Server-Side Tracking Setup: sGTM, Google Tag Gateway, Meta CAPI, and Offline Conversions

Browser-only tracking keeps losing signal, and ad platforms bid on whatever signal they get. John Williams builds the server-side layer that sends verified outcomes back to Google, Microsoft, and Meta, with consent respected and nothing counted twice.

Jun 15, 2026 offline imports moved to Data Manager API
48 h Meta deduplication window
SHA-256 hashing for first-party data

TL;DR

Who this is for

The components, and what each one is for

Component What it does Source
Server-side Google Tag Manager A tag container that runs on a server you control, in your Google Cloud project or another environment, instead of in the browser. Clients receive requests and turn them into events, and tags forward them on. Google recommends serving it from your first-party domain in production mode. Google for Developers
Google tag gateway for advertisers Loads the Google tag from your own domain and sends some measurement requests through it, using your CDN, load balancer, or web server. Google recommends combining it with server-side tagging "for the most durable tagging setup." Google for Developers
Enhanced conversions Sends SHA-256-hashed first-party data (email, phone, address) with conversions to improve measurement. Since June 2026, enhanced conversions for web and for leads are one on/off setting, fed by tags, Data Manager, and API connections together (settings update). Google Ads Help
Offline conversion import / enhanced conversions for leads Sends CRM outcomes (qualified, closed, value) back to Google Ads using GCLID and/or hashed user data. From June 15, 2026, these uploads move to the Data Manager API and are blocked in the Google Ads API, apart from legacy allowlisting. Google Ads Help
Meta Conversions API A server-to-Meta connection for web, app, offline, and messaging events. Can be set up in one click from Events Manager if you already have a Pixel, or built as a direct integration. Meta for Developers

What's included

How John builds server-side tracking

Map the conversion journey

Click, landing, lead or purchase, CRM stages, revenue. For each step: which system knows about it, what identifiers exist (GCLID, fbclid/fbc, email), and how long it takes. This map decides everything else.

Fix the browser layer first

Server-side tracking amplifies whatever you feed it, mistakes included. The web container, data layer, and consent mode have to be right first (see GA4 setup).

Stand up the first-party layer

Deploy Google tag gateway for quick first-party serving, then the server container on a first-party subdomain for the tags that benefit from server processing. Verify in Tag Assistant that hits go to your measurement path.

Wire Meta CAPI with deduplication

Meta's recommended method: the Pixel's eventID must match the server's event_id, and the event names must match. Meta discards the duplicate only if both arrive within 48 hours (Meta deduplication docs). For website events, Meta requires action_source, event_source_url, and client_user_agent. Event Match Quality is scored 0–10 from the last 48 hours of events (About event match quality).

Close the CRM loop

Store GCLID and hashed contact data with each lead, then send stage changes back as conversions with values. Google now recommends enhanced conversions for leads over classic offline import, and routes uploads through Data Manager (About offline conversion imports). Then point bidding at the qualified-lead or revenue action (see bidding strategy).

Monitor, don't just launch

Alerts on event volume drops, daily Event Match Quality and enhanced-conversion diagnostics checks, and a documented response plan. When something breaks, a data exclusion in Google Ads keeps Smart Bidding from learning from the bad days (data exclusions).

Common server-side mistakes John fixes

Which setup fits which business

Situation What John usually recommends
Small site on Cloudflare, Google Ads only Google tag gateway through the Cloudflare integration, enhanced conversions, and solid consent mode. A server container is often unnecessary at first.
Ecommerce on Shopify or similar, Google and Meta Tag gateway, enhanced conversions, Meta CAPI (platform integration or server container) with deduplication, and purchase values checked against orders.
Lead gen with a CRM (HubSpot, Salesforce) Enhanced conversions for leads, CRM stage uploads through Data Manager, Meta CAPI for qualified-lead events, and bidding pointed at qualified outcomes.
Many vendors, heavy pages, multiple platforms Server-side GTM on a first-party subdomain to consolidate vendors and transform data, plus tag gateway for Google tags.
Long sales cycle, low conversion volume Offline imports with values and an intermediate qualified-stage conversion, so bidding has enough signal (see the bidding strategy page).

