# Shopware server-side tracking plugin

> The Shopware 6 plugin that sends your conversions to Meta, GA4 and Google Ads from the server. One single key, consent-aware, EU-hosted.

- Original page: https://server-side.datafirefly.com/en/shopware-server-side-tracking.html
- Language: en
- Updated: 2026-07-28
- Publisher: DataFirefly (Datafirefly Limited), https://server-side.datafirefly.com/en/

---

Shopware 6.5 / 6.6 plugin: version 1.0.0

Install the **DatafireflyServerSide** plugin on your Shopware 6 store and send the purchase conversion server-side, directly to **Meta Conversions API (CAPI), GA4, TikTok, Pinterest and Microsoft Advertising**. Per-shop HMAC signing, fail-safe by design so a tracking error never breaks checkout, and a configurable GDPR consent option. A single connection key, no pixel IDs to paste into Shopware.

[Create an account](https://admin.datafirefly.com/pricing?lang=en) How to install the plugin

Fail-safe: checkout is never interrupted Per-shop HMAC signing EU-hosted

The plugin installs like any Shopware extension: a ZIP uploaded in "My extensions" in the administration, no FTP access required.

The flow, end to end

**Your Shopware store** DatafireflyServerSide plugin: order placed event

**DataFirefly dispatcher** Hosted in Germany: HMAC-authenticated channel

Meta CAPI GA4 TikTok Pinterest Microsoft Advertising

The problem

## Your Shopware browser tags are leaking sales

The Meta pixel, GA4 tag, or TikTok tag in your Shopware theme runs in the customer's browser: where it's increasingly blocked before it even gets to fire.

- **Ad-blockers**

  stop the tags from loading on the order confirmation page: the purchase is never reported to your platforms.
- **Safari ITP**

  and similar protections shorten or remove the cookies your conversion tags depend on.
- **Cookie restrictions and consent friction**

  further reduce what browser-side tracking can capture at the moment of purchase.

The result: incomplete Shopware conversions, degraded match quality, and campaigns optimising on a partial view. You're paying for sales you can't fully measure.

The solution

## The Shopware purchase conversion, sent server-side

The **DatafireflyServerSide** plugin captures the purchase the moment the **order is placed** (`checkout.order.placed` event), server-side, and sends it **server-to-server, directly to each platform's conversion API** (CAPI): the channel built for reliable, first-party conversion data.

### Recovered purchases

The purchase conversion no longer depends on browser tags surviving ad-blockers and ITP, so you recover sales that would otherwise be lost.

### Better match quality

The plugin captures the available browser identifiers (`_fbp`, `_fbc`, `_ttp`, GA `clientId`) for a richer, more reliable match signal.

### Zero risk to checkout

Fail-safe by design: tight timeouts and full exception handling. A tracking error is logged but never interrupts the order.

How it works on Shopware

## Three steps to complete purchase tracking

1

### Install the Shopware plugin

Upload the **DatafireflyServerSide** ZIP in Extensions → My extensions → Upload extension, then activate it. Shopware registers the order event subscriber automatically.

2

### Paste your connection key

Open the plugin configuration and paste your connection key (dfss\_…) copied from "Connect your shop" in your DataFirefly account (/app). No pixel IDs to enter.

3

### The purchase goes out server-side

On every placed order, the purchase event is HMAC-signed and delivered to the dispatcher, which fans it out to all your configured destinations. One install, every platform.

What the plugin does

## The server-side connector for Shopware, in detail

### Server-side purchase conversion

Sends the purchase event when the order is placed, directly to the conversion APIs.

### HMAC-SHA256 signing

Every request is signed per shop (X-Dfss-Tenant, X-Dfss-Timestamp, X-Dfss-Signature headers). Destination credentials never touch the browser.

### Fail-safe by design

Tight HTTP timeouts and full exception handling: a tracking error never breaks checkout. Failures are logged.

### Consent gating

"Require consent" option: the purchase is only sent if the consent cookie you specify is present, name and value configurable to match your CMP, checked server-side.

### Richer match quality

Captures the available browser identifiers (\_fbp, \_fbc, \_ttp, GA clientId) alongside order and customer data.

