Found in AI answers?Get a free review
Theory Road.
Analytics & tracking

Server-side tracking, Conversions API and offline conversion setup.

We build the tracking that ad platforms actually bid on: server-side Google Tag Manager on a first-party subdomain, the Meta Conversions API with proper event deduplication, Google Ads enhanced conversions for web and for leads, and offline conversion imports that send booked jobs and closed revenue from your CRM back to the platforms.

Browser pixels alone now miss a meaningful share of conversions because of ad blockers, browser privacy limits and consent choices, and they only see the form fill, never the sale. We close that gap for companies that sell through forms and calls as much as through checkouts. Theory Road holds Meta Verified Business and a Google Ads manager account, and we run this stack on our own brands before we sell it to anyone.

Questions this page answers

  • What is server side tracking and do I need it?
  • How do I set up the Meta Conversions API without double counting?
  • How do enhanced conversions work in Google Ads?
  • How do I import offline conversions from my CRM into Google Ads?
  • Is it safe to use the Meta pixel on a healthcare website?
  • Why is my Meta event match quality low?

Step 1 of 2

How can we help you get found?

What do you need help with?

Next: name, email and budget. That’s it.

How Server-side tracking and Conversions API really works

Where Server-side tracking and Conversions API pays off, and where it stalls.

A browser pixel fires from the visitor's device, so anything that blocks scripts or trims cookies blocks the signal. Server-side tracking moves the collection point to a server container on your own subdomain, which receives events from the site and forwards them to GA4, Meta and Google Ads. The Conversions API is Meta's server endpoint; enhanced conversions are Google's way of matching hashed first-party data like email to signed-in users. Offline conversion import goes further and reports what happened after the lead: the appointment, the signed contract, the invoice.

Setups break in predictable places. The Conversions API gets switched on through a plugin while the pixel keeps firing, with no shared event_id, so Meta counts every lead twice and bidding learns from inflated numbers. Customer data is sent unhashed or not at all, so event match quality stays low. GCLIDs never get captured on forms, so there is nothing to match offline sales to. Consent is ignored on the server side. Health businesses send page URLs and form fields that reveal conditions to ad platforms, which regulators have warned against.

We treat it as one pipeline. First we capture identifiers on every form and call: click IDs, UTM values, and consented email and phone. Then we stand up server GTM on a first-party subdomain, send paired browser and server events with the same event_id, hash customer data before it leaves your server, and respect the consent state. Finally we connect the CRM so booked and closed outcomes flow back to Google Ads and Meta with values attached. Each link is verified in Meta Events Manager diagnostics and Google Ads conversion diagnostics.

Where Server-side tracking and Conversions API sits in your stack

Feeds it

  • Website forms
  • Tracked calls
  • Checkout orders
  • CRM deal stages
  • Consent state
Server-side tracking and Conversions API

It feeds

  • Meta conversion events
  • Google Ads conversions
  • Offline revenue imports
  • GA4 key events

Every connection is built on your accounts and documented, so the data survives any change of vendor.

What we do

Server-side tracking and conversion API setup, scoped to the result.

Scope it with us →
  • Server-side GTM deployment

    We provision a server container on Google Cloud Run or a managed host, map it to a first-party subdomain like data.yourdomain.com, and route GA4, Meta and Google Ads events through it.

  • Meta Conversions API

    We send lead, booking and purchase events server-side with a shared event_id for deduplication, hashed customer parameters, and correct action source, then confirm dedup and match quality in Events Manager.

  • Google Ads enhanced conversions

    We enable enhanced conversions for web and for leads, pass hashed email and phone from forms, and verify the diagnostics in Google Ads show matched, healthy data.

  • Offline conversion import

    We capture GCLID and hashed email at lead time, store them in your CRM, and upload qualified, booked and closed-won stages to Google Ads with values, on a schedule or via API.

  • CRM-to-platform revenue loop

    We map CRM stages to conversion actions in Google Ads and Meta so bidding optimizes toward sales, not form fills, and the same stages feed your reporting.

  • Health-business tracking review

    For clinics and health brands we review what data reaches ad platforms, strip sensitive URLs and parameters, and design tracking around your counsel's HIPAA guidance.

What usually goes wrong

Where Server-side tracking and Conversions API setups break.

The problems we are most often hired to fix, in the order they tend to cost money.

  • No deduplication

    The pixel and the Conversions API both send the same lead without a matching event_id and event name. Meta counts two conversions, reported cost per lead halves overnight, and the algorithm scales spend on false confidence.

  • Missing click IDs

    Forms and call tracking never store the GCLID or the Meta click ID, so when the lead closes weeks later there is nothing to match it to. Offline imports fail or match only a sliver of sales.

  • Raw or thin customer data

    Email and phone are sent unhashed, badly formatted, or not at all. Event match quality stays low, enhanced conversions show errors, and the server events add little over the pixel they were meant to back up.

  • Server-side that ignores consent

    Moving tags to a server makes them harder for blockers to stop, which tempts teams to skip consent checks entirely. That creates legal exposure and breaks the promise your cookie banner makes to visitors.

