What Your Tags Actually Collect

Tag Management / Reference

What Marketing Tags Actually Collect: The Common Tags on Your Site and the Data They Share

Summary

Marketing and analytics tags are small scripts that track what visitors do on your site and send that data to third parties like ad platforms and analytics tools. Depending on the tag and its setup, that data can include IP address, device and browser details, pages viewed, and hashed personal data such as email addresses.

Start with the notes on how to read this page, then the reference table, which compares the common tags side by side. After that come what changes with and without consent, and a closer look at each tag in turn.

How to read this page

Each tag on a website is there for a reason, usually analytics or advertising, and each one usually sends data to another company. This page is a plain reference for what that data actually is, tag by tag.

Two things are worth saying up front. First, a tag collecting data is not the same as a tag breaking the law. What a tag is allowed to collect, and when, depends on your consent setup and the privacy laws that apply to you. This page describes what tags collect. For whether a given setup is compliant, see our privacy and compliance resources.

Second, the same tag can behave very differently on two different sites. Much of what a tag collects depends on whether it fires before or after a visitor consents, and on options like advanced matching that send hashed personal data when they are turned on. Where that is true, we say so.

Every claim on this page is sourced to the tag vendor’s own documentation. Where a specific behavior has come up in litigation, we link to the case record rather than describe it here.

Reference / 12 tags

The reference table

“Fires before consent?” means whether the tag, as commonly installed, can load and send data before a visitor has consented. This depends on your consent setup, which is exactly why it is worth auditing.

Tap a tag to open its card with the full detail.

Showing 12 of 12 tags

Common marketing tags, what each collects, where the data goes, whether it can fire before consent, and how DataTrue detects it. Column headers sort the table.
What it collects (in brief)DataTrue detects as
Meta PixelAdvertisingPrivacy profile HTTP header data (which may include IP address and browser), page URL and referrer, button clicks and their labels, form field names, the Pixel ID and Meta cookie, and (with Advanced Matching on) hashed email, phone, name, location, and more Meta (Facebook/Instagram) Facebook Pageview Impression Connect
TikTok PixelAdvertisingPrivacy profile IP address (for geolocation), user agent (device, OS, browser), timestamps, page metadata and button clicks, ad/event data, cookies, and (with Advanced Matching) hashed email and phone TikTok TikTok
Google Analytics (GA4)AnalyticsPrivacy profile Device and browser data, geographic data derived from IP, on-site activity/events, and first-party cookies. IP addresses are used but not logged or stored Google Google Analytics - GA4
Google AdsAdvertisingPrivacy profile Click identifier (GCLID), and first-party cookies with a user/click ID for conversion and remarketing, plus (with Enhanced Conversions, set at account level) hashed customer data such as email Google Google Ads Conversion Remarketing Measurement
LinkedIn Insight TagAdvertisingPrivacy profile IP address, browser/device characteristics, page URL, referrer, timestamp, and a first-party ad tracking cookie (li_fat_id), plus (with enhanced matching) hashed email. Links to your LinkedIn profile when you are logged in LinkedIn (Microsoft) Linkedin Analytics
Google Tag ManagerTag container Little on its own (no IP or per-user IDs retained per Google). It loads and fires the other tags, which each collect their own data Google (minimal), plus other vendors via the tags it loads Google Tag Manager
Microsoft (Bing) UETAdvertising Page views and conversion events, and cookies including MUID, _uetvid and _uetsid, plus (with enhanced conversions on for a goal) hashed email or phone Microsoft Microsoft Bing
HotjarSession replay / analytics Clicks, mouse movement, scrolling, page content, and device/browser. Keystrokes and input fields are suppressed client-side by default, and no IP is stored at rest (a UUID is used) Hotjar (Contentsquare) Hotjar
FullstorySession replay / analytics User interactions, DOM structure, page changes, and form submissions. When Private by Default is on (standard for newer accounts), no text leaves the browser unless allowlisted, and images cannot be masked on web sessions Fullstory FullStory
Pinterest TagAdvertising Standard conversion events and site activity, and (with Enhanced Match) a browser-hashed email sent to match visitors to Pinterest accounts, plus cross-device conversions Pinterest Pinterest Analytics Conversion
Snap PixelAdvertising Events (page view, view content, add to cart, purchase, etc.), plus hashed email and phone, passed by the site or picked up from forms by Automated Matching when that toggle is on Snap Snapchat
Criteo OneTagAdvertising / retargeting Product views, add-to-cart actions, purchases, and site activity, plus hashed email and cross-device and cross-site identifiers via cookies Criteo Criteo

No tags match.

Underlined hashed personal data (with advanced matching or enhanced conversions)

Note on “unless gated”: whether any of these fire before consent is set by your consent management platform and tag configuration, not by the tag itself. A tag that is supposed to wait for consent can still fire early if it is misconfigured. Confirming which of your tags fire before consent, and what they send when they do, is what a consent-aware tag audit checks.