### Built-in test event

Verify connectivity and the signature with a single console command (`bin/console datafirefly:serverside:test`), before even placing a real test order.

### One key, no exposed secrets

The connection key (dfss\_…) stays server-side. Destination tokens live in the dispatcher, never in the storefront.

### EU-hosted

The dispatcher runs in Germany: your data stays in the EU.

Destinations

## Meta CAPI, GA4, TikTok, Pinterest and Microsoft Advertising from Shopware

The Shopware purchase conversion is delivered server-side to your platforms' conversion APIs. Configure it once in your DataFirefly account.

[![Meta logo: Meta Conversions API (CAPI) server-side destination](https://server-side.datafirefly.com/assets/logos/meta.svg) Meta Conversions API CAPI](https://server-side.datafirefly.com/en/shopware-meta-capi-server-side-tracking.html) [![GA4 logo: Google Analytics 4 destination via Measurement Protocol](https://server-side.datafirefly.com/assets/logos/ga4.svg) GA4 Measurement Protocol](https://server-side.datafirefly.com/en/shopware-ga4-server-side-tracking.html) [![TikTok logo: TikTok Events API server-side destination](https://server-side.datafirefly.com/assets/logos/tiktok.svg) TikTok Events API](https://server-side.datafirefly.com/en/tiktok-events-api-server-side-tracking.html) [![Pinterest logo: Pinterest Conversions API server-side destination](https://server-side.datafirefly.com/assets/logos/pinterest.svg) Pinterest Conversions API](https://server-side.datafirefly.com/en/pinterest-conversions-api-server-side-tracking.html) [![Google Ads logo: destination via Google Ads Data Manager API](https://server-side.datafirefly.com/assets/logos/google-ads.svg) Google Ads Data Manager API](https://server-side.datafirefly.com/en/shopware-google-ads-server-side-tracking.html) [![Microsoft Advertising logo: destination via Microsoft Advertising Conversions API](https://server-side.datafirefly.com/assets/logos/microsoft-ads.svg) Microsoft Advertising Conversions API](https://server-side.datafirefly.com/en/microsoft-ads-conversions-api-server-side-tracking.html)

Google Ads (Data Manager API) is available at the platform level. The Shopware plugin 1.0.0 delivers the purchase to Meta CAPI, GA4, TikTok, Pinterest and Microsoft Advertising.

Installation

## Install the server-side plugin on Shopware

Requirements: Shopware 6.5 or 6.6, a DataFirefly server-side account, and outbound HTTPS access to serverside.datafirefly.com.

1

### Get your connection key

In "Connect your shop" in your DataFirefly account (/app), copy your **connection key** (prefixed `dfss_…`). It contains everything the plugin needs: tenant, HMAC secret and endpoint are already encapsulated, no other settings to enter.

2

### Upload the ZIP in the administration

Shopware administration → Extensions → **My extensions** → **Upload extension**, then select the plugin ZIP. Then click **Activate**. On the command line: `bin/console plugin:install --activate DatafireflyServerSide`.

3

### Configure the plugin

Open the **plugin configuration**. Paste your connection key (dfss\_…). If you use a CMP, enable **Require consent** (off by default) and specify the name and value of the consent cookie to check. Switch **tracking** to enabled, then save.

4

### Verify the connection

Run `bin/console datafirefly:serverside:test`: a success message confirms the key and signature are valid. Then place a real test order and open the **Inspector** in /app to confirm the purchase event arrives (value, currency, reference).

Delivery errors are logged in the Shopware logs (entries prefixed `[DataFirefly SS]`). A tracking failure is logged but never interrupts the order.

Pricing

## Simple pricing that scales with your store

One subscription covers your whole account: all of its Shopware stores: on a single consolidated invoice. Move up a tier for more sites and more monthly events.

### Free

Free while you stay under the monthly allowance: nothing breaks if you go over.

€0 / month

**1** site included

Up to **10,000** events / month

No credit card required

[Start free](https://server-side.datafirefly.com/en/free.html)

### Starter

For a single Shopware store getting server-side tracking in place.

