If you run a health ecommerce store, you have probably felt this weird tension.
On one hand, you need proper marketing data. Which ads are working? Which landing pages actually convert? Is that new subscription offer doing anything other than annoying people?
On the other hand, health-related products can get sensitive fast. Not just in a legal sense, but in a human sense. People do not always want to feel watched while they’re browsing supplements, skin treatments, fertility products, incontinence aids or anything that hints at a condition.
And then you open GA4 and think, right. How do I track conversions without accidentally creating a compliance mess?
This guide is basically the way I’d set up GA4 for a health ecommerce brand if I had to keep it clean, useful and defensible. Not “track everything”, more like “track what matters, in a way you can justify”.
The uncomfortable truth about “health data” in analytics
A lot of ecommerce teams assume the risky stuff is only inside forms. Like, “as long as we do not ask for medical info, we’re fine”.
But analytics can become sensitive even when you never ask a single question.
Because you can infer things.
If someone lands on a page called /treatment-for-psoriasis and then buys a specific product, the browsing behaviour itself might be considered sensitive personal data depending on context, jurisdiction and what else is being collected.
In the UK and EU context, GDPR and UK GDPR are the backdrop. Add PECR for cookies and similar tech in the UK. If you sell globally, you may have other rules too, but let’s not spiral.
The practical takeaway for GA4 is this:
You want to minimise what you collect, avoid sending anything that could identify someone and keep your event naming and parameters generic enough that you are not encoding health in the tracking layer.
And yes, you can still do conversion tracking. It just needs a slightly different mindset.
GA4 basics that matter for compliance (without a legal lecture)
GA4 is event-based. Everything is an event. Page views, purchases, sign-ups, scrolls, add to carts, all events.
For compliance-friendly measurement, the main GA4 levers you care about are:
- Consent Mode (so GA4 behaves differently based on consent)
- Data minimisation (only send what you need)
- PII controls (never send emails, phone numbers, names, addresses)
- Event and parameter hygiene (avoid sensitive data in URLs, event names, product names, search terms)
- Retention and access settings (limit who can see what, and for how long)
- Server-side tagging (optional, but often worth it for health ecommerce)
I’ll walk through each in a way you can apply.
Step 1: Sort your consent approach first (otherwise everything else is shaky)
If you operate in the UK, you generally need opt-in consent for non-essential cookies and similar identifiers used for marketing and analytics. There are nuances, but again, we’re being practical.
Consent Mode v2 is Google’s framework for adapting tags based on user consent status. It allows measurement to be modelled when consent is denied and full measurement when consent is granted.
A typical setup looks like:
- A consent banner or CMP (Cookie Management Platform) collects consent choices.
- Your site sets consent states (analytics_storage, ad_storage, ad_user_data, ad_personalization).
- GA4 and Google Ads tags read those states.
- GA4 may use aggregated or modelled data where permitted.
What you want to avoid is “GA4 loads and drops identifiers before consent”. That is the thing that causes problems.
Implementation note: most brands do this through Google Tag Manager (GTM) with a CMP integration. If you already have a CMP, check whether it supports Consent Mode and whether it’s actually configured, not just “installed”.
Also, please test it. Like actually test it in a browser with the banner set to reject. Watch the network calls. Make sure you are not firing marketing tags pre-consent.
Respecting customer privacy isn't just about regulatory compliance - it also plays an important role in building confidence. Our guide to building trust when selling health products online explores how transparent data practices contribute to stronger customer relationships.
Step 2: Decide what a “conversion” means in health ecommerce (and what should not be a conversion)
The term conversion is often misused. In GA4, any event can be marked as a conversion, but it's important to be selective.
In the context of health ecommerce, I typically categorise conversions into two main buckets:
Primary conversions (revenue tied)
purchase(this one is obvious)subscribeorsubscription_start(if you offer recurring plans)refundorcancel_subscription(not technically a conversion, but it's important to track)
Secondary conversions (leading indicators)
add_to_cartbegin_checkoutgenerate_lead(only if it is a generic lead, not specific to a health condition)view_promotionandselect_promotion(for onsite promotions)
However, there are certain actions that should not be marked as conversions in this niche:
- Anything that reveals or implies condition interest, such as completing a “symptom checker” event with symptom parameters.
- Internal search terms as conversions. In fact, internal search often becomes a sensitive data trap.
These actions can still be tracked, but it should be done with strict parameter controls and sometimes not tracked at all, depending on your risk profile.
And remember, collecting accurate data is only the first step. Once your tracking is in place, you can start using it to identify friction points and improve conversions. Our conversion rate optimisation service turns these insights into measurable improvements.
Step 3: Clean up your URLs, page titles, and onsite search before you even touch GA4
This part might seem tedious but it pays off later.
