campaigns.

The way out is not a trick, it is architecture. Obtain consent cleanly, set Consent Mode v2 as the signal, let server-side tracking send only where a legal basis exists - and process as much as possible inside the EU.

Four building blocks that belong together

Legally sound conversion tracking does not rest on a cookie banner alone. These four elements must exist and be wired cleanly at a technical level.

Active consent

A legally compliant cookie banner with no pre-ticked boxes. Rejecting must be as easy as accepting. Consent must be obtained before the first consent-requiring tag fires.

Privacy policy

The tracking services in use, their purposes and the data processing must be named transparently, including a note on possible third-country transfers.

Roles and agreements under GDPR

For each service and each processing operation you have to establish whether it is processing on behalf, joint controllership or independent controllership. That determines whether an Art. 28 agreement or an Art. 26 arrangement is required. For Google and Meta this is not uniformly the same.

Section 25 TDDDG

Consent is required before any access to the device (cookies, identifiers). The authoritative German law since 13 May 2024, with fines up to 300,000 euros (cortina-consult.com).

What server-side does and does not solve

What server-side tracking solves

  • Recovers signal lost to ad blockers, ITP and iOS
  • First-party data handling on your own domain
  • IP anonymization and PII hashing before forwarding
  • Enforces consent on the server: it only sends where a legal basis exists
  • EU data residency you can document

What it does not do

  • Create a legal basis to track users who refused
  • Replace your consent banner or CMP
  • Let you forward data on rejection, even anonymized or hashed
  • Fix a banner with pre-selected acceptance or a hidden reject button
  • Remove the need for a data processing agreement

What the cookie banner costs you

~40%
reject cookies

A realistic rejection rate in Germany - with every correctly placed banner it rises rather than falls.

30-50%
missing conversion data

Without countermeasures this share is missing from GA4 and the ad platforms - your reporting shows a world that does not exist.

300k €
TDDDG fine range

TDDDG violations can be fined up to 300,000 euros - the incentive to get it right cuts both ways.

Schrems II, Data Privacy Framework and the residual risk

2020

Schrems II

The CJEU struck down Privacy Shield. US data transfers became a permanent legal issue - many tracking setups suddenly stood on shaky ground.

July 2023

Data Privacy Framework

The adequacy decision made transfers to certified US recipients possible again. A foundation - but a young and untested one.

Residual risk

Schrems III?

Privacy advocates such as noyb have announced a challenge. The framework is considered unstable - whoever can, keeps processing inside the EU.

Legal note

This page offers a professional opinion from tracking and infrastructure practice and does not replace legal advice. Under the GDPR and the German TDDDG, accessing or storing information on a device still requires consent, and server-side tagging on its own does not create a legal basis. For a binding assessment of your specific setup, please consult a law firm specialising in data protection or your data protection officer.

Privacy & Security

German Data Centers.
Highest Security Standards.

Your data stays in Germany. On infrastructure certified to the strictest international standards - which is exactly how you keep the US data-transfer question out of your tracking stack.

ISO 27001 Certification

Hetzner data centers in Nuremberg and Falkenstein are ISO 27001 certified – the international standard for information security management systems.

Physical security: Biometric access controls, 24/7 video surveillance
Redundant power supply: Uninterruptible power supply (UPS) + backup generators
Cooling: Redundant air conditioning with automatic failover

Privacy-oriented by design

The processing layer we build runs in the EU; what goes on to connected platforms follows the integrations you choose. Privacy is not a feature – it's the foundation of the entire architecture.

IP anonymization: Automatic anonymization before any processing
PII hashing: SHA-256 hashing of all personal data
Consent Mode: Full integration with cookie consent platforms
SSL/TLS 1.3: End-to-end encryption of all data transmissions
100%
EU Data Residency
EU
Data residency
<50ms
Response Time
24/7
Monitoring & Alerts

What completed projects look like

Four anonymised cases from different industries, described without a performance promise attached. Measurement coverage after a repair depends on consent, browsers, ad blockers and platform processing.

Web foundation Online fashion retail · DACH · anonymised
Situation
Only about half the shop purchases were reliably visible in analytics. The main site and the shop ran on separate platforms through separate measurement paths, and the order confirmation counted again on every reload.
Work
The measurement plan was rewritten, one container now serves both domains, consent signals and transaction IDs were unified, and deduplication was verified by repeatedly calling the checkout confirmation.
Outcome
Purchases arrive in analytics and in the ad account with value and a unique transaction ID. Acceptance was a real test purchase; documentation was handed over.

