This website uses cookies

Read our Privacy policy and Terms of use for more information.

A server-side event is still data collection. A hashed identifier is still not automatically anonymous. Measurement choices change where an event travels; privacy choices govern whether and how personal data may be used. This guide explains the general mechanics of browser and server tracking, cookies, consent tools and privacy transformations. It also separates technical controls from legal obligations. Laws and browser policies change, so use the linked primary guidance and qualified advice for your specific jurisdictions and processing.

⭐ Know these first

Start with Server-side tracking, Consent management platform (CMP), General Data Protection Regulation (GDPR), Pseudonymization, Event deduplication. Then follow the grouped learning order below.

📎 How to read this page

What it means gives the precise meaning. Operator translation gives the version you might hear in a real ecommerce meeting. In real life shows an illustrative example. Watch out and the confusion boxes show where a familiar term can mislead.

📈 Read the relationships first

These combinations are diagnostic hypotheses, not proof of causality. Compare the same period and scope, then investigate the mechanism.

🖥️ Client-side events ↓ + server events ↑

Usually means: The collection route may have changed, while consent and event eligibility still govern. Check next: Compare event IDs and destination rules.

🍪 Consent choices ↑ + advertising events flat

Usually means: The tag manager may not be applying the recorded signal, or the events may be blocked downstream. Check next: Test consent states end to end.

🔐 Hashed identifiers ↑ + match rate ↑

Usually means: Matching may improve, but hashing alone does not make data anonymous. Check next: purpose, access, retention and applicable privacy rules.

📊 Browser + server purchase events ↑ + orders flat

Usually means: Both paths may count the same purchase twice. Check next: Use a shared event identifier and a defined deduplication window.

How events are collected

01 · 🔵 Operations

Client-side tracking = Collection code running in a user’s browser or device

🧠 What it means
Collection code running in a user’s browser or device

💬 OPERATOR TRANSLATION

“Client-side tracking collects or sends events from code running in the visitor’s browser or app. Browser settings, blockers, consent and device conditions can limit what is observed.”

🛍️ In real life
A product-page script sends a view event from the shopper’s browser after applicable permission and configuration.

A browser records a storefront interaction and sends an event.

🔗 Related: Server-side tracking · Tag manager · Tracking pixel · ↑ all terms

02 · 🟢 Core

Server-side tracking = Collection or forwarding of events from a server environment

🧠 What it means
Collection or forwarding of events from a server environment

💬 OPERATOR TRANSLATION

“Server-side tracking processes or forwards event data from a server. It can improve control over routing but does not itself create consent, identity or permission to collect data.”

🛍️ In real life
A commerce backend forwards a completed order event to an analytics endpoint under the merchant’s data rules.

A server routes approved event data to measurement destinations.

🔗 Related: Client-side tracking · Tag manager · Tracking pixel · ↑ all terms

03 · 🔵 Operations

Tag manager = Tool for deploying and controlling website tags or tracking code

🧠 What it means
Tool for deploying and controlling website tags or tracking code

💬 OPERATOR TRANSLATION

“A tag manager lets authorized users configure tags, triggers and variables, often without editing site code for each change. Governance and testing remain necessary.”

🛍️ In real life
An analytics team deploys a page-view tag when a page loads, following approved consent settings.

A tag manager routes configured tracking tools from a storefront.

🔗 Related: Client-side tracking · Server-side tracking · Tracking pixel · ↑ all terms

04 · 🔵 Operations

Tracking pixel = Small request or code element used to signal an event to a service

🧠 What it means
Small request or code element used to signal an event to a service

💬 OPERATOR TRANSLATION

“A tracking pixel commonly refers to code or a remote request that signals a page view or interaction to a measurement service. The term does not guarantee a literal visible pixel.”

🛍️ In real life
Opening a page triggers an event request to an advertising platform when allowed by implementation and privacy rules.

A small tracking request travels from a page to a measurement service.

🔗 Related: Client-side tracking · Server-side tracking · Tag manager · ↑ all terms

05 · 🔵 Operations

First-party cookie = Cookie set in the context of the site being visited

🧠 What it means
Cookie set in the context of the site being visited

💬 OPERATOR TRANSLATION

“A first-party cookie is set by the site the user is visiting, under browser and site rules. Its availability and permitted use depend on settings, consent and applicable law.”

🛍️ In real life
A store uses a cookie to remember a basket preference on its own domain.

A storefront stores a small preference for its returning visitor.

