TrackSure Cloud – Server-Side Tracking, Meta CAPI & GA4 for WooCommerce
★ What Makes TrackSure Different TrackSure is the only free WordPress plugin that combines server-side conversion tracking (Meta CAPI + GA4 Measurement Protocol) with a complete first-party analytics platform — no GTM required, no external cloud, no monthly fees. Unlike PixelYourSite, TrackSure includes a full analytics dashboard — user journeys, funnels, and attribution — at no extra cost. Unlike GTM-based solutions, it needs no server container, no custom subdomain, and no external hosting. 42% of internet users run ad blockers, and iOS 14+ reduced Meta Pixel reported conversions by 30–40% for most advertisers. TrackSure’s server-side tracking recovers conversions from both, sending events directly from your WordPress server to Meta, GA4, TikTok, Pinterest, and Google Ads — bypassing browser limitations entirely. Setup takes under 3 minutes: paste your Meta Pixel ID and Access Token, and TrackSure handles the browser pixel, Conversion API, event deduplication, and Advanced Matching for maximum Event Match Quality (EMQ). For WooCommerce Store Owners If you run WooCommerce and Meta or Google Ads, TrackSure connects your real purchase data directly to your ad platform — bypassing iOS restrictions, ad blockers, and Safari cookie limits. Higher Event Match Quality (EMQ) means better optimization and lower cost-per-acquisition. For Marketers & Agencies Get user journey tracking, funnel visualization, multi-touch attribution, and traffic source analysis without paying $500/month for Amplitude or Mixpanel. Five attribution models and an assisted conversions report show exactly which channels drive revenue. Manage multiple client sites from the same plugin. For Developers TrackSure exposes a JavaScript API (window.TrackSure.track()), a PHP API, and WordPress hooks (tracksure_filter_event_data, tracksure_conversion_recorded) for custom event tracking with full server-side control — no dependency on browser JavaScript. window.TrackSure.track('button_click', { button_name: 'Download PDF' }); Documentation | Support | GitHub | Get Pro What TrackSure Does Server-Side Conversion Tracking (CAPI) Meta Conversion API — send purchase, view content, add to cart, checkout, and page view events server-to-server Google Analytics 4 Measurement Protocol — server-side GA4 event forwarding TikTok Events API and Pinterest Conversion API (Pro) Automatic browser + server event deduplication — each event gets a unique ID shared between client and server so platforms count it once First-Party Analytics Dashboard All analytics data stored in your WordPress database — you own every byte Automatic traffic source detection — organic search (Google, Bing, DuckDuckGo), social media (Facebook, Instagram, LinkedIn, TikTok), email, referrals, AI chatbots (ChatGPT, Claude, Perplexity), and direct — identified without UTM tags Session-based user journeys with 30-day attribution window (configurable) — complete path from first visit to conversion, including every touchpoint across multiple sessions Five attribution models: first-touch, last-touch, linear, time-decay, position-based Assisted conversion reporting — see which channels helped even without getting final credit Real-time visitors — see who is on your site now and what pages they’re viewing Goals, Funnels & Conversion Tracking Custom conversion goals for form submissions, purchases, downloads, video views, or any event Funnel visualization — see where visitors drop off in your checkout or signup flow Goal completion rates with trend analysis Revenue attribution — connect each sale to its traffic source, campaign, and touchpoint eCommerce Conversion Tracking Auto-tracks the full purchase funnel: product view → add to cart → checkout → purchase Works with WooCommerce and FluentCart (Free), Easy Digital Downloads, SureCart, Cartflow, and MemberPress (Pro) Revenue attribution — connect each sale to its traffic source and campaign Checkout funnel visualization with drop-off rates at each step Privacy & Compliance GDPR and CCPA ready with built-in consent manager support (Cookiebot, CookieYes, OneTrust, and more) Cookieless tracking option (uses localStorage instead of cookies — no consent banner