hello@datascale.de+49 89 921 35 623tracked cookie-free · /openDEEN

Search services, integrations and blog posts.

HomeServicesMeasurement & Privacy Engineering

Service 01 · Measurement & Privacy Engineering

Server-side tracking that keeps delivering under GDPR

We investigate technical signal loss and build the measurement chain that fits: EU hosting, documented data filters and tested consent logic.

First call within 48 h · 3 working days · €1,490 net

You're in the right place if:

Ads reports fewer conversions than your shop or CRM actually sees.

The same conversion shows up twice in reporting.

Consent Mode V2 is wired up somehow, but nobody trusts the numbers.

Since the UA-to-GA4 migration the numbers are questioned internally.

GA4GTM Server-Sidestape.ioBigQuery (Frankfurt)

What we build

Four modules. One setup.

Bookable individually or as a chain, depending on the maturity of your existing tracking.

01

Web Analytics Setup & Audit

GA4 · Plausible CE · GTM · GTM Server-Side · stape.io

Full implementation or technical audit of an existing web analytics setup. Tool-agnostic, we recommend what fits the use case.

GA4, Plausible CE or Matomo, server-side via stape.io, UA-to-GA4 cleanup, cross-domain, bot and referral filters.

02

Mobile & App Analytics (Firebase)

Firebase Analytics · GA4 · BigQuery · Usercentrics · OneTrust

Analytics for native and hybrid apps. Firebase properly configured, with an event schema that fits the web strategy and merges into BigQuery.

iOS/Android event schema, privacy-first Firebase config, app consent with enterprise CMP, Firebase ↔ GA4 BigQuery export.

03

Cookie Consent & Consent Engineering

Usercentrics · OneTrust · Cookiebot · Consent Mode V2

The consent layer is not a checkbox. Misconfigured it destroys data, configured properly it protects users and lets analysis run.

CMP selection and setup, cookie scanning, Consent Mode V2, pre-consent scan, ongoing CMP operations.

04

Conversion APIs & ad platforms

Meta CAPI · Google Enhanced Conv. · TikTok Events · LinkedIn CAPI

Pixel plus Conversion API per platform, distributed from one server container and deduplicated via a shared event ID. Conversions arrive in the platforms without counting twice.

Meta, Google, TikTok, LinkedIn, Criteo, Outbrain. Click-ID capture (gclid, fbclid), CRM and offline conversions, match-quality monitoring.

How it works

From click to platform, in four steps.

First-party to your own server, not through dozens of third-party domains.

01browser → 1st-party

Signal

An event fires in the browser and goes first-party to your own subdomain, not directly to Google.

02GTM SS · stape.io

Server container

GTM Server-Side on stape.io receives the event and applies configured data filters.

03Consent Mode V2

Consent gate

The browser sends the consent state. We verify how each server tag responds to it.

04GA4 · CAPI · BigQuery

Distribution

Permitted fields go to configured destinations such as GA4, Meta CAPI and BigQuery Frankfurt.

Process

Four phases, fixed order.

always starts with phase 1 · no blind build

Phase 1 · 3 working days

Audit Sprint

One website, one GA4 property, one web GTM container, one CMP, one ads account and up to three conversion paths.

Phase 2 · 1–2 weeks

Architecture

Data contract, event design, target architecture. We fix where each number is produced and who guarantees it.

Phase 3 · 2–6 weeks

Build Sprint

Delivery in sprints, every module signed off on its own. Your team stays involved, not locked out.

Phase 4 · ongoing

Managed Evolution

Monitoring, release support, platform updates. Optional; plenty of clients run the setup themselves.

What you get

A report, not a workshop afterglow.

The Audit Sprint ends in a document: findings per layer, severity, effort, sequence. Not a slide deck full of recommendations in the subjunctive.

→ Findings with severity and reproduction path

→ Effort estimate per finding, in person-days

→ A draft data contract for the core events

→ An implementation plan another agency could execute

Request an anonymised sample →

Deliverables · Measurement & Privacy Engineering

4 groups · 15 items
01Strategy & Planning4 items
02Technical Implementation4 items
03QA & Validation4 items
04Handover & Operations3 items

Structure taken from this page's scope of delivery. The concrete scope comes out of the audit.

Scopes

Assess, implement, improve.

02 · Implement

Build Sprint

Fixed price

Quoted for your project scope

2–6 weeks

New implementation or rework to the agreed specification.

  • Measurement Blueprint + GTM / server-side via stape.io
  • CMP integration + Consent Mode V2
  • QA sign-off against the blueprint + 30-day support
03 · Improve

Managed Evolution

Monthly

Quoted for your support scope

3-month minimum

Ongoing support and development of your data architecture.

  • Monthly development + roadmap
  • QA on every release deploy
  • Slack support, < 4 h response (Mon–Fri)
  • Monthly report + executive summary

Audit Sprint: From the agreed start with complete access and documents. Scope and delivery date are agreed before commissioning.

All prices net, plus statutory VAT. For companies in Germany, Austria and Switzerland.

Asked often

Cleared up front.

Different question? Write to us directly, reply within 48 h.

