Agent skill

Server Side Tracking

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implementing server-side tracking with privacy controls using Google Tag Manager server containers.

Apache-2.0Auto-check passedBackend & APIs

Install Server Side Tracking

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills server-side-tracking --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/server-side-tracking .claude/skills/server-side-tracking && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
server-side-tracking
GitHub stars
295
Token cost
~2.4k tokens
SKILL.md length
887 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implementing server-side tracking with privacy controls using Google Tag Manager server containers.

  • Works in 6 steps: Compare client-side events sent vs.… → Verify consent state is correctly parsed… → Confirm no PII is forwarded to… → …
  • Tasks that involve Backend development
  • SKILL.md covers Overview, Architecture, Consent-Aware Event Forwarding and Server-Side Tag Configurations, plus 2 more sections
  • Runs Python scripts from its folder; reaches data.pinnacle-ecommerce.com

What it does

Server Side Tracking is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implementing server-side tracking with privacy controls using Google Tag Manager server containers. Covers first-party data collection, IP anonymization, consent-aware event forwarding, and reducing client-side third-party cookie exposure.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Backend & APIs, covering Backend development and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Backend development
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/server-side-tracking”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Compare client-side events sent vs. server-side events received (expect < 2% loss)
  2. Verify consent state is correctly parsed for all forwarded events
  3. Confirm no PII is forwarded to destinations where consent is denied
  4. Check that IP anonymization is applied before all third-party forwarding
  5. Validate first-party cookie durations match policy
  6. Review server logs for any unexpected outbound connections

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • data.pinnacle-ecommerce.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Server Side Tracking loads about 2.4k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 887 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 887 words, ~2,379 tokens.

Download SKILL.mdSave it as .claude/skills/server-side-tracking/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
server-side-tracking
description
Implementing server-side tracking with privacy controls using Google Tag Manager server containers. Covers first-party data collection, IP anonymization, consent-aware event forwarding, and reducing client-side third-party cookie exposure.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
cookie-consent-compliance
metadata.tags
server-side-tracking, gtm-server, first-party-data, ip-anonymization, consent-forwarding

Server-Side Tracking with Privacy Controls

Overview

Server-side tracking moves data collection from the user's browser to a server-controlled environment, providing greater control over what data is shared with third parties. Instead of loading third-party JavaScript directly in the browser (which sets third-party cookies and sends data to external servers without intermediation), a server-side container receives events from the client, processes them, and selectively forwards data to analytics and advertising endpoints. This architecture enables IP anonymization before data leaves the first-party infrastructure, consent-based routing of events, and reduced reliance on third-party cookies — directly supporting ePrivacy Directive Article 5(3) compliance and data minimization under GDPR Article 5(1)(c).

Architecture

Client-Server Flow
User's Browser
    │
    ├── Client-side GTM container (minimal)
    │   └── Sends events to first-party endpoint
    │
    ▼
First-Party Server Endpoint
(https://data.pinnacle-ecommerce.com)
    │
    ├── Server-side GTM container
    │   ├── Validates consent state
    │   ├── Anonymizes IP address
    │   ├── Strips unnecessary identifiers
    │   ├── Applies data minimization rules
    │   │
    │   ├── [If analytics consent granted]
    │   │   └── Forward to Google Analytics 4
    │   │
    │   ├── [If advertising consent granted]
    │   │   ├── Forward to Google Ads
    │   │   ├── Forward to Meta Conversions API
    │   │   └── Forward to other ad platforms
    │   │
    │   └── [If all consent denied]
    │       └── Log aggregate pageview count only (no PII)
    │
    └── First-party server logs (retention: 90 days)
Infrastructure Setup for Pinnacle E-Commerce Ltd

Server Container Hosting Options:

OptionProviderMonthly Cost (est.)LatencyControl
Google Cloud RunGoogle CloudEUR 50-200LowHigh
AWS App RunnerAmazon Web ServicesEUR 40-180LowHigh
Custom DockerSelf-hostedEUR 30-150VariesMaximum
Stape.ioManaged serviceEUR 20-100LowMedium

Pinnacle E-Commerce Ltd Configuration:

SettingValue
Server container URLhttps://data.pinnacle-ecommerce.com
Custom domaindata.pinnacle-ecommerce.com (CNAME to container)
Container regioneurope-west1 (Belgium) — co-located with EU users
ScalingMin 1 instance, max 10 instances
SSL certificateLet's Encrypt via managed certificate
First-party cookie domain.pinnacle-ecommerce.com
Custom Domain for First-Party Context

