Five diagnostics, five distinct root causes.
Projects delivered via digital marketing agencies, with the end client anonymized for confidentiality. The technical work is 100% real.
Personal data leak in server-side tracking
Legal risk / GDPRThe server-side container was sending email, name, country, and zip code to Meta CAPI, TikTok Events API, and Google Ads even when ad consent had been denied.
Consent Mode v2 audit across 154 tags: 128 had missing or misconfigured gates, plus a race condition in the CMP marking consent as granted before user interaction.
ad_storage and ad_user_data gates implemented on the 15 affected server-side tags, blocking publication until the gap was fully closed.
Complete elimination of PII sent outside of consent before going live. A legal risk fix under GDPR, not a tracking tweak.
GTM container migration at scale
Scaled architectureData discrepancies between properties after migrating GA4 e-commerce events from one container to another.
Audit of 21 tags, 64 triggers, and 177 variables: three data-exclusion causes running in parallel (a global toggle variable, a 35-ID regex blacklist, and an independent blocked-sites table).
Validated export with recursive dependency resolution and cleanup of legacy Universal Analytics tags.
Container reduced from 177 to 102 variables and 21 to 7 tags, with zero broken references. Architecture built to scale to thousands of client containers.
Multi-layer forensic diagnosis: DV360/Floodlight
Forensic diagnosisFloodlight recording zero visits despite confirmed site traffic.
Four simultaneous causes: a Floodlight snippet hardcoded in the HTML duplicating the GTM-fired tag, undefined consent, missing tag sequencing, and a second GTM container of unknown origin.
Universal Pixel implemented as the setup tag, consent requirements added, tags renamed to reflect their actual scope.
Validated in Preview and published. A diagnosis with several simultaneous causes, not one.
E-commerce dataLayer audit
Before / AfterEvery GA4 e-commerce event failing in staging, before going live.
Incomplete item schema, incorrect variants in add_to_cart, purchase blocked by the external checkout architecture.
Event-by-event implementation guide with exact specs for the dev team and a standardized naming convention.
From total failure to full validation. The clearest before/after case to visualize.
Reconciling a Google Ads vs. GA4 discrepancy via BigQuery
BigQuery / SQLGoogle Ads reported ~34% more purchase conversions than GA4 for the same period and channel, with no clue as to why in the dashboard.
Dropped to the raw event table in BigQuery: purchase duplication by transaction_id, lost attribution from uncaptured gclid, and a structural consent gap.
Each cause isolated and quantified separately: ~8% duplication, ~19% lost attribution, ~7% consent.
A defensible breakdown of the 34% gap, with three distinct owners and fixes, plus the honest caveat that the gap never hits zero by design of both platforms.
Dimensional GA4-in-BigQuery model built with dbt
dbt / BigQueryThe native GA4-to-BigQuery export isn’t an analytical table, it’s a nested event log: every query re-writes the same UNNEST and carries the risk of double-counting purchases.
On the public Google Merchandise Store dataset (4.3M events): session isn’t a column, purchase duplicates, and attribution arrives in two scopes that can’t be collapsed without losing information.
Four dbt models across two layers: staging flattens and types the event; the marts expose sessions, deduplicated purchases, and users. 25 quality tests and CI on GitHub Actions.
360,129 sessions and 270,154 users modeled, 4,451 deduplicated purchases, 25/25 tests passing locally and in CI, documentation with a navigable lineage graph published on GitHub Pages.
A layered GEO/AEO measurement framework, self-applied
GEO/AEOAI answer engines (ChatGPT, Perplexity, Google AI Overviews) are capturing a growing share of informational searches, and no standard measurement tool natively tells you whether your content is cited there, or how much traffic arrives from it.
The problem breaks down into independent signals no single metric solves: technical visibility to crawlers, measurable referred traffic, real bot crawling, and cross-referencing both signals.
A 5-layer framework on this very site: technical foundation, referred traffic in GA4, bot crawling, cross-referencing both signals in BigQuery, and real citation testing in answer engines.
All 5 layers verified in production. The traffic cross-reference doesn’t find overlap yet, expected at this volume, and the citation test comes back at 0% across 80 real checks: the brand doesn’t show up in AI answer engines yet.
A self-hosted tagging server on Cloud Run, no Stape
Server-side taggingThe site measured everything client-side: with no server-side layer, GA4 hits were exposed to blockers, ITP, and third-party cookies, and there was no way to prove the skill without a client asking for it first.
Two paths: pay for an intermediary SaaS like Stape, or deploy the server-side container directly on the same Google Cloud account already running the GEO/AEO pillar.
A server-type GTM container on Cloud Run with a custom domain, managed certificate, and scale-to-zero. A CSP bug silently blocking the connection, found and fixed already in production.
Real traffic confirmed end to end, from the browser through sgtm.cristhianvelasquez.com to GA4, verified in Cloud Run logs and in GA4 realtime.