No ROAS or CAC figures are published for this case.

Cross-domain Travel operator · long booking path · anonymised
Situation
A booking ran across three domains: website, offer path and an external booking system. The session broke on each switch, every booking appeared as direct traffic, and no campaign was ever credited.
Work
Cross-domain linking was set up, the redirect chain cleaned, referral exclusions configured, and a server-side return path added for the booking system confirmation.
Outcome
A booking stays one session across all three domains. The confirmation from the external system reaches the ad account with value and booking number.

No claim about booking volume or cost per booking; what was measured is attribution.

Offline conversions Manufacturer · B2B enquiries · anonymised
Situation
Advertising was optimised on form submissions. A large share of those were job applications, complaints and price requests with no purchase intent, yet the ad account valued them all the same.
Work
Enquiry types were separated in the form, qualification was fed back from the CRM, offline conversions were imported with tiered values, and matching was stabilised on an identifier of their own.
Outcome
The ad account sees qualified enquiries separately from the rest. The feedback from the CRM runs on a schedule and is logged.

No effect on close rate or revenue is claimed; what is described is the data path.

Consent and duplicates Subscription shop · Shopify · anonymised
Situation
After a consent banner went live the numbers dropped, while a tracking app installed in parallel reported different purchases. Two systems counted the same order differently.
Work
Consent Mode v2 was wired correctly, the duplicate collection was switched off, a custom pixel was set up in the checkout, and first orders were distinguished from renewals in the subscription model.
Outcome
One order produces one event with one identifier. The consent signals are present in the documented form, and the behaviour is tested for both acceptance and refusal.

Technical assessment, not legal advice. Whether a setup is permissible depends on its specifics.

Ownership

Buy Once. Own Forever.

SaaS tools cost $600–$1,800/month. Over 3 years: $21,600–$64,800. And you own nothing.

That is monthly rent for a software wrapper (TripleWhale, Hyros and the like). The alternative is an asset: we build the infrastructure, we hand over the code, you own the system. After that no FW Delta licence fees and no per-event billing apply. Infrastructure, maintenance and the cost of the connected platforms remain, and are stated openly.

What You Own
One-time • Complete System
Dedicated Hetzner AX server in Germany + complete configuration
Server-Side GTM + full integration: Meta CAPI, Google Enhanced Conversions, GA4, TikTok, LinkedIn
Privacy-oriented data processing: IP anonymization, PII hashing, Consent Mode, First-Party Cookies
Migration in parallel operation + QA report with before/after evidence
Complete source code + technical documentation + architecture diagrams
2-hour video walkthrough + knowledge transfer session
Real-time monitoring dashboard + error logging + performance metrics
Fixed-price, scoped to your project - request a quote.
Explore the Tracking Stack

Pick the next step for your setup

This page is the pillar - it covers server-side tracking, sGTM and GDPR conversion tracking end to end. Two topics go deeper on their own page. Not sure where you are losing data? Start with a free consultation.

Comparing tools first? See why the SaaS Graveyard makes ownership the safer bet, or run the numbers in the cost calculator.

Frequently Asked Questions

Server-side tracking, sGTM, cost and duration, and the GDPR questions buyers actually ask.

What is server-side tracking, explained simply?

+

Server-side tracking moves the measurement of conversions from the visitor's browser to your own server. Instead of the browser sending data directly to Meta, Google or TikTok (where ad blockers, Safari ITP and iOS restrictions cut it off), the event first hits a server container you control. From there it is sent to the platforms via their APIs (Meta CAPI, Google Ads Enhanced Conversions, GA4 Measurement Protocol). The result: fewer blocked events, more reliable attribution, and full control over what data leaves your infrastructure.

What is the difference between server-side tracking, server-side tagging and sGTM?

+

Server-side tracking is the broader practice of measuring on your own server instead of in the browser. Server-side tagging usually refers to running that logic inside a server-side Google Tag Manager container (sGTM) - a variant of GTM where tags execute in a container on your infrastructure rather than in the user's browser. sGTM is the most common implementation of server-side tracking, but not the only one: events can also be forwarded to the platform APIs directly from your backend. We build both, on infrastructure you keep.