Tag cards / swipe or use the arrows

The tags, one by one

Each entry below expands its row. Sources are the tag vendor’s own documentation unless noted. The five profiled tags (Meta, TikTok, GA4, Google Ads, LinkedIn) link to their full privacy profile.

1 / 12

Swipe for the next tag

Advertising01/12

Meta Pixel

Sends to Meta (Facebook/Instagram)

What it collects

HTTP header data (which may include IP address and browser), page URL and referrer, button clicks and their labels, form field names, the Pixel ID and Meta cookie, and (with Advanced Matching on) hashed email, phone, name, location, and more

Before consent?

Yes, unless gated

DataTrue detects as

Facebook Pageview Impression Connect

Read the full entry

Meta’s advertising and conversion-tracking tag for Facebook and Instagram. On page load and on events it sends data in standard HTTP headers, which may include the visitor’s IP address and browser information, plus page location, document, and referrer. It collects the Pixel ID and the Meta cookie, it tracks buttons clicked, their labels, and pages visited as a result, and it sends form field names, such as email or address. With Advanced Matching on, it also sends customer data the site holds, hashed with SHA-256: email, phone, first and last name, city, state, zip, country, date of birth, gender, and an external ID.

Sources: Meta Pixel overview and Advanced matching, developers.facebook.com.

Privacy riskHighFull profile
Advertising02/12

TikTok Pixel

Sends to TikTok

What it collects

IP address (for geolocation), user agent (device, OS, browser), timestamps, page metadata and button clicks, ad/event data, cookies, and (with Advanced Matching) hashed email and phone

Before consent?

Yes (third-party cookies on by default)

DataTrue detects as

TikTok

Read the full entry

TikTok’s advertising tag. Per TikTok it gathers the IP address (for geolocation), the user agent (device make, model, OS, browser), timestamps, ad and event information, and descriptive page metadata, structured microdata, page performance data, and button clicks. First-party cookies are optional, but third-party cookies are on by default. Advanced Matching adds hashed email and phone.

Sources: About TikTok Pixel and Advanced Matching for Web, ads.tiktok.com.

Privacy riskHighFull profile
Analytics03/12

Google Analytics (GA4)

Sends to Google

What it collects

Device and browser data, geographic data derived from IP, on-site activity/events, and first-party cookies. IP addresses are used but not logged or stored

Before consent?

Yes, unless gated (Consent Mode)

DataTrue detects as

Google Analytics - GA4

Read the full entry

Google’s analytics platform. It collects device and browser data, geographic data, and on-site activity, and it mainly uses first-party cookies. Google states it does not log or store IP addresses, though the IP is used in transit to derive coarse location. On apps it uses an app-instance identifier.

Source: Safeguarding your data (GA4), support.google.com/analytics.

Privacy riskMediumFull profile
Advertising04/12

Google Ads

Sends to Google

What it collects

Click identifier (GCLID), and first-party cookies with a user/click ID for conversion and remarketing, plus (with Enhanced Conversions, set at account level) hashed customer data such as email

Before consent?

Yes, unless gated (Consent Mode)

DataTrue detects as

Google Ads Conversion Remarketing Measurement

Read the full entry

Google’s conversion-tracking and remarketing tags. They store cookies with a unique identifier for the user or the ad click (the GCLID, Google Click Identifier). When a visitor converts, the tag reads this and sends it to Google Ads with the conversion. Enhanced conversions add hashed customer data such as email. The setting is made at the account level, and new conversion actions inherit it. Sources: How Google Ads tracks website conversions and About enhanced conversions, support.google.com/google-ads. Full profile: /en/resources/tags/profiles/google-ads/.

Sources: How Google Ads tracks website conversions and About enhanced conversions, support.google.com/google-ads.

Privacy riskHighFull profile
Advertising05/12

LinkedIn Insight Tag

Sends to LinkedIn (Microsoft)

What it collects

IP address, browser/device characteristics, page URL, referrer, timestamp, and a first-party ad tracking cookie (li_fat_id), plus (with enhanced matching) hashed email. Links to your LinkedIn profile when you are logged in

Before consent?

Yes, unless gated

DataTrue detects as

Linkedin Analytics

Read the full entry

LinkedIn’s B2B advertising tag. Per LinkedIn, for every page load it collects the visitor’s IP address, browser and device characteristics, page URL, referrer, and a timestamp, LinkedIn truncates or hashes the IP addresses. When a visitor is logged in to LinkedIn, the data can be connected to their profile. Its cookies include li_fat_id, a first-party cookie that is on by default for new tags, and UserMatchHistory and li_sugr, which LinkedIn sets on its own domains. With enhanced matching on, it also sends email addresses hashed on your site.