GA4 automatically collects page location (URL) and page title. If your URLs contain sensitive terms, it could pose a problem. This isn't always the case, but there's potential for issues.
Here are some things to watch out for:
- Condition names in URL slugs (a common issue with SEO content)
- Query parameters that include user inputs
- Onsite search queries in URLs, such as
?q=eczema+flare+up - Email addresses inadvertently included in URLs (this usually happens due to careless email tools)
- Order IDs or personal details in URLs (rare occurrences, but they do happen)
Quick fixes:
- Retain medical or condition content in your site but avoid passing user entered inputs in query strings.
- If onsite search query parameters must be used, consider employing GTM to strip or redact them before sending page_view to GA4.
- Properly utilise GA4’s List unwanted referrals and cross domain settings to prevent data leakage via redirects and payment providers.
For onsite search tracking, I prefer using event tracking where the search term is either:
- Not sent at all
- Classified into a safe category
Step 4: Use product IDs and safe categories, not descriptive product names that reveal too much
Here is a classic mistake in health ecommerce GA4 ecommerce tracking.
You send item_name like:
“Thrush treatment oral capsule 7 day”.
Even if that is your product name, you are now piping sensitive context into analytics data that lots of people internally might access. Plus, it can appear in exports, dashboards, shared screenshots, all that.
A safer pattern:
item_id: a neutral SKU, likeSKU_18483item_name: a brand neutral name, likeCapsules 7 day(still descriptive, but not condition coded)item_category: safe taxonomy likeSupplements,Personal care,Bundlesitem_category2:Vitamins,Skin care,Oral careetc
Then keep the “medical specificity” on your website and in your product catalogue, not in your analytics payload.
Is it annoying? Yes. Does it reduce marketing clarity? A bit. But it is the trade-off we have to make.
If you do need detail for merchandising, consider a separate internal BI system with stricter access, not GA4 for everything.
Step 5: Implement GA4 ecommerce events properly (and keep parameters tight)
If you are on Shopify, WooCommerce, Magento, whatever, the mechanics vary. But the event set is standard.
GA4 recommended ecommerce events include:
view_item_listselect_itemview_itemadd_to_cartremove_from_cartview_cartbegin_checkoutadd_shipping_infoadd_payment_infopurchase
For compliance friendly tracking, the key is not the event names, it is what you include inside them.
What to include
- transaction ID (not personally identifying)
- value, currency, tax, shipping totals
- item_id, quantity, price
- high-level categories
What to avoid
- customer email
- phone number
- full address
- anything from free text fields
- prescription notes (if you have that)
- doctor name, clinic name, referral text, anything like that
If you are using GTM dataLayer, do a quick audit: open the console and inspect what is being pushed. Sometimes ecommerce platforms push way more than you expect.
If any PII is present, you do not “just ignore it”. You stop it from being sent.
Step 6: Set up compliance friendly conversion goals in GA4
In GA4, go to Admin → Events and mark conversion events. At minimum:
- Mark
purchaseas a conversion - Mark
subscribeas a conversion if subscription is core - Consider
begin_checkoutas a micro conversion if you need funnel visibility
Then, create Audiences carefully.
This is important: audiences can become sensitive profiling if you build them around health interests.
A safer way to do audiences in health ecommerce is to keep them behaviour-based, not condition based.
Examples that are usually safer:
- “Added to basket but did not purchase in 7 days”
- “Viewed product category: Supplements” (broad categories)
- “High AOV customers”
- “Subscription customers”
- “Returning purchasers”
Examples that are riskier:
- “Viewed erectile dysfunction products”
- “Visited fertility pages”
- “Searched for depression supplements”
Even if it is “just marketing”, it is still profiling. And it gets messy.
Step 7: Use Google Tag Manager to control what data goes out (this is where the magic is)
If your GA4 tracking is hardcoded or installed through a plugin with limited controls, you are basically stuck with whatever it sends.
GTM gives you a layer where you can:
- Block tags until consent
- Redact URL query parameters
- Hash or remove user inputs
- Standardise ecommerce payloads
- Rename events and parameters into safe naming
A simple example: you track onsite search, but you do not want the raw query.
Instead of sending search_term = "eczema cream", you map search terms to a safe classification:
search_topic = "skin_care"search_intent = "treatment"(even this can be sensitive, so keep it generic)- or just
search_used = truewithout details
You can do this with lookup tables in GTM. Not perfect. But better than shipping raw health-related keywords.
Step 8: Consider server-side tagging if you want extra control (and fewer surprises)
Server-side GTM is not required. But for health ecommerce, it can be a genuinely good move.
Why?
Because it gives you:
- Better control over what is forwarded to Google and ad platforms
- A place to redact data centrally
- More resilience against browser restrictions
- Potential performance improvements, depending on setup
It does not magically make you compliant. You still need consent and good governance. But it can reduce accidental leakage.
