If your GA4, Meta Ads, Google Ads and Shopify or CRM numbers all disagree, you’re not alone, and you can’t fix it with one more tag. Reliable tracking in 2026 is a layered setup: a clean GA4 configuration, Consent Mode v2, a server-side Google Tag Manager container on your own subdomain, Meta Conversions API and Google Enhanced Conversions with proper deduplication, strict UTM rules, and a monthly reconciliation against your backend. This checklist is the one I use when I take over a growth account. Work through it in order; each layer depends on the one before.
Server-side tracking means sending events from a server you control to analytics and ad platforms, instead of relying only on scripts running in the visitor’s browser. It improves data quality and control. It does not remove the need for consent.
How the pieces fit together
| Component | What it fixes | Where it runs |
|---|---|---|
| GA4 configuration | Wrong settings, polluted data, missing ecommerce events | GA4 admin and your tags |
| Consent Mode v2 | Compliance, plus modeled conversions when users decline | Consent banner and Google tags in the browser |
| Server-side GTM | Data lost to blockers and tracking prevention; control over what leaves your site | Cloud hosting on a first-party subdomain |
| Meta Conversions API | Meta conversions missed by the browser Pixel | Server container, platform app or backend |
| Google Enhanced Conversions | Google Ads conversions that can’t be matched | Google tag or server container |
| UTM governance | “(not set)” and unassigned traffic | Naming rules and a shared link builder |
| Reconciliation | Trusting the wrong source of truth | A monthly report against CRM or Shopify |
1. GA4 foundations
- One GA4 property per business, with the correct time zone and currency
- Data retention changed from the default two months to 14 months
- Internal and developer traffic filtered out
- Unwanted referrals listed, such as payment gateways and login providers, so they don’t steal credit for conversions
- Cross-domain measurement set up if checkout, booking or signup lives on another domain
- Key events (GA4’s current name for conversions) limited to events that matter to revenue or pipeline
- Ecommerce events follow Google’s recommended schema (
view_item,add_to_cart,begin_checkout,purchase) withtransaction_id,value,currencyanditems - BigQuery export enabled, so you own the raw event data
- Google Ads and Search Console linked
- A custom channel group that separates paid social, paid search and AI assistant referrals
2. Consent Mode v2
Consent Mode v2 is Google’s framework for passing a user’s consent choices to Google tags. It uses four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. Google requires it for advertisers who want full measurement and audience features for users in the EEA and the UK.
- A consent management platform (CMP) that supports Consent Mode v2 natively
- Default consent state set before any tag fires, with region-specific defaults (denied by default where the law requires it)
- An update command fires whenever the user changes their choice
- Basic or advanced mode chosen deliberately. Basic blocks Google tags until consent; advanced sends cookieless pings that enable conversion modeling. Check the choice with whoever handles your legal compliance
- Consent state checked on every key event using Tag Assistant
- Non-Google tags (Meta, TikTok, LinkedIn and others) also respect consent, because Consent Mode only governs Google tags
- Consent state passed to the server container, which doesn’t forward data to ad platforms when consent is denied
3. Server-side Google Tag Manager
- Server container hosted on Google Cloud or a managed hosting provider, sized for production traffic rather than the test setup
- Mapped to a first-party subdomain, such as
data.yourdomain.com, so requests stay in your own domain context - Google tag in the web container configured to send to the server container URL
- GA4 client set up in the server container, with GA4, Meta and Google Ads tags firing from it
- Payloads cleaned: no personal data sent to GA4, and customer data hashed where a platform requires it
- Every key event tested in server-side preview mode before launch
- Uptime monitoring, error logging and cost alerts in place
- A data map documenting which fields go to which platform, for your privacy documentation
4. Meta Conversions API
- The Conversions API sends the same standard events as the Pixel:
PageView,ViewContent,AddToCart,InitiateCheckout,PurchaseandLeadwhere relevant - Each browser and server event pair shares the same
event_nameandevent_id, so Meta can deduplicate them - Customer information parameters included when consent allows: SHA-256 hashed email and phone, plus
fbpandfbccookies, client IP address and user agent -
valueandcurrencyon every purchase event - Events sent in near real time, not batched hours later
- Event Match Quality reviewed in Events Manager, and improved by adding missing parameters
- Events verified with the Test Events tool before going live
- On Shopify, either the official Meta app’s Conversions API or your own server container handles purchases, not both without shared deduplication
5. Google Enhanced Conversions
Enhanced Conversions supplements Google Ads conversion tags with hashed first-party data, such as email, phone, name and address, so Google can match more conversions to its signed-in users.
