hello@datascale.de+49 89 921 35 623tracked cookie-free · /openDEEN

Search services, integrations and blog posts.

DatascaleResourcesChecksTracking architecture

Check · C03 · Tracking core

Tracking architecture: client-side, hybrid or server-side

The deep scan reads from the request log whether measurement pings run through a first-party endpoint or go straight to Google: client-side, hybrid or server-side.

What gets tested

After "Accept", the deep scan collects all measurement pings (collect paths and requests carrying the consent stamp) and sorts them by destination: own domain or foreign host. That yields the verdict: server-side (first-party endpoint only), client-side (direct pings to Google and co. only) or hybrid (both in parallel).

Why it matters

The architecture decides how much signal arrives and who controls the data flow. Client-side measurably loses signals to ad blockers and Safari ITP; server-side routes through your own domain, with full control over what gets forwarded to the platforms. Hybrid is normal as a migration state. As a permanent one, it is a double-counting risk.

Common causes

  • Hybrid by accident: the sGTM migration was started, the old client tag never switched off.
  • A plugin or theme ships a second, directly embedded Google tag that sends past the server container.
  • The first-party endpoint sits on a foreign domain (the vendor's default domain) instead of your own subdomain, so it reads as client-side.

The fix

For hybrid, clarify the duplication: migration with an end date, or an accident. For client-side with relevant ad spend, price the first-party endpoint (sGTM on your own subdomain) as the next stage: more arriving signal against running container costs. For server-side, verify that every tag actually routes through the container.

Check it yourself first

The Tracking Check tests this point along with all the others, in seconds.

Start the Tracking Check →
What does the "tracking architecture" finding mean?

After consent, the deep scan watched where the measurement pings go. Through an endpoint on your own domain (e.g. analytics.your-domain.com): server-side. Straight to google-analytics.com: client-side. Both in parallel: hybrid. The finding is a note, not a judgement.

Is a hybrid setup a problem?

Not necessarily. Sending in parallel is normal during a migration. As a permanent state it is a risk: the same conversion can be counted twice, and attribution drifts between the two paths. Clarify whether the duplication is deliberate and has an end date.

Why is server-side worth it at all?

The first-party endpoint runs under your domain: ad blockers and Safari ITP bite far less often, you control cookie lifetimes and data flow, and you decide server-side what gets forwarded to Google, Meta and co. The price is running and maintaining your own container.

The fix, delivered

Wired up in days, not sprints.

Findings from the Tracking Check go into a ranked sequence with effort estimates in the Audit Sprint, every module with an acceptance criterion.