What we connect it to

Server-side tracking and Conversions API, wired into the rest of the business.

  • Google Cloud Run

    Hosts the server Tag Manager container on infrastructure you own and pay for directly.

  • Stape

    Managed server container hosting when you would rather not run Google Cloud yourself.

  • Meta Events Manager

    Where we verify deduplication, event match quality and Conversions API diagnostics after launch.

  • HubSpot

    Deal stages mapped to offline conversions for Google Ads and Meta with click IDs stored on contacts.

  • Salesforce

    Opportunity stages and amounts sent back to ad platforms as qualified and closed conversions.

  • CallRail

    Call conversions carry click IDs so phone leads can be imported and valued like forms.

  • Shopify

    Order events sent server-side with order IDs so purchases dedupe against the browser pixel.

  • Twilio

    Custom call and text flows pass lead identifiers into the same conversion pipeline.

How an engagement runs

From audit to running it.

  1. Audit.

    We trace one real lead from ad click to closed sale, list every place identifiers are lost, check dedup and match quality, and review what sensitive data reaches ad platforms.

  2. Fix or build.

    We add click ID and consent capture to forms and calls, deploy server GTM on a first-party subdomain, and send deduplicated Conversions API and enhanced conversion events.

  3. Connect.

    We map CRM stages to Google Ads and Meta conversion actions, schedule offline uploads with values, and confirm matched rates in each platform's diagnostics before bidding depends on them.

  4. Run or hand over.

    We monitor diagnostics, match rates and upload errors monthly, or hand over runbooks, hosting access and credentials in your own accounts so your team runs it.

A good fit

  • Lead-gen businesses where the real sale happens by phone or in person, days or weeks after the form fill.
  • Advertisers spending enough on Meta or Google that a wrong conversion signal is wasting real budget every week.
  • Ecommerce brands losing purchase signal to ad blockers, browser privacy limits and consent choices.
  • Health and regulated businesses that need tracking designed around what may and may not leave the site.

Probably not a fit

  • If you spend little on paid media, a clean browser pixel and GA4 setup is enough; server-side can wait.
  • If your CRM does not record lead outcomes yet, fix that first, because offline imports need stages to report.
  • We are not lawyers; HIPAA decisions belong to your counsel, and we build to their written guidance.
What it costs

Pricing, plainly.

The platforms themselves do not charge for the Conversions API, enhanced conversions or offline conversion imports. Server-side Tag Manager is free software, but the container needs hosting: either your own Google Cloud project, billed by usage, or a managed host on a monthly plan. For most small and mid-size sites that cost is modest and scales with traffic. Our side is scoped after a short call, usually a fixed-scope audit and build first, then monthly monitoring of diagnostics and uploads or a documented hand-over. Ongoing work runs month to month after an initial term.

Perspectives

Reading on Server-side tracking and Conversions API.

All perspectives
Questions

Hiring help with Server-side tracking and Conversions API.

Q01
Are you a certified Meta or Google partner?
No. We are independent, not a Meta Business Partner or Google Partner. We hold Meta Verified Business and a Google Ads manager account, and we run server-side tracking on our own brands. Independence means we recommend what your volume actually needs, whether that is a full server container or just enhanced conversions, and we are not paid to push hosting plans or add-ons.
Q02
What is server side tracking in plain terms?
Instead of every ad platform's script running in the visitor's browser, the site sends events to one server container on your own subdomain. That container forwards clean, consented, deduplicated events to GA4, Meta and Google Ads. You get more reliable signal, fewer third-party scripts slowing the page, and control over exactly what data each platform receives.
Q03
How does Meta deduplicate pixel and Conversions API events?
Meta matches a browser event and a server event when they share the same event name and the same event_id within a short window, and keeps one. So the site must generate one ID per action and send it through both paths. We set that up and check the deduplication status in Events Manager before calling the job done.
Q04
What is the difference between enhanced conversions and offline conversion import?
Enhanced conversions add hashed email or phone to a conversion that happens on your site, helping Google match it to a signed-in user. Offline import reports an outcome that happens later, like a booked job or a signed contract, matched by the stored GCLID or hashed contact data. Most lead-gen accounts benefit from both working together.
Q05
Can we use the Meta pixel on a healthcare website?
Carefully, and only with your counsel's sign-off. Regulators have warned that tracking technologies on health sites can disclose protected health information through URLs, form fields and event names. We audit what is being sent, remove sensitive pages and parameters from tracking, and often send only generic, non-identifying events server-side. HIPAA compliance is a legal decision; we build to your counsel's written guidance.
Q06
How far back can offline conversions be imported into Google Ads?
Google Ads accepts click-based offline conversions only within the conversion action's click-through window, and uploads for clicks older than 90 days are rejected. That is why we schedule uploads daily or weekly rather than quarterly, and why the GCLID must be stored on the lead record the moment the form is submitted.
Work with us

Let’s get Server-side tracking and Conversions API working for you.

A short note on where the business is and where it needs to go. A senior partner replies within one business day.

t@theoryroad.com