What we measure
Tag Monitor watches whether the tags in your Google Tag Manager containers still do what they should. This page says exactly what is recorded for that, where it is kept, for how long, and who handles it.
What we record
For every measured event we record technical facts about your tag setup: which tag ran, whether Tag Manager reports it finished successfully, how long it took, the event name, your container version and the state of your consent at that moment. Consent is four separate signals: whether analytics storage and advertising storage were allowed, and whether your data may be used for advertising and for ad personalisation. We record each one as a yes or a no. On server-side containers Tag Manager passes on only the first two, so that is all we have there.
On server-side containers we also check whether the fields a conversion needs are there. We record the names of the fields that are missing and the names of the ones that were present, never what is in them. Both lists come from a fixed list written into the template, which your Tag Manager admin can read before publishing it. Recording what was present matters more than it sounds: the same customer data can be sent under several different field names, and a check that knows only one of them reports a field as absent when it is sitting right there. Knowing which names did arrive is what stops us telling you something is broken when it is not.
When a tag runs we also check whether a fixed list of known identifier cookies (such as _ga and _fbp) exists at that moment. We record only the name of the cookies that are present, never the contents: that a cookie exists is not personal data, the value in it is. The value is never sent and does not leave the page (for three cookies the tag looks at it inside the page to work out its age; see below). The answer this gives is, for example, “this tag ran without _fbp”, which explains why a platform matches fewer conversions.
For three of those cookies (_ga, _fbp and _gcl_au) the value contains the date the cookie was created. The tag works out, inside the page, roughly how old the cookie is and sends only a band: less than a day, up to a week, up to a month, or older. The value itself and the exact date never leave the page. Alongside that band we record the browser family the measurement came from (for example Safari, Chrome or iOS), taken from the browser's own request and never stored in full. Together these show whether a browser deletes your identifiers early: Safari and every browser on iOS shorten cookies set by scripts to 7 days, which makes returning visitors look new.
We only look at a cookie when the consent that governs it has been given. Article 5(3) of the ePrivacy Directive covers gaining ACCESS to information on your device, not only the storing of personal data, so “the name is not personal data” is not the test that applies. Separately, at the moment you give consent we record which of those cookies were already there. That is the first moment we are allowed to look, and it answers whether something was written before permission existed. There too it is only the name, never the contents, and only the fixed list above. Nothing is written; the tag only looks at whether something is already there. The list is fixed in the template, which asks Tag Manager for permission to read exactly those names and nothing else, so your GTM admin can see the full list before publishing.
If you separately opt in, we also record the amount and currency of conversion events. That is business information, not personal data: it is not tied to a visitor, order or customer, and it lets us say what an outage cost you instead of how many attempts failed. This option is off by default.
If you want alert mails sent to people at your company, we store their email addresses and use them only to send those alerts. Nothing else is sent to them, and we remove the addresses when you ask or when the site is offboarded.
We also record the hostname the event came from, for example www.your-shop.nl. The host only: the path and anything after it are cut inside your own container and never sent, because the path is where personal data would be. An order confirmation carries an order number in its address and a search page carries what somebody typed, and neither ever leaves your container. We keep the host because one container often serves several of your sites and without it every measurement looks the same, and because it is how we notice a container running somewhere it should not be.
What we do not record
No personal data about your visitors. No names, email addresses or IP addresses, no cookie contents, no user IDs, no page addresses beyond the bare hostname above, no order data, no order IDs and no contents of the events themselves. The measurements cannot be traced back to a visitor and we cannot build profiles from them. To keep the load low we measure only a share of the traffic.
Where it is kept and for how long
Measurements arrive at monitor.newnorth.nl and are stored in BigQuery in a Google Cloud project owned by New North Digital, with the EU as the storage location. Measurements are kept for at most 400 days and then deleted automatically. The text of the reports we write for you is kept until your site is offboarded. Only New North Digital staff have access to the data; the report you get from us is yours to share through a link that expires after a while.
Who processes the data
Three providers are involved in delivering the service:
- Vercel (US company): hosts the application and the endpoint that receives the measurements. Compute runs in Frankfurt (EU).
- Google Cloud BigQuery (EU multi-region): stores the measurements, the site registry and the reports.
- Resend (US company): sends the alert mails.
Who is responsible for what
This monitoring is our own service: New North Digital decides what is measured and why, and is the controller for these technical data. The measurements themselves contain no personal data about your visitors; the only personal data we hold are the email addresses of the people you want alerted. We sign a data processing agreement on request. If you want us to stop measuring or to delete the data, we do that, and deleting removes everything ever measured for your site.