What is the difference between Consent Mode and server-side tracking?

+

Consent Mode v2 is a consent signal: it tells Google in real time whether a user has agreed and thereby controls which data is collected and whether conversions are modelled. Server-side tracking is an architecture: events run through your own server container instead of straight from the browser, which makes them more resilient against ad blockers and ITP and gives you data sovereignty. The two complement each other. Consent Mode governs the whether, server-side governs the how and where. Only together do you get a legally sound and technically complete setup.

Do I need sGTM if I only use GA4?

+

Not strictly - but it pays off earlier than most people think. If you spend meaningful ad budget, suffer from ad blockers and iOS signal loss, or need reliable conversion data for bidding, a server container measurably recovers signal and improves Event Match Quality. If you use GA4 purely descriptively without performance marketing, client-side tracking with correct Consent Mode is often enough. In a free initial consultation we answer exactly this question honestly - instead of selling you infrastructure you do not need.

Does server-side tracking work against ad blockers?

+

Largely, yes. Ad blockers and tracking-prevention features target known third-party domains and browser-side scripts. Because server-side tracking sends events from your own first-party domain (for example a tracking subdomain) and from your server, it is not caught by the typical blocklists in the same way. Ad blocker usage in Germany sits around 49 percent (Europe's highest), so this is where most of the recovered signal comes from. It is not a magic bypass, but it recovers a large share of events client-side tracking loses.

Should I self-host sGTM, use Stape, or Google Cloud Run?

+

This is the core question of any server-side project, and there is no blanket answer. Seven points are worth comparing: contracting party, region, cost model, operational effort, scaling, degree of control, and the scope of the privacy and transfer review required. Google Cloud Run bills variably per request, Stape starts at a fixed monthly price and takes operations off your hands, and your own infrastructure costs a fixed amount but demands maintenance in-house or under an agreement. We assess traffic volume, privacy requirements and your in-house know-how and recommend the architecture that fits.

How do I migrate from client-side to server-side without opening a measurement gap?

+

With parallel operation instead of a hard cutover. We run client-side and server-side tracking in parallel for a while, reconcile the data volumes per event, and only switch over when the deviation is explainable and stable. That way no measurement gap is opened on purpose: the old path stays active until the new one is verified, and a rollback point is agreed. A simple migration is realistic in 2 to 4 weeks; complex setups with many platforms take 6 to 12 weeks.

What does a server-side setup cost and how long does it take?

+

Project cost depends on the number of platforms, the migration scope, and the hosting architecture, which is why we work with individual quotes rather than flat prices. On duration there are reliable benchmarks: simple setups go live in 2 to 4 weeks, complex migrations take 6 to 12 weeks. Ongoing hosting costs differ significantly by architecture - Cloud Run around 120 to 300 USD per month variable, Stape from 20 EUR fixed, own infrastructure predictable by server class. The cleanest entry point is a free initial consultation, where we map your scope and the concrete effort together.

How quickly will I see results?

+

Most clients see a significant improvement in conversion data in their ad platforms within 48 hours of going live. The full impact on campaign performance shows after 2-4 weeks, once algorithms start optimizing based on complete data.

Do you also offer ongoing monitoring and maintenance?

+

Yes. A server container is not a set-and-forget system: platform APIs change, consent setups break silently, event parameters go stale. On request we take over hosting, updates, monitoring, and alerting so tracking gaps surface before they distort your bidding. If you prefer to run it yourself, we hand over the fully documented system - our role ends when you are confident, not when a contract runs out.

Do I need technical knowledge?

+

Day to day, very little. Updates are automated and monitoring reports outages. It is not maintenance-free though: server updates, changes to platform APIs and new consent requirements remain work, either for you or under a maintenance agreement. Documentation and a walkthrough are part of the handover.

What if I want to expand the system later?

+

You own the code. You can add any platform, define custom events, implement new tracking logic – either yourself, with any developer of your choice, or with us. There are no technical limits. Optional maintenance packages available, but not required.

Is server-side tracking GDPR-compliant and do I still need a consent banner?

+

Yes, you still need a consent banner. Server-side tracking is not a consent bypass. Under the GDPR and the German TDDDG, accessing or storing information on a user's device still requires consent, and server-side tagging does not create a legal basis on its own. What server-side tracking does give you is control: first-party data handling, IP anonymization, PII hashing and EU data residency. It makes your setup more privacy-robust and easier to document - it does not let you track users who refused consent. (Factual guidance, not legal advice.)

