Skip to content
Advisory & Setup · Server-Side GTM

Server-Side GTM Consulting: set up sGTM right, GDPR-compliant.

The hosting decision, migration without a tracking gap, and Consent Mode v2 - the three places where most sGTM projects fail. We advise, implement, and hand over. Control stays with you.

ISO/IEC 27001:2022 · Hetzner Germany EU data residency, GDPR guidance Vendor-neutral · handover included

What you get

What server-side GTM consulting delivers

Server-side GTM consulting is the expert guidance for setting up, migrating, and securing a server-side Google Tag Manager container (sGTM). It decides the points at which an sGTM project loses data or becomes legally exposed - before you put budget into implementation.

Scoping & architecture decision

Before a single line of config, we clarify which hosting architecture fits your traffic, privacy needs, and in-house know-how - own infrastructure, Stape, or Cloud Run.

Migration without a tracking gap

Parallel operation of client and server-side, clean reconciliation of data volumes, controlled cutover moment. No period where conversions vanish.

Consent Mode v2 wired correctly

The most common point of failure in sGTM. We wire the signals so you stay compliant without throwing away recoverable signal.

Platform tags in the server container

GA4, the Meta Conversions API, and Google Ads Enhanced Conversions cleanly in the container, including deduplication and event mapping.

QA & evidence-based measurement

We measure Event Match Quality, match rate, and captured conversions before and after the switch - with evidence, not promises.

Training & handover

Documentation, knowledge transfer, and optional ongoing monitoring. You should understand and run the system, not depend on us.

In short

Server-side GTM (sGTM) in one paragraph

Server-side GTM is a variant of Google Tag Manager in which the tags run not in the user's browser but in a server container on your own infrastructure. Instead of the device sending data directly to Meta, Google, and others, the event first goes to your server container - and from there, in a controlled way, to the platforms.

The difference sounds technical but it is economically decisive: the data path runs over your own subdomain, is more robust against ad-blockers and iOS signal loss, and you control which data ever leaves the building. This container is the heart of modern server-side tracking - and setting it up correctly is what this consulting is about.

The core decision

Hosting decision: own infrastructure, Stape, or Cloud Run

Where your server container runs determines cost, privacy, and control. There is no universally right answer - only the one that fits your traffic, your privacy requirements, and your in-house know-how. This is the first and most important consulting question.

Maximum data sovereignty

Own infrastructure (Hetzner, DE)

Predictable, by server class

  • Full data sovereignty, EU data residency
  • ISO/IEC 27001:2022
  • No per-request costs
  • No US-adjacent provider in the data path
  • Requires setup and ops know-how
  • We can run it managed for you
Fast start

Stape

From ~20 EUR fixed / month

  • Quick to set up
  • Low fixed cost at the start
  • Lots of sGTM tooling built in
  • US-adjacent managed provider
  • Privacy needs careful review
  • Less control over the data path
Scales with volume

Google Cloud Run

~120 to 300 USD / month variable

  • Auto-scaling under high traffic
  • Native Google integration
  • Familiar toolset
  • Variable cost per request
  • US cloud, data-transfer question
  • Hard-to-plan monthly budget

Cost benchmarks from public provider figures (Stape, Google Cloud Run). FW Delta recommends the architecture that fits you - not the one with the highest margin.

No data break

Migration from client-side to server-side

The most dangerous phase is the switch itself. Turn off client-side tracking before server-side measures cleanly, and you tear a gap into the data - and bidding optimises on gaps for weeks.

Our answer is parallel operation. Client and server-side run at the same time for a while. We reconcile the data volumes per event - client and server-side values typically deviate 20 to 40 percent because server-side lets more conversions through in the first place. Only when the deviation is explainable and stable do we switch over in a controlled way.

2-4 wks
Simple sGTM setup
6-12 wks
Complex migration
0
Tracking-gap days
Most common failure point

Consent Mode v2 in sGTM - where most projects fail

Consent Mode v2 has effectively been mandatory since 2024 for meaningful GA4 and Google Ads use in the EEA. Without it you get no modelled data - with wrong wiring you either lose signal or process without a legal basis.

What correct setup delivers

Combined with a clean sGTM setup, Consent Mode v2 can model around 70 percent of the conversion paths of users who reject cookies. That is the difference between blind bidding and reliable optimisation.

We wire the signals so consent is respected while no recoverable data is given away.

The honest framing

Server-side GTM is not a consent bypass. German law (TDDDG) has required consent before accessing terminal devices since 2024 - a server container alone does not create a legal basis.

Clean consent handling makes your setup more legally robust, not guaranteed compliant. We provide professional guidance, not legal advice.

In the server container

Platforms we connect

Three platforms form the core of almost every server container. We configure them including deduplication, event mapping, and hashed first-party data.

GA4

Google Analytics 4

Server-side collection via the Measurement Protocol, robust against ad-blockers, with correct consent behaviour and clean value mapping.

Meta CAPI

Meta Conversions API

Pixel and CAPI in parallel with correct deduplication via event_id - lifting Event Match Quality typically from 3-5 to 8-9.

Google Ads

Enhanced Conversions

Server-side Enhanced Conversions with hashed first-party data for more precise attribution and better bidding.

Governance

Data protection & governance, from the start

The advantage of your own server container only pays off if governance is right. This is not an afterthought - it is part of the architecture consulting.

GDPR / TDDDG framing

Consent before device access. We frame where consent is needed - professionally, not as legal advice.

ISO/IEC 27001:2022

Operation on certified, German infrastructure instead of a US-adjacent default cloud.

EU data residency

Hosting at Hetzner in Germany. Data does not leave the EU unchecked.