Source: LinkedIn Insight Tag FAQs, linkedin.com/help.

Privacy riskMediumFull profile
Tag container06/12

Google Tag Manager

Sends to Google (minimal), plus other vendors via the tags it loads

What it collects

Little on its own (no IP or per-user IDs retained per Google). It loads and fires the other tags, which each collect their own data

Before consent?

Loads early, often before consent unless gated

DataTrue detects as

Google Tag Manager

Read the full entry

A tag container rather than a tracking tag. Google states GTM does not collect, retain, or share information about visitors beyond aggregated tag-firing data that excludes IP and per-user identifiers, plus standard HTTP logs deleted within 14 days. The privacy question with GTM is what it deploys: the tags it fires each collect their own data, and GTM often loads early, so it can fire them before consent unless gated.

Source: Data privacy and security, support.google.com/tagmanager.

Advertising07/12

Microsoft (Bing) UET

Sends to Microsoft

What it collects

Page views and conversion events, and cookies including MUID, _uetvid and _uetsid, plus (with enhanced conversions on for a goal) hashed email or phone

Before consent?

Yes, unless gated

DataTrue detects as

Microsoft Bing

Read the full entry

Microsoft Advertising’s Universal Event Tracking tag. It tracks on-site events, such as page views, leads and purchases, and uses cookies including MUID, _uetvid and _uetsid. With enhanced conversions turned on for a conversion goal, it sends email or phone hashed with SHA-256.

Sources: Microsoft Advertising FAQ: UET and user consent, and Enhanced conversions, learn.microsoft.com/advertising.

Session replay / analytics08/12

Hotjar

Sends to Hotjar (Contentsquare)

What it collects

Clicks, mouse movement, scrolling, page content, and device/browser. Keystrokes and input fields are suppressed client-side by default, and no IP is stored at rest (a UUID is used)

Before consent?

Yes, unless gated

DataTrue detects as

Hotjar

Read the full entry

A session-replay and behavior tool. It captures clicks, mouse movement, scrolling, page content, and device/browser information. Hotjar automatically suppresses keystroke data on all input fields client-side, so it never reaches their servers, and by default it does not store IP addresses at rest, using a generated UUID instead. What it captures depends on your suppression settings.

Source: Data Safety, Privacy & Security, help.hotjar.com.

Session replay / analytics09/12

Fullstory

Sends to Fullstory

What it collects

User interactions, DOM structure, page changes, and form submissions. When Private by Default is on (standard for newer accounts), no text leaves the browser unless allowlisted, and images cannot be masked on web sessions

Before consent?

Yes, unless gated

DataTrue detects as

FullStory

Read the full entry

A session-replay and experience-analytics tool. It captures user interactions, the DOM structure of pages, and how visitors move through the site and submit forms. When Private by Default is on (standard for newer accounts, and on request for older ones), no text is captured or sent outside the browser unless explicitly allowlisted, and form inputs are masked. One documented limit: images cannot be masked on web sessions, so sensitive information shown in an image can be captured unless the element is excluded.

Source: Fullstory Private by Default, help.fullstory.com.

Advertising10/12

Pinterest Tag

Sends to Pinterest

What it collects

Standard conversion events and site activity, and (with Enhanced Match) a browser-hashed email sent to match visitors to Pinterest accounts, plus cross-device conversions

Before consent?

Yes, unless gated

DataTrue detects as

Pinterest Analytics Conversion

Read the full entry

Pinterest’s conversion-tracking tag. It tracks standard conversion events and site activity. With Enhanced Match it sends a hashed email address to Pinterest, hashed with SHA-256 in the browser, to match site events when no Pinterest cookie is present, and supports cross-device conversions.

Source: Enable enhanced match, help.pinterest.com.

Advertising11/12

Snap Pixel

Sends to Snap

What it collects

Events (page view, view content, add to cart, purchase, etc.), plus hashed email and phone, passed by the site or picked up from forms by Automated Matching when that toggle is on

Before consent?

Yes, unless gated

DataTrue detects as

Snapchat

Read the full entry

Snapchat’s advertising tag. It tracks standard events (page view, view content, add to cart, start checkout, purchase, and more). It can also send hashed email and phone, either passed by the site or picked up from forms by Snap’s Automated Matching when that toggle is on. Snap’s terms prohibit configuring the pixel to send health-related or other sensitive information.

Source: Snap Pixel FAQs, businesshelp.snapchat.com.

Advertising / retargeting12/12

Criteo OneTag

Sends to Criteo

What it collects

Product views, add-to-cart actions, purchases, and site activity, plus hashed email and cross-device and cross-site identifiers via cookies

Before consent?