🔗 Related: Third-party cookie · Consent management platform (CMP) · Consent record · ↑ all terms

06 · 🔵 Operations

Third-party cookie = Cookie set in a context distinct from the site being visited

🧠 What it means
Cookie set in a context distinct from the site being visited

💬 OPERATOR TRANSLATION

“A third-party cookie is associated with a domain other than the site shown in the browser context. Browser support and policy restrictions vary and continue to change.”

🛍️ In real life
An embedded advertising service attempts to read its cookie while a shopper visits the retailer’s site.

A browser blocks or permits a cross-site cookie request.

🔗 Related: First-party cookie · Consent management platform (CMP) · Consent record · ↑ all terms

07 · 🟢 Core

Consent management platform (CMP) = Tool that presents choices and records consent signals

🧠 What it means
Tool that presents choices and records consent signals

💬 OPERATOR TRANSLATION

“A consent management platform presents privacy choices and stores or communicates consent signals. Its configuration must reflect applicable jurisdiction, purpose and implementation requirements.”

🛍️ In real life
A shopper selects analytics but declines advertising cookies, and the CMP records the chosen signal.

A customer selects privacy choices on a consent interface.

🔗 Related: First-party cookie · Third-party cookie · Consent record · ↑ all terms

08 · 🔵 Operations

Consent record = Evidence of a person’s choice or other recorded consent state

🧠 What it means
Evidence of a person’s choice or other recorded consent state

💬 OPERATOR TRANSLATION

“A consent record stores information such as the choice, time, notice version and relevant purposes. Required evidence and legal basis depend on jurisdiction and processing context.”

🛍️ In real life
A retailer retains a timestamped record of a customer’s marketing opt-in and the notice shown.

A consent choice is recorded alongside its time and notice version.

🔗 Related: First-party cookie · Third-party cookie · Consent management platform (CMP) · ↑ all terms

Privacy laws and personal data

09 · 🟢 Core

General Data Protection Regulation (GDPR) = EU data-protection regulation governing personal-data processing

🧠 What it means
EU data-protection regulation governing personal-data processing

💬 OPERATOR TRANSLATION

“The GDPR establishes rules for processing personal data in its territorial scope, including principles, rights and controller or processor duties. Determine applicability and lawful basis with qualified counsel.”

🛍️ In real life
An ecommerce business serving people in the EU maps the personal data it collects and its processing purposes.

A team maps personal-data uses and responsibility under a defined legal scope.

🔗 Related: California Consumer Privacy Act (CCPA) · California Privacy Rights Act (CPRA) · Personally identifiable information (PII) · ↑ all terms

10 · 🔵 Operations

California Consumer Privacy Act (CCPA) = California privacy law granting covered consumers rights over personal information

🧠 What it means
California privacy law granting covered consumers rights over personal information

💬 OPERATOR TRANSLATION

“The CCPA, as amended, gives covered California consumers rights regarding personal information and places duties on covered businesses. Coverage and obligations depend on current law and facts.”

🛍️ In real life
A covered business handles a California resident’s request to know, correct or delete personal information under applicable rules.

A company reviews a consumer privacy request and routes it to the right team.

🔗 Related: General Data Protection Regulation (GDPR) · California Privacy Rights Act (CPRA) · Personally identifiable information (PII) · ↑ all terms

11 · 🔵 Operations

California Privacy Rights Act (CPRA) = California ballot measure that amended and expanded the CCPA

🧠 What it means
California ballot measure that amended and expanded the CCPA

💬 OPERATOR TRANSLATION

“The CPRA is the 2020 measure that amended the CCPA; many current requirements are commonly discussed under the CCPA as amended. Check current statutory text and regulations for obligations.”

🛍️ In real life
A privacy lead checks current California rules on sensitive personal information and consumer requests.

A legal team reviews updated California privacy requirements.

🔗 Related: General Data Protection Regulation (GDPR) · California Consumer Privacy Act (CCPA) · Personally identifiable information (PII) · ↑ all terms

12 · 🔵 Operations

Personally identifiable information (PII) = Information that identifies or can be linked to a person

🧠 What it means
Information that identifies or can be linked to a person

💬 OPERATOR TRANSLATION

“PII is a context-dependent term for information that identifies or can be linked to an individual. Definitions differ across laws and policies; minimize collection and protect identifiers.”

🛍️ In real life
An email address combined with order details can identify a customer and needs appropriate safeguards.

An analyst flags customer-linked fields before exporting a dataset.