DPA & hashing

Data processing agreement handled cleanly, first-party data hashed instead of sent in clear text.

Legal note: This content is professional guidance from a tracking and infrastructure perspective and does not replace individual legal advice. For a binding data-protection assessment, please consult qualified counsel.

How we work

Our consulting process

From inventory to operation - in five traceable steps. Each step has a concrete deliverable that belongs to you.

01

Audit & inventory

We analyse your existing tracking read-only: where signal leaks, what already runs server-side, how consent is wired. In a free initial consultation we map the concrete lever together.

Deliverable: Evidence-based gap analysis + prioritised roadmap
02

Concept & architecture

Hosting decision, platform selection, consent strategy, and migration plan. You get a clear concept any developer can implement - with us or without.

Deliverable: Tracking concept + architecture recommendation
03

Implementation & migration

Set up the server container, configure platform tags, wire Consent Mode v2, run parallel operation, and switch over in a controlled way - with no tracking gap.

Deliverable: Production server container in parallel operation
04

QA & verification

Event Match Quality, deduplication, value integrity, and consent behaviour are checked and evidenced. The setup is only done once the numbers hold up.

Deliverable: QA report with before/after evidence
05

Operation or handover

You decide: a fully documented handover to your team, or ongoing monitoring, updates, and maintenance by us. The consulting ends when you are confident.

Deliverable: Documentation + optional managed monitoring
Which path fits?

Consulting & handover, or a full ownership build?

Two paths to the same goal: reliable server-side tracking. You choose how much you take on yourself.

This page

Server-Side GTM Consulting

Advisory, setup, and handover. We make the architecture decision with you, set up the container, and hand over to your team. Ideal if you have in-house know-how or want to build it.

  • Architecture and hosting decision
  • Setup, migration, and QA
  • Training and documentation
  • Our role ends when you are confident
The full build

Server-side tracking as infrastructure

We build your measurement as server-side infrastructure that belongs entirely to you - hosted in Germany, with no per-event SaaS fees. Ideal if you want to own tracking permanently rather than manage it.

  • Complete infrastructure that is yours
  • No per-event SaaS fees
  • Optional ongoing managed monitoring
  • Focus: data recovery and performance
To the server-side tracking build

Frequently asked questions

What buyers want to know before server-side GTM consulting

What does server-side GTM consulting actually deliver?

Server-side GTM consulting answers the questions that decide between success and data loss before you spend money on implementation: where your server container is hosted, how you migrate without a tracking gap, how Consent Mode v2 is wired correctly, and which platforms belong in the container. You get a defensible concept, a clean setup, and a handover your team can run on its own. We advise and implement - control stays with you.

Should I self-host sGTM, use Stape, or Google Cloud Run?

This is the core question of any sGTM consultation, and there is no blanket answer. Google Cloud Run costs a variable 120 to 300 USD per month and scales with request volume. Stape starts at around 20 EUR fixed per month but is a US-adjacent managed provider. Your own infrastructure on German hardware (Hetzner) gives you full data sovereignty, ISO/IEC 27001:2022, and predictable costs with no per-request billing. We assess your traffic volume, privacy requirements, and in-house know-how and recommend the architecture that fits you - not the one we earn most from.

How do I migrate from client-side to server-side without losing data?

With parallel operation instead of a hard cutover. We run client-side and server-side tracking in parallel for a while, reconcile the data volumes per event, and only switch over when the deviation is explainable and stable. That way no tracking gap opens up where conversions disappear or bidding algorithms optimise on broken data. A simple migration is realistic in 2 to 4 weeks; complex setups with many platforms take 6 to 12 weeks.

Is my setup GDPR-compliant with Consent Mode v2?

Consent Mode v2 has effectively been mandatory since 2024 for meaningful GA4 and Google Ads use in the EU - without it you get no modelled data. But Consent Mode v2 in sGTM is also the most common point of failure: mis-wired signals lead either to data loss or to processing without a legal basis. Server-side GTM alone does not create a legal basis; German law (TDDDG) still requires consent before accessing terminal devices. We review your wiring and set it up cleanly - which makes your setup more legally robust, but this is professional guidance, not legal advice.

What does an sGTM setup cost and how long does it take?

Project cost depends on the number of platforms, the migration scope, and the hosting architecture, which is why we work with individual quotes rather than flat prices. On duration there are reliable benchmarks: simple sGTM setups go live in 2 to 4 weeks, complex migrations take 6 to 12 weeks. Ongoing hosting costs differ significantly by architecture - Cloud Run around 120 to 300 USD per month variable, Stape from 20 EUR fixed, own infrastructure predictable by server class. The cleanest entry point is a free initial consultation, where we map your scope and the concrete effort together.

Do you also offer ongoing monitoring and maintenance?

Yes. A server container is not a set-and-forget system: platform APIs change, consent setups break silently, event parameters go stale. On request we take over hosting, updates, monitoring, and alerting so tracking gaps surface before they distort your bidding. If you prefer to run it yourself, we hand over the fully documented system - the consulting ends when you are confident, not when a contract runs out.

Do I need sGTM if I only use GA4?

Not strictly - but it pays off earlier than most people think. If you spend meaningful ad budget, suffer from ad-blockers and iOS signal loss, or need reliable conversion data for bidding, a server container measurably recovers signal and improves Event Match Quality. If you use GA4 purely descriptively without performance marketing, client-side tracking with correct Consent Mode is often enough. In the consultation we answer exactly this question honestly - instead of selling you infrastructure you do not need.

Start with clarity, not configuration.

In a free initial consultation we map what your current tracking loses and which sGTM architecture is worth it - the most honest foundation for any project.

Vendor-neutral ISO/IEC 27001:2022 · Hetzner DE EU data residency