Skip to content
Performetic

Performance Marketing

Why server-side tracking and Conversions API matter

Written by Published Last updated 5 min read
Why server-side tracking and Conversions API matter

In short

Server-side tracking sends conversion data to ad platforms from your server instead of the shopper's browser. Browser restrictions, ad blockers and cookie limits all erode pixel data. Meta's Conversions API and Google enhanced conversions reduce that loss and give bidding algorithms more complete signals. A correct setup needs event_id deduplication and consent mode.

Contents
  1. What is server-side tracking?
  2. Why does browser-based tracking lose data?
  3. Browser tracking prevention
  4. Ad blockers
  5. Consent choices
  6. Technical gaps
  7. How does Meta's Conversions API work?
  8. Why is deduplication critical?
  9. What are Google enhanced conversions and server-side GTM?
  10. Why do you need consent mode?
  11. Client-side vs server-side tracking compared
  12. How should you plan the setup?
  13. Key takeaways

What is server-side tracking?

Server-side tracking sends conversion events such as purchases and add-to-carts from your own server directly to ad platforms, rather than relying on a pixel running in the shopper's browser. It is far less exposed to browser restrictions, ad blockers and short-lived cookies. On Meta this is done with the Conversions API; on Google, with enhanced conversions and server-side tagging.

Why does it matter? Google's and Meta's bidding algorithms learn from the conversion signals they receive. Missing data means missing learning: the algorithm cannot fully see which audiences and creatives drive sales, so it allocates budget less effectively.

Why does browser-based tracking lose data?

In a classic pixel setup, the event is sent by JavaScript running in the user's browser. That chain can break in several places:

Browser tracking prevention

WebKit, the engine behind Safari, restricts cookies through Intelligent Tracking Prevention (ITP). According to WebKit's own documentation, cookies created in JavaScript and other script-writeable storage are deleted after 7 days without user interaction with the site. When a user lands from a domain classified as having tracking capabilities with link decoration (such as click IDs appended to the URL), that cap drops to 24 hours. So if someone clicks an ad and comes back a few days later to buy, that purchase may not be tied to the ad.

Ad blockers

Browser extensions, and built-in blockers in some browsers, can stop known tracking scripts from loading at all. When that happens, the event is never sent.

Under GDPR, KVKK and similar laws, if a user declines cookies, marketing tags must not use them. That is an obligation to respect, not something to work around. The goal is to pass consent status correctly to platforms and make sure data users did consent to is not lost.

Technical gaps

A checkout on a different domain, a thank-you page closed before it loads, or a slow page where tags fire late all cause lost purchase events.

How does Meta's Conversions API work?

The Conversions API lets you send events to Meta from your website server, ecommerce platform or CRM. Meta recommends keeping the pixel and running the Conversions API alongside it rather than replacing one with the other: when a browser event fails, the server event fills the gap.

Adding customer information such as email or phone (hashed) to server events improves how well Meta can match the event to a person. You can monitor this with the event match quality indicator in Events Manager.

Why is deduplication critical?

When the pixel and the Conversions API both send the same purchase, Meta needs to know they are one event. Otherwise sales are reported twice, ROAS is inflated and the algorithm learns from bad data.

Meta's deduplication relies on both events carrying the same event name (event_name) and the same event ID (event_id). In practice:

  1. Generate a unique ID when the order is created (for example, the order number).
  2. Pass it to the pixel event as the eventID parameter.
  3. Send the same ID in the server event as event_id.
  4. Make sure event names match exactly (for example, Purchase on both).
  5. Check deduplication status in Events Manager.

What are Google enhanced conversions and server-side GTM?

Enhanced conversions send first-party customer data collected at conversion, such as email, hashed with SHA256. Google matches it against signed-in Google accounts, so conversions can be tied back to ad interactions even when cookies are gone.