Yes, unless gated

DataTrue detects as

Criteo

Read the full entry

Criteo’s retargeting tag. It captures product views, add-to-cart actions, purchases, and site activity, and sends them to Criteo. It supports hashed email collection and cross-device tracking, and uses cookies for audience segmentation and ad delivery.

Sources: Introduction to the Criteo OneTag, help.criteo.com. Criteo privacy, criteo.com/privacy.

How to see what your own tags collect

A reference tells you what these tags can collect. It cannot tell you what yours are doing right now, on your site, in each consent state. That is a question about your own pages, and it changes every time a tag is added or a container is edited.

A DataTrue journey test reading what a GA4 page view sent: the event name, page name and measurement ID each pass their checks.

DataTrue answers it by testing your live site and apps continuously, and alerting when it changes. Coverage tests crawl your whole site and report what is tagged on every page. Simulation tests walk a defined journey, like a checkout, step by step and in each consent state, and read the actual data payload each tag sends at each step. Sensitive Data Detection flags when a tag is sending personal data it should not. You can also test changes before they go live, against draft GTM Preview and Adobe Tags containers.

How DataTrue does it

See how DataTrue detects what your tags collect

Web analytics testing

Questions

What data do marketing tags collect?

It depends on the tag, but commonly: IP address, device and browser details, the pages a visitor views, and their actions on the site. Advertising tags often also send hashed personal data such as email addresses when advanced matching or enhanced conversions are turned on. Each tag sends its data to the company that provides it, like Meta, Google, or TikTok.

Do tags collect data before a visitor consents?

They can. Many tags fire as soon as a page loads, which is before a visitor has made a consent choice, unless your consent setup blocks them until then. Whether your tags wait for consent depends on your configuration, which is why it is worth checking rather than assuming.

What is advanced matching (or enhanced conversions)?

It is an option on many advertising tags that sends hashed personal data, usually email and phone, to improve how well the platform matches a visitor to a known account. The data is hashed, but it is still personal data being sent to a third party, so it matters whether it is sent with consent.

What is the difference between what a tag collects and whether it is legal?

This page covers what tags collect. Whether collecting that data is compliant depends on the law that applies to you and how your site is configured. For the compliance question, see our privacy and compliance resources.

How do I find out what tags are on my own site and what they send?

Run a tag audit that inspects the data payload and tests each consent state, or monitor your site continuously so you are alerted when a tag changes. See our tag audit guide.

Sources

  1. Meta Pixel overview: developers.facebook.com/docs/meta-pixel
  2. Meta Pixel, Advanced matching: developers.facebook.com/documentation/meta-pixel/advanced/advanced-matching
  3. About TikTok Pixel: ads.tiktok.com/help/article/tiktok-pixel
  4. TikTok, Advanced Matching for Web: ads.tiktok.com/help/article/best-practices-for-advanced-matching-for-web
  5. GA4, Safeguarding your data: support.google.com/analytics/answer/6004245
  6. Google Ads, How Google Ads tracks website conversions: support.google.com/google-ads/answer/7521212
  7. Google Ads, About enhanced conversions: support.google.com/google-ads/answer/9888656
  8. LinkedIn Insight Tag FAQs: linkedin.com/help/lms/answer/a427660
  9. Google Tag Manager, Data privacy and security: support.google.com/tagmanager/answer/9323295
  10. Microsoft Advertising, Universal Event Tracking: learn.microsoft.com/en-us/advertising/guides/universal-event-tracking?view=bingads-13 (base UET behavior, events, and remarketing). Cookie names: Microsoft Advertising, FAQ: UET and user consent: learn.microsoft.com/en-us/advertising/msa-help/hlp_ba_conc_uet_consentfaq
  11. Microsoft Advertising, Enhanced conversions: learn.microsoft.com/en-us/advertising/msa-help/hlp_ba_conc_uet_enhancedconversions
  12. Hotjar, Data Safety, Privacy & Security: help.hotjar.com/hc/en-us/articles/36819972898193-Data-Safety-Privacy-Security
  13. Fullstory, Private by Default: help.fullstory.com/hc/en-us/articles/360044349073-Fullstory-Private-by-Default
  14. Pinterest, Enable enhanced match: help.pinterest.com/en/business/article/enhanced-match
  15. Snap Pixel FAQs: businesshelp.snapchat.com/s/article/pixel-faqs
  16. Criteo OneTag introduction: help.criteo.com/kb/guide/en/introduction-to-the-criteo-onetag-8fjCDwCENw . Criteo privacy: criteo.com/privacy
30-day free trial

Know what your tags send, page by page

DataTrue runs real journeys on your site and checks each tag’s data against what you expect, field by field. A missing event or a wrong value shows up in a test before it reaches a report.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue journey step reading what a GA4 page view sent, with each property checked
A journey step checking what a GA4 tag sent