Ownership and maintenance

Server-side infrastructure is something you own, which also means you're responsible for keeping it running. We set it up in your cloud or hosting account, document it, and hand over admin access, so you're never locked into us. Ongoing costs are your hosting bill (Cloud Run or a managed host) plus whatever monitoring you choose. We quote hosting options upfront, so the running cost is a known number before you commit.

Launch checklist before any server-side setup goes live

Nothing ships until every line below has been checked and written into the runbook.

Pricing and engagement

Server-side work is quoted as a flat project fee after we map your conversion journey, because a tag gateway on Cloudflare and a multi-platform server container with CRM uploads are very different builds. The quote separates our fee from the hosting you'll pay your provider directly, so both numbers are known up front. Per the pricing page, nothing at Ahmeego is billed as a percentage of ad spend and there are no long contracts. The free Marketing Analytics Auditor shows what your browser tags are doing today.

Platforms we work in

Server-side tracking connects your site, your CRM, and every ad platform. Official product pages for each are below.

Google Tag Manager logoGoogle Tag Manager Google Cloud logoGoogle Cloud Run Cloudflare logoCloudflare Stape Google Ads logoGoogle Ads Meta logoMeta Events Manager Microsoft logoMicrosoft Advertising HubSpot logoHubSpot Salesforce logoSalesforce Google BigQuery logoBigQuery

Logos via the Simple Icons project. Trademarks belong to their owners; no endorsement implied.

Proof you can check before you call

Builds and write-ups from ahmeego.com on tags, conversion endpoints, and closing the loop with ad platforms.

Free tool
Marketing Analytics Auditor: detect pixels, consent, and data layer issues
Article
Buddy levels up: runtime tag verification
Article
How John launched a ChatGPT Ads campaign and set up conversion tracking
Q&A
Google Tag Manager enhanced conversion tracking
Q&A
Infrequent, high-value offline conversions and Smart Bidding
Case study
Summit Tracker: the Cloudflare Workers stack behind our conversion endpoints

Frequently asked questions

What is server-side tracking?
Instead of every ad platform's tag running in the visitor's browser, events go to a server you control (such as a server-side Google Tag Manager container), which then forwards them to Google, Meta, and others. It can also receive events straight from your backend or CRM.
Do I need server-side GTM, or is Google tag gateway enough?
Tag gateway is the faster first step: it serves Google tags from your own domain through your CDN. Server-side GTM adds a container you control for transforming and routing data to multiple platforms. Google recommends using both for the most durable setup. Many smaller sites start with the gateway alone.
How do I stop duplicate conversions between Meta Pixel and the Conversions API?
Send the same event_id from the Pixel (as eventID) and the server, and use matching event names. Meta deduplicates events received within 48 hours of each other.
What changed with Google offline conversion imports in 2026?
Starting June 15, 2026, offline conversion import and enhanced conversions for leads uploads are migrated to the Data Manager API and blocked in the Google Ads API, except for allowlisted legacy access. Separately, Google Ads began accepting user-provided data from tags, Data Manager, and API connections at once in April 2026, and combined enhanced conversions for web and leads into one on/off setting in June 2026.
Does server-side tracking get around cookie consent?
No, and it shouldn't. Consent requirements apply to the data, not the transport. We carry the visitor's consent state to the server and every server tag respects it.
Where should the server container be hosted?
Google's documentation describes running it in your own Google Cloud project or another environment. Cloud Run and managed hosts like Stape are both common. Either way, serve it from a first-party subdomain in production mode.

Scope your server-side tracking

Tell John your site platform, CRM, ad platforms, and where you think signal is being lost. He'll reply with which components you actually need.

John, Kristy, or Sandeep will reply. One of the three of us will respond personally within 1 business day. No SDR queue.
We respond within 1 business day. No spam, ever. Read our privacy notice.

Top 25 references

The primary sources, standards, research, and tools we rely on for this work. Every link was checked on 2026-10-11. We aren't affiliated with these publishers unless noted.