**€39** / month (Monthly) · **€32** / month (Yearly 2 months free)

Billed €390 per year: 12 months commitment, no pro-rata refund.

**1** site included

Up to **500K** events / month

One consolidated invoice

[Choose Starter](https://admin.datafirefly.com/pricing?lang=en&plan=starter)

Most popular

### Growth

For merchants and small agencies running up to five stores.

**€119** / month (Monthly) · **€99** / month (Yearly 2 months free)

Billed €1 190 per year: 12 months commitment, no pro-rata refund.

**5** sites included

Up to **2M** events / month

One consolidated invoice

[Choose Growth](https://admin.datafirefly.com/pricing?lang=en&plan=growth)

### Scale

For agencies and portfolios managing up to twenty stores at higher volume.

**€349** / month (Monthly) · **€290** / month (Yearly 2 months free)

Billed €3 490 per year: 12 months commitment, no pro-rata refund.

**20** sites included

Up to **10M** events / month

One consolidated invoice

[Choose Scale](https://admin.datafirefly.com/pricing?lang=en&plan=scale)

The Shopware plugin is included in every plan. See the [full pricing on the homepage](https://server-side.datafirefly.com/en/#pricing).

Trust & GDPR

## Built for European privacy standards

**EU-hosted (Germany)**

Your data is processed in the EU.

**HMAC-authenticated ingestion**

Every purchase request is signed per shop (HMAC-SHA256).

**Consent-aware**

With "Require consent", the purchase is only sent if the configured consent cookie is present: checked server-side.

**Credentials never exposed**

Destination tokens stay on the dispatcher side, never in the browser.

**A single connection key**

The dfss\_… key encapsulates everything: no destination token ever lives in the store.

**99.5% availability target**

Measured and tracked in real time on our [public status page](https://serverside.datafirefly.com/status), in line with our SLA.

FAQ

## Frequently asked questions: Shopware plugin

### What is the server-side tracking plugin for Shopware?

The **DatafireflyServerSide** plugin (version 1.0.0, compatible with Shopware 6.5 and 6.6) sends your store's purchase conversion server-to-server, directly to each platform's conversion API (Meta CAPI, GA4, TikTok, Pinterest, Microsoft Advertising). The purchase event fires when the order is placed and is HMAC-signed for your shop. Destination credentials never pass through the browser.

### Can the plugin break my Shopware store's checkout?

No. The plugin is fail-safe by design: tight HTTP timeouts and full exception handling mean a tracking error can never interrupt the order or the checkout. A failed delivery is logged (prefixed `[DataFirefly SS]` in the Shopware logs) but the order always completes normally.

### Do I have to paste pixel IDs into Shopware?

No. You only paste a connection key (`dfss_…`), copied from the "Connect your shop" screen in your DataFirefly account (/app). The dispatcher knows which destinations to fan out to. You never paste a pixel ID or access token into the store.

### Does the plugin respect GDPR consent?

Yes, via the **Require consent** option (off by default). Once enabled, the purchase is only sent if the consent cookie you specify is present: cookie name and value are configurable and checked server-side. Shopware 6 does not expose a single server-readable marketing consent cookie, so the plugin adapts to your store's consent solution. The dispatcher is EU-hosted (Germany) and personal data is redacted.

### Do I need to host a server-side GTM container?

No. DataFirefly sends events directly to each platform's conversion API: there's no server-side GTM container to host or maintain. Setup is limited to the Shopware plugin and a single connection key.

On another platform? Discover the [PrestaShop server-side tracking module](https://server-side.datafirefly.com/en/prestashop-server-side-tracking.html) or the [WooCommerce server-side tracking plugin](https://server-side.datafirefly.com/en/woocommerce-server-side-tracking.html).

## Move your Shopware store's tracking server-side

Send the purchase conversion server-side to Meta CAPI, GA4, TikTok, Pinterest and Microsoft Advertising: HMAC-signed, fail-safe for checkout, EU-hosted and consent-aware.

[Create an account](https://admin.datafirefly.com/pricing?lang=en) [Talk to us](https://server-side.datafirefly.com/en/contact.html)