required in some jurisdictions) IP anonymization, Do Not Track (DNT) support, and WordPress privacy tools integration No data leaves your server unless you enable an ad platform destination — with the single exception of the optional IP geolocation lookup, which can be switched off in Settings → Privacy Who Is TrackSure For? WooCommerce & FluentCart store owners running paid ads who need more accurate conversion data for Meta, Google Ads, and other platforms Bloggers & content creators who want to see which posts bring the most traffic, engagement, and conversions Small business owners who need simple, privacy-friendly analytics without Google Analytics complexity Digital marketers managing ad campaigns who want user journey tracking, funnel visualization, and multi-touch attribution Agencies & freelancers who need analytics and conversion tracking across client sites (Pro includes white label) Privacy-focused site owners who want GDPR-compliant analytics without sending data to external services Developers who need JavaScript and PHP APIs for custom event tracking with WordPress hooks Free vs Pro Free includes everything you need for analytics and conversion tracking: First-party analytics dashboard with user journeys, funnels, goals, and attribution Real-time visitor tracking Meta Pixel + Conversion API (CAPI) server-side tracking Google Analytics 4 + Measurement Protocol server-side tracking WooCommerce and FluentCart automatic ecommerce tracking All form plugins (Contact Form 7, Gravity Forms, WPForms, Fluent Forms, Elementor Forms) All page builders (Elementor, Divi, Beaver Builder, Gutenberg, WPBakery, Oxygen, Bricks) Five attribution models with assisted conversion reports Consent management integration Unlimited events and sessions Pro adds advanced ad platforms and ecommerce integrations: 14+ ad platform destinations: TikTok, Pinterest, LinkedIn, Snapchat, Reddit, Google Ads, Microsoft Ads, Twitter/X, Taboola, Outbrain, and more Advanced ecommerce: Easy Digital Downloads, SureCart, Cartflow, MemberPress, LearnDash, Amelia, WooCommerce Bookings, GiveWP Cart abandonment emails, session recording, heatmaps, cohort analysis, predictive analytics Email marketing sync (Mailchimp, ActiveCampaign, Klaviyo) White label for agencies Priority support with 24-hour response time Compare Plans Integrations eCommerce: WooCommerce, FluentCart, Easy Digital Downloads (Pro), SureCart (Pro), Cartflow (Pro), MemberPress (Pro) Forms: Contact Form 7, Gravity Forms, WPForms, Fluent Forms, Elementor Forms Builders: Elementor, Divi, Beaver Builder, Gutenberg, WPBakery, Oxygen, Bricks Ad Platforms: Meta (Facebook/Instagram), Google Analytics 4, Google Ads (Pro), TikTok (Pro), Pinterest (Pro), LinkedIn (Pro), Snapchat (Pro), Microsoft Ads (Pro), Reddit (Pro), Twitter/X (Pro), Taboola (Pro), Outbrain (Pro) Consent: Cookiebot, CookieYes, OneTrust, and custom consent filters Getting Started Install and activate TrackSure Cloud from the WordPress plugin directory Visit TrackSure → Settings to review tracking and privacy options (Optional) Add your Meta Pixel ID + Access Token or GA4 Measurement ID for server-side conversion tracking Go to TrackSure → Overview — analytics data starts appearing after 1 hour External services This plugin connects to external third-party services to provide its functionality. Below is a complete list of all external services used, when they are called, what data is transmitted, and links to their terms of service and privacy policies. When You Enable Meta Pixel / Conversion API: Service: Meta (Facebook) Graph API Purpose: Send conversion events (purchases, add-to-cart, page views) to Facebook for ad optimization What data is sent: Event name, timestamp, hashed user email/phone (if available), product SKU, revenue, IP address, user agent, pixel ID When it’s sent: Automatically when a tracked event occurs (product view, purchase, etc.) and Meta destination is enabled in settings Service provider: Meta Platforms, Inc. Terms of Service: https://www.facebook.com/legal/terms Privacy Policy: https://www.facebook.com/privacy/policy Data Processing Agreement: https://www.facebook.com/legal/terms/dataprocessing When You Enable Google Analytics 4: Service: Google Analytics 4 Measurement