GDPR / DSGVO

Server-side does not mean consent-free. It means you control the path.

Every vendor in this category says "GDPR compliant" and none of them can promise it, because the merchant is the controller and carries the risk. What a processor can do is say exactly what it does with the data. That is what this page is.

Four things Tracyn does, each with a document behind it.

Not commitments to make later. Every one of these is readable in full before you install anything.

  • Processed in the EU

    Event processing runs on Google Cloud in the Frankfurt am Main region, and delivery runs through Cloudflare. Both are named as subprocessors with their entities and locations, not described vaguely as "EU infrastructure".

    See the subprocessor list
  • Identifiers hashed before they leave

    Email and phone go to the ad platforms as SHA-256 hashes, computed server-side. Plain-text contact data is never sent to Meta, Google Ads or TikTok — the hash is what the platform matches against, and it is all they receive.

    What each half sends
  • Your consent verdict travels with the event

    Whatever your storefront banner decides is attached server-side and translated into each platform’s own restricted-processing flag — Meta’s data_processing_options, Google’s consent signals, TikTok’s limited data use — instead of being lost between systems.

  • A real Auftragsverarbeitungsvertrag

    An Art. 28 DSGVO processing agreement, published in full rather than promised on request, with the technical and organisational measures and the subprocessor list as annexes.

    Read the AVV

Who is responsible for what.

The split that decides every other question on this page, and the one most often described dishonestly.

Controller

You

It is your shop, your customers and your decision to run advertising. You choose which platforms are connected, which events are sent, and what your consent banner asks. The lawful basis for that processing is yours to establish.

Processor

Tracyn

We process your customers’ data on your instructions and for no purpose of our own. What that covers, for how long, and under which safeguards is the AVV — a contract, not a paragraph on a marketing page.

The full picture is in the Datenschutzerklärung — Teil A covers what we do as controller for this website, Teil B what we do as processor for your shop. Both are in German, because they are the operative legal documents of a German company.

The honest part

What this does not do for you.

Four limits worth knowing before you rely on any of it — including the one that makes most server-side sales pitches wrong.

  • This page is not legal advice, and Tracyn is not your DPO

    Everything here describes what the product does. Whether that is sufficient for your business depends on your data, your customers and your own risk assessment, and that assessment is yours to make with your own counsel.

  • Consent is signalled, not enforced

    Your banner’s verdict is attached to the event and passed to each platform as its restricted-processing flag. Tracyn does not silently drop events it judges non-consented — the platform receives the signal and honours it. If you need a hard block, that belongs in your banner, before the event is generated.

  • Server-side does not remove the consent requirement

    Reading a purchase from the order rather than the browser changes the transport, not the law. Personal data is still being processed and still needs a basis. Anyone selling server-side tracking as a way around consent is describing a liability, not a feature.

  • The ad platforms are their own controllers

    Once a conversion reaches Meta, Google or TikTok, that platform processes it under its own terms for its own purposes as well as yours. That relationship is between you and them; no vendor sits in the middle of it.

Before you install

What merchants ask about GDPR.

Is server-side tracking allowed under GDPR?

Yes, on the same terms as any other processing of personal data: you need a lawful basis, and for the storage and reading of information on a device you need consent under § 25 TDDDG. Moving the send to a server does not change either requirement. What it changes is where the data is handled, who it passes through, and how much of it leaves the EU — all of which are easier to control server-side than in a third-party browser script.

Do I still need a consent banner?

Yes. Tracyn does not replace your consent layer and does not decide consent for you. Your banner establishes the verdict; Tracyn attaches that verdict to every event and passes it to each ad platform as that platform’s own restricted-processing flag.

Where is the data processed, and does it leave the EU?

Event processing runs on Google Cloud in the Frankfurt am Main region, with Cloudflare handling delivery. Both are listed as subprocessors with their legal entities. Data does leave the EU at one point that no vendor can avoid: when you instruct Tracyn to forward a conversion to Meta, Google Ads or TikTok, it goes to that platform under your own relationship with them.

What customer data actually reaches the ad platforms?

The order value and currency, the line items, the Shopify order ID, the click IDs from the original ad click, and SHA-256 hashes of email and phone. The hashes are computed before the event leaves — the platforms receive the hash, never the address or the number.

Do you sign a data processing agreement?

Yes, and it is published in full rather than sent on request. The Art. 28 DSGVO agreement, the technical and organisational measures under Art. 32, and the complete subprocessor list are all readable before you install anything.

Ready to scale on numbers you can trust?

Run Tracyn free for 14 days. We do not charge at all in that window, so if your tracked revenue and match quality have not moved, you walk away having paid nothing.

  • Five-minute setup, no developer
  • Tracking live the same day
  • No contract, cancel anytime