If you are already spending serious money on paid media, server-side tagging often pays for itself just through better measurement stability. Especially with consent mode modelling in the mix.
Step 9: GA4 settings you should actually review (most people never do)
Inside GA4 Admin, check these:
Data retention
Go to Admin → Data settings → Data retention.
- Set retention to the minimum that still lets you do your analysis. Many teams choose 2 months or 14 months. Be intentional.
- If you do not need long lookbacks in GA4, do not keep them.
Google signals
Google signals enables cross device reporting and remarketing features. In sensitive verticals, this is something to review carefully.
If you do not need it, consider leaving it off. If you do need it, make sure your consent setup covers it properly.
User ID
If you use User ID, do not use anything identifiable. No emails. No phone numbers. Use an internal random ID.
And also ask yourself if you need it. Sometimes you think you need it, but you really just need better reporting.
Enhanced measurement
Enhanced measurement can track things like outbound clicks, file downloads, site search, video engagement.
In health ecommerce, site search tracking is the big one to watch. If enhanced measurement automatically captures it, you may be collecting sensitive search terms without realising.
Turn off what you do not want.
Step 10: Reporting that still helps marketers, even with the guardrails
So, you have reduced the granularity. Great. Now your paid social manager complains they cannot see which “condition line” is working.
This is where you rebuild clarity in safer ways.
Some reporting ideas that usually stay on the right side of the line:
- Performance by high-level product category
- Performance by format: tablets vs gummies vs creams (if that is not condition linked)
- Performance by bundle vs single
- Performance by new vs returning
- Performance by subscription vs one time
- Funnel drop off by step (product view, add to cart, begin checkout, purchase)
- Landing page performance by intent type: educational vs product listing vs product page
And for SEO content, instead of tracking conversions by “condition article”, track by content type:
- Guides
- Ingredient explainers
- Routine builders
- Brand pages
You still learn what moves people. You just do not label users as “interested in X condition” in your analytics tools.
A quick checklist: what I’d audit tomorrow morning
If I had 60 minutes and needed to reduce risk fast, I’d check:
- Consent banner properly blocks GA4 and ads tags until opt in
- Enhanced measurement site search is off (or redacted)
- No PII in dataLayer, URLs or event parameters
- Ecommerce item names do not encode conditions
- Audiences are behaviour-based, not health interest based
- GA4 data retention set intentionally
- Access controls: who can see GA4 property, who can export, who can link to ads accounts
That last one matters more than people admit. Analytics risk is not just what you collect, it is who can access it.
FAQs
Is GA4 allowed for health ecommerce sites in the UK?
Usually yes, but it depends on your implementation. The big issues are consent (PECR), lawful basis and transparency (UK GDPR) and making sure you are not collecting or leaking personal data or sensitive inferences through URLs, search queries, or event parameters. GA4 itself is not the compliance problem. Sloppy tracking is.
Can I track purchases in GA4 without collecting personal data?
Yes. A GA4 purchase event can be implemented with transaction and product details that do not identify a person. Do not send email, phone, name or address in events or parameters. Use non identifying order IDs and neutral product identifiers.
Should I track onsite search terms for a health store?
Be careful. Onsite search can easily contain sensitive health-related terms. A safer approach is to disable search term collection, or map search terms into broad categories (or just track that search happened, without the term).
What about remarketing audiences, are they risky?
They can be. In health ecommerce, avoid building audiences that imply a health condition or sensitive interest. Stick to behavioural audiences like cart abandoners, returning buyers, category level viewers and subscription status. Also make sure consent covers remarketing features.
Does Google Consent Mode make me compliant automatically?
No. Consent Mode helps tags behave based on consent status and can support modelled measurement. You still need a valid consent mechanism, clear cookie information and you still need to avoid sending personal or sensitive data in the first place.
Is server-side tagging necessary for compliance?
Not strictly. But it can help you control and redact data more reliably, reduce accidental leakage and improve measurement stability. Think of it as an extra layer of control, not a compliance shortcut.
How do I know if I’m accidentally sending PII into GA4?
Check your GTM preview mode and browser developer tools, inspect network requests to Google Analytics and audit your dataLayer pushes. Also review URLs for query strings containing emails or user inputs. If you suspect PII has been collected, treat it as an incident: stop the flow, fix the source and consider deleting affected data where possible.
Should I keep product names generic in GA4?
If your product names include condition or treatment terms, yes, consider using neutral names in analytics and rely on SKUs and category taxonomy for reporting. This reduces the chance you are encoding sensitive health context into your analytics datasets.
What is the simplest “safe” conversion setup for a health ecommerce store?
Consent Mode + GA4 purchase tracking with minimal parameters, plus a couple of micro conversions like add to basket and begin checkout. No onsite search terms, no free text field tracking and no condition-based audiences. Keep it boring. Boring is good here.