Protocol Purpose: Send analytics events to Google Analytics for website traffic analysis What data is sent: Event name, page URL, referrer, session ID, client ID, IP address, user agent, device information When it’s sent: Automatically when page views or custom events occur and GA4 destination is enabled in settings Service provider: Google LLC Terms of Service: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy Policy: https://policies.google.com/privacy When Loading Google Tag Manager Script (If Enabled): Service: Google Tag Manager CDN Purpose: Load gtag.js library for browser-side Google Analytics tracking What data is sent: Standard HTTP request data (IP address, user agent, referrer) when loading the script When it’s sent: On every page load when GA4 browser tracking is enabled Service provider: Google LLC Script URL: https://www.googletagmanager.com/gtag/js Terms of Service: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy Policy: https://policies.google.com/privacy When Loading Facebook Pixel Script (If Enabled): Service: Facebook Connect CDN Purpose: Load fbevents.js library for browser-side Facebook Pixel tracking What data is sent: Standard HTTP request data (IP address, user agent, referrer) when loading the script When it’s sent: On every page load when Meta Pixel browser tracking is enabled Service provider: Meta Platforms, Inc. Script URL: https://connect.facebook.net/en_US/fbevents.js Terms of Service: https://www.facebook.com/legal/terms Privacy Policy: https://www.facebook.com/privacy/policy Cloudflare IP Detection (Always Active): Service: Cloudflare IP Ranges API Purpose: Fetch current list of Cloudflare proxy IP addresses to accurately detect real visitor IPs behind Cloudflare CDN. A bundled static list is included as fallback. What data is sent: Standard HTTP request headers only (no user data transmitted) When it’s sent: Once per day (cached for 24 hours) to refresh the Cloudflare IP list. The plugin includes a bundled fallback list and works without this request. Service provider: Cloudflare, Inc. API URLs: https://www.cloudflare.com/ips-v4 and https://www.cloudflare.com/ips-v6 Terms of Service: https://www.cloudflare.com/website-terms/ Privacy Policy: https://www.cloudflare.com/privacypolicy/ IP Geolocation (When Tracking Is Enabled): Service: ipapi.co (primary), ip-api.com (secondary fallback), WordPress.com Geo API (tertiary fallback) Purpose: Determine the country, region, and city of visitors based on their IP address for geographic analytics reporting What data is sent: The visitor’s IP address is sent to one of the geolocation providers. No other user data is transmitted. When it’s sent: When a new visitor session is recorded and the IP has not been looked up recently. Results are cached for 24 hours per IP. Service providers and policies: ipapi.co (primary) – https://ipapi.co/privacy/ and https://ipapi.co/terms/ ip-api.com (fallback) – https://ip-api.com/docs/legal WordPress.com Geo API (fallback) – https://automattic.com/privacy/ and https://wordpress.com/tos/ Local sources are tried first: if your site is behind Cloudflare, has the PHP GeoIP extension, or has a local MaxMind database, the country is read from those and no address leaves your server. Transport: ipapi.co and the WordPress.com Geo API are contacted over HTTPS. ip-api.com does not offer HTTPS on its free tier, so that fallback is contacted over plain HTTP — it is only reached if ipapi.co has already failed. Turning it off: Settings → Privacy → “Look up visitor location remotely”. Turning it off keeps the local sources above and stops any address being sent to a third party. Developers can also decide per request with the tracksure_remote_geolocation_enabled filter. Important Notes: Destinations are opt-in: TrackSure does not send anything to an advertising or analytics platform — Meta, Google Analytics, or any other destination — unless you enable and configure it in TrackSure Settings → Destinations. IP geolocation, described above, is the one exception: it runs while tracking is enabled and is not tied to any destination. Consent-aware: If you use a cookie consent plugin (Cookiebot, CookieYes, etc.), TrackSure will respect user consent choices and only fire pixels after consent is