Server-side tracking is not a universal prerequisite for lawful GA4 use. The legal basis, required consent, data scope and contracts must fit the actual setup. Data controls and operating requirements determine whether a server container is useful. Consent can also be checked in the browser with Tag Assistant.

One possible cause is a browser pixel and Conversion API running in parallel without suitable deduplication. Check the event or transaction IDs required by each destination, tags firing more than once and reconciliation with orders.

Yes, following the same pattern: capture the click ID, send events from the server container, consent signal in front. The six core platforms (Google, Meta, TikTok, LinkedIn, Criteo, Outbrain) are documented in the catalog; further destinations are added per project through the same server container.

Consent Mode V2 communicates user choices to Google tags, which adjust their behaviour. Basic blocks Google tags until consent; Advanced can send limited, cookieless measurement when storage consent is denied. This is not automatically anonymous or legally permitted. The CMP and checks for other destinations remain necessary.

A Google Tag Manager container that processes events on a server. It provides an additional place for data filters and destination controls. Your own endpoint guarantees neither immunity from blockers nor longer cookie lifetimes.

A server-to-server interface that reports conversions directly to Meta, Google and others, independent of the browser pixel and therefore more robust.

We first identify the technical losses that actually occur. Your own endpoint can improve the transmission path but browsers and blockers can still restrict it. We configure data filters and consent rules for each destination and inspect outgoing requests. This does not replace required consent.

Consent Mode V2 controls how Google tags react to the consent state, it does not replace a full CMP implementation. Used correctly they work together: the CMP owns the consent decision, Consent Mode V2 transmits the state correctly to Google services. Without a CMP behind it, Consent Mode V2 is just an API.

Pure event tracking is not affected by the EU AI Act. The Act becomes relevant the moment analytics data drives automated decisions: BigQuery ML for lookalike audiences, custom LLMs for content personalisation, predictive scoring in the CRM. Those pipelines need risk classification, data-provenance documentation and, in the high-risk case, an external audit. The EU AI Act takes effect in phases: many central obligations become relevant from 2 August 2026, with further rules into 2027. We document this in the Measurement Blueprint from day one.

The Frankfurt region on Google Cloud keeps data inside the EU legal space. Third-country transfer becomes the exception rather than the default, and Standard Contractual Clauses cover those exceptions. The residual risk stays: Google is a US parent company and therefore within CLOUD Act reach. Where that matters we harden with CMEK and external key management, described on the [Marketing Data Lakehouse](/en/services/marketing-lakehouse/) page.

A measurement blueprint connects business questions with event definitions, sources, destination mappings and acceptance criteria. A data contract adds quality targets, permitted usage, ownership and versioning. Tests and runtime checks enforce the agreed rules. Guide and template: [Measurement Blueprint](/en/blog/measurement-blueprint-tracking-projects/).

Your dev team implements the tracking, against our Measurement Blueprint. We write the spec, stay available for questions, and take over full QA and everything after implementation. Deliberate stance against vendor lock-in: the code stays with you.

Yes, apps use Firebase Analytics as the foundation, websites use GA4 or Plausible. Event schemas differ, consent architecture differs (app consent vs. browser consent), and QA methodology is technically different. We cover both worlds.

Audit Sprint: €1,490 net, report in 3 working days. One website, one GA4 property, one web GTM container, one CMP, one ads account and up to three conversion paths. Evidence, action plan and a 45-minute review. From the agreed start with complete access and documents. Scope and delivery date are agreed before commissioning. Implementation is separate, with no follow-up obligation. Larger tracking setups: Audit Sprint Plus: from €2,900 net, report in 5–7 working days. One brand, up to two domains and GA4 properties, one web and one server GTM container, one CMP, two ads platforms and five conversion paths; one existing shop or CRM export. Evidence, action plan and a 60-minute review. From the agreed start with complete access and documents. Scope and delivery date are agreed before commissioning. Implementation is separate, with no follow-up obligation.

Yes, the Usercentrics certification (CMP Expert tech track, since June 2026) gives us direct escalation paths and early sight of product changes, not an obligation to recommend. Cookiebot stays our default for SMB setups, OneTrust fits group-wide privacy suites, and where a stack runs without consent-requiring services, we advise a banner-free architecture. All partnerships are listed openly on /en/integrations/.

OneTrust is technically usable at any company size, but the license cost and configuration overhead are usually oversized for SMBs. For smaller companies we typically recommend Usercentrics (DACH market leader) or Cookiebot. We recommend what fits, not what we happen to know best.

Yes, migrating from an existing agency setup is the standard case. We usually start with an Audit Sprint: inventory of the current setup, prioritised defect report, migration plan. Depending on the depth of the existing issues, we decide together whether cleanup or rebuild is more economical. Vendor lock-in is never an argument: all GTM containers, BigQuery exports and CMP configurations stay in the client's ownership.

Next step

Tracking with clear rules and verifiable data flows.

Audit Sprint: €1,490 net, report in 3 working days. One website, one GA4 property, one web GTM container, one CMP, one ads account and up to three conversion paths. Evidence, action plan and a 45-minute review. From the agreed start with complete access and documents. Scope and delivery date are agreed before commissioning. Implementation is separate, with no follow-up obligation.

Juri Saloid

Your contact

Juri Saloid

Founder & Managing Director

hello@datascale.de