🔗 Related: General Data Protection Regulation (GDPR) · California Consumer Privacy Act (CCPA) · California Privacy Rights Act (CPRA) · ↑ all terms

Transform, reconcile and label data

13 · 🔵 Operations

Hashing = One-way transformation that maps data to a fixed-length value

🧠 What it means
One-way transformation that maps data to a fixed-length value

💬 OPERATOR TRANSLATION

“Hashing transforms input into a fixed-length output using a hash function. It is not encryption and does not by itself anonymize data; predictable inputs may be guessed or linked.”

🛍️ In real life
A platform requests normalized, hashed email values for matching, but the retailer still treats the source and output carefully.

A data field is transformed before a controlled matching process.

🔗 Related: Pseudonymization · Anonymization · Event deduplication · ↑ all terms

14 · 🟢 Core

Pseudonymization = Processing that replaces direct identifiers while retaining a re-linking path

🧠 What it means
Processing that replaces direct identifiers while retaining a re-linking path

💬 OPERATOR TRANSLATION

“Pseudonymization reduces direct identification by replacing identifiers with pseudonyms, while additional information can reconnect data to a person. It remains personal data under GDPR when linkable.”

🛍️ In real life
A research dataset replaces customer IDs with tokens while a separately controlled key allows authorized re-linking.

Customer identifiers are replaced with coded tokens and a protected key.

🔗 Related: Hashing · Anonymization · Event deduplication · ↑ all terms

15 · 🔵 Operations

Anonymization = Processing that makes identification no longer reasonably possible

🧠 What it means
Processing that makes identification no longer reasonably possible

💬 OPERATOR TRANSLATION

“Anonymization aims to remove the ability to identify people from data, considering reasonably likely means and auxiliary information. Removing names alone is not enough; legal assessments are context-specific.”

🛍️ In real life
A team tests whether released aggregate data can be combined with outside datasets to identify individuals.

A privacy review checks whether people can be re-identified from released data.

🔗 Related: Hashing · Pseudonymization · Event deduplication · ↑ all terms

16 · 🟢 Core

Event deduplication = Identification and removal or merging of repeated event records

🧠 What it means
Identification and removal or merging of repeated event records

💬 OPERATOR TRANSLATION

“Event deduplication detects multiple records representing the same intended event, often using shared identifiers and rules. Keep the key and window explicit so distinct valid events are retained.”

🛍️ In real life
Browser and server purchase events share an event ID, allowing the analytics pipeline to count one purchase.

Two copies of one purchase event are matched and counted once.

🔗 Related: Hashing · Pseudonymization · Anonymization · ↑ all terms

17 · 🔵 Operations

Urchin Tracking Module parameters (UTM parameters) = URL parameters used to label campaign traffic

🧠 What it means
URL parameters used to label campaign traffic

💬 OPERATOR TRANSLATION

“UTM parameters are query-string labels, commonly for source, medium and campaign, that help analytics classify incoming traffic. Naming conventions and redirects determine whether values survive.”

🛍️ In real life
An email link includes campaign labels so sessions can be grouped under that newsletter promotion.

A labeled campaign link carries source and campaign details into analytics.

🔗 Related: Hashing · Pseudonymization · Anonymization · ↑ all terms

18 · 🔵 Operations

Cross-domain tracking = Measurement setup that connects activity across multiple domains

🧠 What it means
Measurement setup that connects activity across multiple domains

💬 OPERATOR TRANSLATION

“Cross-domain tracking links measurement across domains under configured identity and privacy rules. Domains, consent signals and referral exclusions must be tested; it does not guarantee a complete user journey.”

🛍️ In real life
A retailer links its storefront and hosted checkout domains so eligible activity can be analyzed across the handoff.

A shopper moves from store domain to checkout with a consent-aware measurement handoff.

🔗 Related: Hashing · Pseudonymization · Anonymization · ↑ all terms

🔀 First-party data vs first-party cookie

First-party data describes a relationship or source context; a first-party cookie is browser storage set by the visited site.

🔀 Server-side tracking vs permission

Server-side describes where processing or forwarding runs. It does not create consent or a legal basis.

🔀 Hashing vs pseudonymization vs anonymization

Hashing transforms a value. Pseudonymization can be reversed with separately held information. Anonymization requires re-identification to be no longer reasonably possible in context.

🔀 Consent banner vs consent record

The banner presents choices. The record preserves the choice and context needed to evidence what happened.

🤔 Still confused?

Follow this thread: Client-side tracking → First-party cookie → General Data Protection Regulation (GDPR) → Hashing. That sequence moves from the basic object or relationship to the decisions and checks it supports.

Sources and scope

Primary documentation checked on 27 September 2026. Platform features and eligibility can change; examples and cartoon situations are illustrative.

Reply

Avatar

or to participate