Is conversion tracking allowed without consent?

+

Generally no. As soon as tracking accesses information stored on a user's device or stores information there (cookies or comparable identifiers), Section 25 of the German TDDDG requires active consent. This applies to classic conversion tracking via Google Ads or the Meta Pixel and to most server-side setups alike. Exceptions are narrow (strictly necessary operations). Fully consent-free measurement is realistically only conceivable with strongly data-minimising, cookieless methods such as a suitably configured Matomo instance, and even that is a case-by-case assessment. This is a professional opinion, not legal advice.

What legal basis does conversion tracking need in Germany?

+

Two levels have to be kept apart. Access to the end device, meaning setting and reading cookies and identifiers, falls under section 25 TDDDG and as a rule requires consent. The subsequent processing of personal data falls under the GDPR and needs its own legal basis. On top of that come a privacy policy naming the services and purposes, and per service the appropriate agreement, depending on whether processing on behalf or joint controllership applies. This is a technical assessment and does not replace legal advice.

Which agreements do I need with Google and Meta?

+

That depends on the specific service and the specific processing. Google and Meta provide their own terms for their advertising products, which depending on the constellation reflect processing on behalf or joint controllership; with Google the Data Processing Terms sit in the account, while Meta uses its own controller terms for conversions data. Which role applies in your case and which agreement follows from it belongs in your data protection documentation and should be settled with your legal advisers. We implement the technical side.

What does the TDDDG change for my tracking?

+

The TDDDG (the German Telecommunications Digital Services Data Protection Act) replaced the TTDSG on 13 May 2024 and is the authoritative German law for cookie consent. It requires consent before any access to the device and complements the GDPR. Violations can be fined up to 300,000 euros (cortina-consult.com). In practice this means the banner must sit in front of every consent-requiring tag, and consent must be passed cleanly to all downstream tools at a technical level.

How much conversion data do I lose to the cookie banner?

+

In Germany, realistically around 40 percent of users reject cookies. Without countermeasures, roughly 30 to 50 percent of conversion data is then missing in GA4 and the ad platforms (konzept54.de). This gap optimises your bidding algorithms on a distorted basis, so you pay twice: once in data protection exposure and once in wasted ad budget. Consent Mode v2 plus server-side recovers part of it in a legally compliant way.

Is the EU-US data transfer (Data Privacy Framework) safe?

+

Since the adequacy decision of July 2023, transfers to the US under the EU-US Data Privacy Framework are in principle possible again where the recipient is certified. The framework is, however, considered unstable: privacy advocates such as noyb have already announced a challenge along the lines of Schrems II, a possible Schrems III (jentis.com, taggrs.io). Anyone who wants to reduce the residual risk keeps as many processing steps as possible inside the EU, which is exactly where German infrastructure comes in.

Is this secure and built for GDPR compliance?

+

The processing layer we build runs on Hetzner data centres in Nuremberg or Falkenstein. Data sent onward to connected platforms such as Google, Meta or TikTok leaves that layer by design, according to the integrations you choose. Hetzner is - ISO 27001 certified, redundant power supply, physical security at the highest standard. IP anonymization, PII hashing (SHA-256), Consent Mode v2 integration, SSL/TLS 1.3. You have full control over every data point and a setup that is straightforward to document for your data protection officer. Compliance still depends on your consent banner and legal basis - we build the technical foundation, not the legal opinion.

Why not just use a SaaS tool?

+

Because then you're dependent. Monthly costs that never end. No control over the infrastructure. And when the vendor raises prices, kills features, or decides your industry isn't profitable anymore, you're back to square one. With your own server-side tracking, you own the system. You decide what happens. Forever.

Stop Burning Money.
Start Measuring Precisely.

We build you a server-side tracking system that you own. One-time. Forever.
No FW Delta licence fee. Hosting and platform costs stay visible.

Response within 24 hours No obligation Handled confidentially
Newsletter

Research for technical decisions

New reports, benchmarks and technical analyses on SaaS economics, AI engineering and owned infrastructure.

Original research Public sources No sales mail

By subscribing you receive new analyses and updates from FW Delta by email. You can withdraw your consent at any time. Further information is available in the privacy policy.