granted. First-party analytics: TrackSure’s core analytics features store all data in your WordPress database. Nothing is sent to an analytics platform unless you enable Google Analytics 4 or another destination. The one external call made without a destination being enabled is the IP geolocation lookup described above, which can be switched off in Settings → Privacy. You control the data: You choose which platforms to enable, what events to track, and what user data to include (emails, phones, etc.). For more information about data privacy and compliance, see the Privacy & GDPR Compliance section below. Source Code & Build Instructions The admin interface is built with React 18 and TypeScript, compiled with Webpack 5. The compiled files in admin/dist/ are generated from the source code in admin/src/. Full source code is available on GitHub: https://github.com/tracksure-cloud/tracksure To build from source: Navigate to the admin/ directory Run npm install to install dependencies Run npm run build for a production build, or npm run dev for development mode with watch Build tools used: Node.js (v18+) npm Webpack 5 (config: admin/webpack.config.js) TypeScript 5 (config: admin/tsconfig.json) ts-loader for TypeScript compilation Key source directories: admin/src/ — React/TypeScript source code (pages, components, contexts, hooks) admin/dist/ — Compiled production JavaScript (generated by Webpack) assets/js/ — Frontend tracking scripts (non-compiled, human-readable) includes/ — PHP backend (non-compiled, human-readable) Privacy Policy TrackSure stores the following data in your WordPress database: Tracking Data (90-day retention): – Page URLs visited – Referrer URLs – UTM campaign parameters – Device type (desktop/mobile/tablet) – Browser and OS information (user agent) – IP address (can be anonymized) – Session duration and engagement metrics For E-commerce (if using WooCommerce/FluentCart/EDD/SureCart): – Product views – Cart actions – Order completion (order ID, total, items) – Customer email and phone (hashed when sent to Meta/GA4) External Data Sharing (Optional): TrackSure stores all analytics data locally in your WordPress database. No data is sent to an ad platform or analytics service unless you enable that integration. The one exception is the IP geolocation lookup used for geographic reporting, described under “External services” above — it is not tied to any integration, and it can be switched off in Settings → Privacy. Privacy Controls: – IP Anonymization: Available in Settings → Privacy. Default is off for accurate geo reporting; enable it for GDPR compliance. – Cookieless Mode: Uses localStorage instead of cookies to avoid cookie consent requirements. – Consent Integration: Respects Cookiebot, CookieYes, OneTrust, and custom consent filters. Supported Third-Party Services: TrackSure connects to the following services only when you enable them and provide API credentials. 1. Meta (Facebook/Instagram) – Available in Free & Pro – Method: Server-to-Server via Meta Graph API (CAPI) – Data Sent: Event data (PageView, ViewContent, AddToCart, Checkout, Purchase), Hashed user data (email, phone, IP, User Agent) – Purpose: Ad optimization and attribution 2. Google Analytics 4 (GA4) – Available in Free & Pro – Method: Server-to-Server via Measurement Protocol – Data Sent: Event parameters, Client ID, User Agent, IP – Purpose: Analytics reporting 3. Pro-Only Integrations (Add-ons) – Google Ads: Sends offline conversion adjustments via Google Ads API. – TikTok: Sends web events via TikTok Events API. – Pinterest: Sends conversion events via Pinterest API. – Snapchat: Sends conversion events via Snapchat Conversions API. – Microsoft Ads: Sends offline conversions via Microsoft Ads API. – LinkedIn: Sends conversion events via LinkedIn CAPI. You must obtain user consent before enabling these destinations (GDPR/CCPA requirement). Your Responsibilities: Disclose TrackSure’s tracking in your privacy policy Obtain consent before tracking (if required by law) Configure data retention periods appropriately Enable IP anonymization if required Data Deletion: Users can request data deletion via WordPress Privacy Tools or TrackSure Settings → Privacy. Support Free Support: Documentation [Community …