Server-side Google Tag Manager (sGTM) runs your tags on a cloud server you control instead of in the browser. The browser sends data to a single endpoint, usually on your own subdomain (for example, metrics.yourbrand.com), and the server forwards it to destinations like Google Analytics, Google Ads and Meta. This reduces third-party code on your pages and gives you control over exactly what data reaches each platform.

One caveat: WebKit states that it detects subdomains pointing to third-party servers via CNAME or IP address and caps cookies set in those responses to 7 days. Server-side GTM is not a magic fix; how it is hosted matters too.

Google consent mode passes the user's cookie choice to Google tags, using signals such as ad_storage, analytics_storage, ad_user_data and ad_personalization to say which data uses are allowed. There are two implementations: in basic mode, Google tags do not fire at all when consent is denied; in advanced mode, tags send cookieless pings and Google can model missing conversions in more detail. Pairing a compliant consent banner (GDPR, KVKK or whatever applies to you) with consent mode is the healthiest setup.

Client-side vs server-side tracking compared

Criterion Client-side (browser pixel) Server-side (CAPI, sGTM)
Setup effort Low Medium to high
Affected by ad blockers Heavily Less
Affected by cookie limits Heavily Less (depends on domain setup)
Data control Limited You decide what is sent
Page speed impact Loads many third-party scripts Less code in the browser
Cost Free Server hosting costs
Deduplication needed No Yes, when used alongside the pixel

How should you plan the setup?

  1. Measure where you are: compare order counts in your store backend with conversions reported by each platform.
  2. Set up a consent management tool and Google consent mode.
  3. Implement Meta's Conversions API; if your ecommerce platform has a native integration (such as Shopify's Meta app), evaluate that first.
  4. Confirm event_id deduplication is working.
  5. Turn on enhanced conversions in Google Ads.
  6. Move to server-side GTM if you need scale and tighter data control.
  7. For two to four weeks after launch, compare platform data with store data.

At Performetic, we audit measurement before touching campaign optimisation on any new account, because optimising on incomplete data just means heading the wrong way faster. More on our performance marketing service page.

Key takeaways

  • Browser pixels lose data to ITP, ad blockers, consent choices and technical gaps.
  • Run Meta's Conversions API alongside the pixel and deduplicate with event_id.
  • Google enhanced conversions strengthen matching with hashed first-party data.
  • Server-side GTM gives you data control, but the domain setup has to be right.
  • Consent mode is how you respect user choice while protecting measurement.

Frequently asked questions

Does the Conversions API replace the Meta pixel?

No. Meta recommends using the pixel and the Conversions API together. The pixel captures browser behaviour, while the Conversions API sends events from your server that the browser missed. When both are used, deduplicate with event_name and event_id so the same purchase is not counted twice.

What is event_id and how is it used?

event_id is a unique identifier assigned to an event. When the same purchase is sent by both the pixel and the server, Meta treats them as one event if both carry the same event_name and event_id. In practice, sending the order number as eventID in the pixel and event_id in the server event is the most reliable approach.

Do I need server-side Google Tag Manager?

Not necessarily. Many ecommerce brands recover much of their lost data with their platform's native Conversions API integration and Google enhanced conversions. Server-side GTM is most valuable for brands that send data to several platforms, want tight control over what is shared, and want to reduce third-party code on their pages.

Can server-side tracking be used to bypass consent?

No, and it should not be. Server-side tracking is not a way to collect data without permission. Users' cookie and marketing choices must be applied on the server side too. In a correct setup, consent mode and your consent tool decide which data can go to which platform; server-side tracking only prevents consented data from being lost.

Sources

  1. Conversions API (Meta for Developers)
  2. About deduplication for Meta Pixel and Conversions API events (Meta Business Help Center)
  3. About enhanced conversions (Google Ads Help)
  4. Consent mode overview (Google for Developers)
  5. Tracking Prevention in WebKit (WebKit)

Your ad budget deserves more.

We review your store and ad accounts and send you three concrete growth opportunities, free of charge.

Get a free audit
Get a free audit