- Enabled in Google Ads conversion settings, with customer data terms accepted
- User-provided data captured at the point of conversion, from the data layer or form fields, and hashed before it’s sent (the Google tag can hash automatically)
- Enhanced conversions for leads set up if you sell offline: qualified leads and closed deals imported from the CRM and matched on hashed email, with the click ID (GCLID) stored as well
- Diagnostics in Google Ads show a healthy status
- Primary and secondary conversion actions set so bidding optimizes on the conversion you actually value
- Transaction ID passed with each purchase to prevent double counting
6. Deduplication
Duplicate conversions quietly inflate ROAS and push bidding algorithms in the wrong direction. Check these explicitly.
- One purchase has one
transaction_id, used across GA4, Google Ads and Meta - Meta browser and server events share an
event_id - Reloading or revisiting the thank-you page doesn’t fire the purchase event again
- On Shopify, native app integrations and custom pixels or GTM don’t both send purchases
- In Google Ads, only one purchase conversion action (Google Ads tag or GA4 import) is set as primary
- Monthly check: count GA4 purchase events against unique transaction IDs for the same period
7. UTM governance
- A written naming convention: lowercase only, with fixed values for
utm_sourceandutm_mediumthat match GA4’s default channel definitions (for examplecpc,paid_social,email) - One shared link builder (a sheet or tool), so nobody types UTMs by hand
- Google Ads auto-tagging switched on
- Meta, TikTok and LinkedIn ads use dynamic URL parameters so campaign and ad names populate automatically
- No UTMs on internal links, because they break sessions and overwrite the real source
-
utm_campaignincludes a campaign ID that also exists in the ad platform and the CRM - UTMs and click IDs captured in hidden form fields and stored against the lead or order
- Monthly review of “(not set)” and “Unassigned” traffic, with fixes at the source
8. Reconciliation with your CRM or Shopify
GA4 and ad platforms will never match your backend exactly. The goal isn’t identical numbers; it’s a known, explained and stable gap.
Source of truth: Shopify orders or CRM closed-won deals for revenue. GA4 for on-site behavior and funnels. Ad platforms for their own optimization, never for total revenue.
A monthly reconciliation takes an hour once it’s set up:
- Pull orders and revenue from Shopify or your CRM for the month.
- Pull GA4 purchases and revenue for the same period and time zone.
- Calculate the capture rate: GA4 transactions divided by backend orders.
- Explain the gap: consent refusals, payment redirects, refunds and cancellations, subscription renewals, POS, draft or manual orders.
- Add up conversions claimed by each ad platform. The total often exceeds real orders because attribution windows overlap. Use marketing efficiency ratio (MER: total revenue divided by total marketing spend) as your sanity check.
- Log the capture rate each month. A sudden drop almost always means a broken tag or a site change, not a change in customer behavior.
Common mistakes to avoid
- Treating server-side tracking as a way around consent
- Launching server-side tags without a full QA pass, then doubling purchases for weeks
- Letting every agency add its own tags to the site
- Optimizing bids on platform-reported ROAS without comparing it to backend revenue
- No named owner for tracking, so it degrades after every site release
Get it built
If your numbers don’t add up and you’re making spend decisions anyway, fixing tracking is usually the highest-return work available. I set up and audit GA4, server-side tracking and ad platform conversions as part of my marketing attribution service. Get in touch and tell me what’s broken.