Official documentation

  1. An introduction to server-side tagging — Google for Developers
    How server containers, clients, and tags work, and Google's advice to use a first-party domain in production mode.
  2. Set up server-side tagging with Cloud Run — Google for Developers
    Google's deployment guide for running the server container on Cloud Run.
  3. Custom domain configuration — Google for Developers
    How to map the server container to a first-party subdomain or same-origin path.
  4. Google tag gateway for advertisers — Google for Developers
    Serving the Google tag from your own domain through a CDN, and Google's advice to pair it with server-side tagging.
  5. Consent mode overview — Google for Developers
    Defines the consent types, basic vs. advanced mode, and the modeling each one enables.
  6. Enable region-specific behavior for tags — Google for Developers
    How the server container can change tag behavior by visitor region, useful for consent handling.
  7. Data Manager API — Google for Developers
    The API that replaced Google Ads API uploads for offline conversions and enhanced conversions for leads.
  8. Manage offline conversions — Google Ads API
    The developer documentation for offline conversion and enhanced conversions for leads uploads.
  9. About enhanced conversions — Google Ads Help
    How hashed first-party data improves conversion measurement for web and for leads.
  10. Updates to your enhanced conversions settings — Google Ads Help
    The 2026 changes: multi-source user data from April, one on/off setting from June, Data Manager from June 15.
  11. About offline conversion imports — Google Ads Help
    Google's recommendation to start with enhanced conversions for leads and the June 15, 2026 API migration.
  12. Upgrade offline conversion import to enhanced conversions for leads — Google Ads Help
    How to add user-provided data to existing GCLID-based imports.
  13. Set up Google tag gateway with Cloudflare — Tag Manager Help
    The GTM Admin flow for turning on tag gateway through Cloudflare.
  14. Enhanced conversions — Microsoft Learn
    Microsoft's enhanced conversions, including formatting and SHA-256 hashing rules for offline uploads.
  15. ApplyOfflineConversions service operation — Microsoft Learn
    Microsoft's API for offline conversion uploads, including the two-hour wait after creating a goal.

Standards & policy

  1. FIPS 180-4: Secure Hash Standard — NIST
    The specification for SHA-256, the hash Google, Meta, and Microsoft all require for emails and phone numbers sent with conversions.
  2. Recommendation E.164: The international public telecommunication numbering plan — ITU-T
    Defines the +countrycode phone format that ad platforms expect before a number is hashed.
  3. Guidelines 05/2020 on consent under Regulation 2016/679 — European Data Protection Board
    The EU regulators' definition of valid consent under GDPR: freely given, specific, informed, unambiguous, and as easy to withdraw as to give.

Leading tools

  1. Google tag gateway for advertisers — Cloudflare Docs
    Cloudflare's own documentation for the native tag gateway integration.
  2. Conversions API Tag for Google Tag Manager — Meta (facebookincubator on GitHub)
    Meta's official server-side GTM template for sending Conversions API events, maintained by Meta.
  3. Cloud Run — Google Cloud
    Google's managed container platform and the default host for server-side GTM.

Expert guides

  1. Server-Side Tagging In Google Tag Manager — Simo Ahava
    The canonical deep dive on how server containers, clients, and tags work, from the best-known GTM practitioner.
  2. How to set up Facebook Conversions API — Stape
    A practical server-side GTM walkthrough for Meta CAPI with event_id deduplication.

Communities & courses

  1. #measure Slack community — Measure Chat
    A long-running Slack community of analytics and tag management practitioners, good for GA4 and sGTM edge cases.
  2. Simmer: online courses in technical marketing — Simmer (Simo Ahava & Mari Ahava)
    Practitioner courses on server-side tagging, GTM, and GA4 from the people who wrote the reference guides.
AI disclosure: This page was drafted with AI assistance and edited by a human. Platform rules and limits are cited to official documentation as checked on 2026-10-11; Google, Microsoft, and Meta change these often, so confirm against the linked source before acting. Brand names mentioned in John's background are past engagements listed on the about page; no current endorsement is implied.

See what your browser tags are missing.

Run the free Marketing Analytics Auditor on your site, then bring the results to John.

Launch the auditor Talk to John