Using a subdomain of the main site domain ensures:

  • Cookies set by the server container are first-party cookies
  • Requests to data.pinnacle-ecommerce.com are same-site, avoiding third-party cookie restrictions
  • Safari ITP and Firefox ETP do not apply cross-site tracking protections

DNS Configuration:

data.pinnacle-ecommerce.com  CNAME  server-container-abc123.run.app

Every event arriving at the server container includes the consent state from the client. The server validates this before forwarding:

Event Payload from Client:

json
{
  "client_id": "1234567890.1709000000",
  "event_name": "purchase",
  "event_params": {
    "transaction_id": "TXN-2026-0314-001",
    "value": 149.99,
    "currency": "EUR",
    "items": [{"item_id": "SKU-001", "item_name": "Widget Pro"}]
  },
  "consent_state": {
    "analytics_storage": "granted",
    "ad_storage": "denied",
    "ad_user_data": "denied",
    "ad_personalization": "denied"
  },
  "user_agent": "Mozilla/5.0...",
  "ip_address": "203.0.113.42"
}

Server-Side Routing Logic:

DestinationRequired ConsentData Sent
GA4 Measurement Protocolanalytics_storage: grantedEvent name, params, anonymized client_id
Google Ads Conversion APIad_storage + ad_user_data: grantedConversion data, gclid, hashed email
Meta Conversions APIad_storage + ad_user_data: grantedEvent data, fbp, hashed email/phone
Aggregate counter (internal)None required+1 to event type counter (no PII)
IP Anonymization

The server container anonymizes IP addresses before forwarding to any third party:

Anonymization Rules:

MethodDescriptionUse Case
IPv4 last octet zeroing203.0.113.42 → 203.0.113.0Standard GA4 anonymization
IPv6 last 80 bits zeroing2001:db8::1234:5678 → 2001:db8::IPv6 anonymization
Full IP removalIP not forwarded at allMaximum privacy (Meta CAPI)
Geolocation-onlyResolve to country/region, discard IPGeo reporting without IP

Pinnacle E-Commerce Ltd Policy:

  • GA4: Forward anonymized IP (last octet zeroed) for geographic reporting
  • Google Ads: Forward anonymized IP for conversion geo-attribution
  • Meta CAPI: Do not forward IP; send hashed email only (with ad_user_data consent)
  • Internal logs: Retain full IP for 24 hours for security/fraud detection, then anonymize
Data Minimization at the Server Layer

The server container strips data before forwarding:

Data ElementRetained for GA4Retained for AdsRetained Internally
Full URLPath only (no query params)Path onlyFull URL (90 days)
User agentReduced UA (SEC-CH-UA)Reduced UAFull UA (24 hours)
IP addressAnonymizedAnonymizedFull (24 hours)
ReferrerDomain onlyDomain onlyFull (90 days)
Client IDGA client_idgclid/wbraid onlyInternal session ID
Email (hashed)Not sentSHA-256 hashNot stored

Server-Side Tag Configurations

Show full SKILL.md (367 more words)Show less
GA4 Server-Side Tag
SettingValue
Measurement IDG-PINNACLE123
API SecretStored in Secret Manager
Send toGA4 Measurement Protocol
IP anonymizationEnabled (default in GA4)
Client ID sourceFirst-party _ga cookie
Session ID sourceFirst-party ga* cookie
Meta Conversions API Tag
SettingValue
Pixel ID123456789012345
Access TokenStored in Secret Manager
Event deduplicationevent_id matches browser Pixel event_id
Data sentEvent name, event_time, action_source, hashed email
IP forwardingDisabled
User agent forwardingReduced UA only

The server container can set first-party cookies via Set-Cookie headers, giving them longer lifetimes than client-side JavaScript cookies (which Safari ITP caps at 7 days):

CookieSet ByDurationPurpose
_gaServer (Set-Cookie header)2 yearsGA4 client identifier
_ga_PINNACLEServer (Set-Cookie header)2 yearsGA4 session persistence
_fbcServer (Set-Cookie header)90 daysMeta click identifier
_pin_sessServer (Set-Cookie header)30 minutesInternal session tracking

All cookies above are set only when the corresponding consent category is granted.

Monitoring and Debugging

Server Container Health Checks
MetricTargetAlert Threshold
Request latency (p99)< 200ms> 500ms
Error rate< 0.1%> 1%
Event throughputBaseline +/- 20%> 30% deviation
Consent validation failures0> 0
Forwarding failures (GA4)< 0.5%> 2%
Forwarding failures (Meta)< 1%> 5%
Data Flow Audit

Monthly audit of server-side tracking:

  1. Compare client-side events sent vs. server-side events received (expect < 2% loss)
  2. Verify consent state is correctly parsed for all forwarded events
  3. Confirm no PII is forwarded to destinations where consent is denied
  4. Check that IP anonymization is applied before all third-party forwarding
  5. Validate first-party cookie durations match policy
  6. Review server logs for any unexpected outbound connections
  • ePrivacy Directive 2002/58/EC, Article 5(3) — Consent for device storage/access; server-side cookies still require consent if non-essential
  • GDPR Article 5(1)(c) — Data minimization principle; server-side filtering reduces data shared with third parties
  • GDPR Article 28 — Data processor requirements for server hosting providers
  • GDPR Article 44-49 — Transfer restrictions if server container is outside EEA
  • Google Tag Manager Server-Side Documentation — Container setup and tag configuration
  • Meta Conversions API Documentation — Server-side event forwarding for Meta advertising
  • Safari Intelligent Tracking Prevention (ITP) — Client-side cookie limitations driving server-side adoption
  • CNIL Deliberation No. 2020-091 — Server-set cookies still subject to consent requirements

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/server-side-tracking of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Server Side Tracking next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Server Side Tracking compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Server Side Tracking this skillmukul975/Privacy-Data-Protection-Skills295—~2.4kAutomated safety check: PassApache-2.0
GitHub Issuesscify/laravel-cookie-guard148—~170Automated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Node Backend Development Guidelinesdiet103/claude-code-infrastructure-showcase10k2 repos~2kAutomated safety check: PassMIT
Laravel Best Practicesanonaddy/anonaddy4.9k13 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • GitHub Issues

    scify/laravel-cookie-guard

    Fetches open GitHub issues for the current repository using the gh CLI.

    148 GitHub stars~170 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Node Backend Development Guidelines

    diet103/claude-code-infrastructure-showcase

    Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.

    10k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Laravel Best Practices

    anonaddy/anonaddy

    Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code.

    4.9k GitHub starsUsed in 13 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Laravel Actions

    coollabsio/coolify

    Build, refactor, and troubleshoot Laravel Actions using lorisleiva/laravel-actions.

    63k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Server Side Tracking

What does Server Side Tracking do?

Implementing server-side tracking with privacy controls using Google Tag Manager server containers. Server Side Tracking is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implementing server-side tracking with privacy controls using Google Tag Manager server containers.

When should I use Server Side Tracking?

Server Side Tracking fits situations like: tasks that involve Backend development; tasks that involve Privacy and GDPR.

How do I install Server Side Tracking in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a claude-code`. Or copy the skill folder (skills/privacy/server-side-tracking in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/server-side-tracking in your project. Claude Code loads it when a task matches its description.

How do I install Server Side Tracking in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a codex`. Or copy the skill folder (skills/privacy/server-side-tracking in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/server-side-tracking in your project. Codex loads it when a task matches its description.

Can I use Server Side Tracking in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill server-side-tracking -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/server-side-tracking, .gemini/skills/server-side-tracking, .github/skills/server-side-tracking and .opencode/skills/server-side-tracking in your project.

What does Server Side Tracking need to run?

Going by SKILL.md and its folder, Server Side Tracking needs Python for the scripts in its folder. Our summary lists: Python 3; Docker.

Does Server Side Tracking access the network?

SKILL.md names 1 domain. In commands or code: data.pinnacle-ecommerce.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Server Side Tracking safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Server Side Tracking use?

Server Side Tracking is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Server Side Tracking use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Server Side Tracking?

Skills that share tags, products or a category with Server Side Tracking: GitHub Issues (scify/laravel-cookie-guard, 148 stars), Configuring Horizon (coollabsio/coolify, 63k stars), Fortify Development (coollabsio/coolify, 63k stars) and Node Backend Development Guidelines (diet103/claude-code-infrastructure-showcase, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Server Side Tracking?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.