On February 2, 2022, Meta CFO David Wehner told analysts that Apple's App Tracking Transparency change would cost Meta roughly $10 billion in 2022 ad revenue. Meta's stock fell 26% the next day.
The market treated that as an Apple story. It was really a measurement story.
Apple did not invent the problem. It exposed it. Web tracking was already fragile. Cookies expired. Pixels were blocked. UTMs were stripped. Customer IDs did not match. Revenue lived in a different system. Bot and internal traffic polluted the data. Privacy changes made the weakness visible.
The result is familiar to every growth team: the ad account says one thing, Shopify says another, GA4 says another, and finance does not trust any of them.
The five places tracking breaks
Tracking fails in layers. Every event has to survive all of them before it becomes a number a team can use.
1. Browser. Safari ITP, App Tracking Transparency, Mail Privacy Protection, Link Tracking Protection, private browsing, and cookie limits all reduce the signal before the event even leaves the user's device. A first-party cookie that once lasted months can now disappear after days or hours.
2. Network. Ad blockers, privacy browsers, corporate firewalls, and block lists stop calls to analytics and ad endpoints. Server-side tagging recovers some signal, but it does not recover what the browser or network never sent.
3. Identity. The same visitor can become several partial users across GA4, Meta, Klaviyo, Shopify, Stripe, the CRM, and support tools. A CDP can help, but it only works when the identifying events are fired and joined correctly.
4. State. The business cares about state changes: became a lead, placed an order, refunded, subscribed, churned, returned. Event tools record events. Commerce, billing, CRM, and support tools record state. The join is where many numbers break.
5. Trust. Consent, bots, internal traffic, QA sessions, and bad traffic are often filtered after they have already polluted the event stream. A model, experiment, or dashboard may have already used the dirty data.
One weak layer hurts the number. Five weak layers multiply.
The compounding effect
A representative chain might look like this:
- browser captures stable identity for 70% of users
- network delivers 80% of those captures
- identity joins 75% of delivered events to a known customer
- state joins 70% of known customers to the right order or lifecycle state
- trust filters accept 90% of the remaining events as legitimate
The compounded result is about 26% of real conversion events reaching the dashboard with the full chain intact.
The exact number will differ by site, channel, device mix, and implementation quality. The point is the shape: each patch only fixes one layer. The final number is the multiplication of every layer's loss.
This is why teams can spend heavily on server-side tagging, Conversions API, a CDP, a consent tool, bot filtering, and a data warehouse, and still not trust the final CAC or ROAS number.
Why the usual fixes are partial
Server-side tagging helps with blocked endpoints. It does not fix identity, state, or trust.
Conversions API helps send events back to ad platforms. It does not prove that the platform's modeled conversions match your source-of-revenue data.
CDPs help stitch identities. They do not force every downstream tool to respect the same customer record.
Consent tools help with legal collection. They do not guarantee the data is good enough to use for budget decisions.
Modeled conversions make reports look complete. They can be useful, but they are not the same as observed, defensible events. Operators need to know which is which.
Why the problem keeps moving
Tracking does not break once. It decays.
The browser changes. Safari shortens cookie life. Apple changes app tracking rules. Google changes Chrome policy. Email clients preload images. Ad blockers update lists. Privacy products remove parameters. Platforms add modeled conversions. Regulations change what can be collected, stored, and joined. Each change is rational from one point of view. Together, they make yesterday's tracking setup less reliable than the day it launched.
That is why "we installed tracking" is not a durable state. It is closer to "we reconciled the bank account." It was true at a point in time. It can be false again tomorrow.
The same decay happens inside the business. A new checkout app changes order events. A new subscription tool changes customer IDs. An agency renames campaigns. A developer changes a form event. A lifecycle team adds a quiz before purchase. A finance team changes how refunds are recorded. None of these changes is dramatic alone. Each can weaken the chain from click to customer to revenue.
Growth teams often discover the break only when the decision matters. Spend is already live. A test is already over. A board deck is due. A founder asks why Meta, GA4, Shopify, and finance disagree. At that point the team is not analyzing growth. It is investigating its measurement system.
The practical hierarchy of tracking
Not all tracking signal deserves the same trust.
At the bottom are anonymous events: page views, clicks, scrolls, impressions, and pixel fires. They are useful for product and media diagnostics, but weak for budget decisions.
Above that are identified events: form submits, emails, logins, checkout starts, subscriptions, and known customer actions. These are stronger because the event can be tied to a person or account.
Above that are money events: orders, charges, refunds, fees, payouts, disputes, subscriptions, and bank deposits. These are the events finance can recognize.
The strongest growth metric connects all three layers: the user action, the customer identity, and the money event. CAC, ROAS, MER, payback, LTV, and margin should not be treated as equal to a pixel event. They are derived from a chain. A good system shows the chain and says where it is weak.
This is also where many dashboards mislead teams. They present all metrics with the same visual confidence. A modeled platform conversion and a reconciled order-to-payment join may both show as a clean number. They should not carry the same weight in a budget meeting.
What good tracking should prove
For every important revenue event, the system should answer:
- Who was this visitor or customer, and how confident are we?
- What was their first known campaign, source, and medium?
- Which page, email, ad, or flow did they touch?
- Did the conversion happen in Shopify, Stripe, or another system that records money?
- Was the event accepted, rejected, suppressed, or unavailable?
- Which layer of the chain is weak?
Without those answers, the team is not measuring. It is reading a blended output from several tools and hoping it is close enough.
What Lyberty does
Lyberty captures first-party events at the edge, ties first-touch UTM data to a tracked user, and joins revenue back through commerce and payment data when an email, form, order, or Stripe customer resolves the identity.
Metric cells carry an availability state, so a missing CAC is not treated the same as a verified zero. Channels only show spend-and-revenue metrics when the spend adapter and revenue join both verify. Where the system cannot defend a number, the cell stays empty and says why.
Lyberty does not pretend to recover every lost signal. Cross-publisher identity is out of scope. Users who never provide a durable signal remain pseudonymous. Account-level tracking is only supported where there is a real account identity. The point is not to make tracking magical. The point is to make the confidence visible.
What to check
- Pick your largest paid channel.
- Trace one customer from click to order to payment.
- Identify where the click, visitor, customer, order, and payment IDs join.
- Ask which joins are deterministic and which are modeled.
- Refuse to scale spend on a number whose chain nobody can explain.
Sources
- Intelligent Tracking Prevention (ITP). Apple WebKit, beginning June 5, 2017. https://webkit.org/blog/7675/intelligent-tracking-prevention/
- Intelligent Tracking Prevention 2.1. Apple WebKit, February 21, 2019. https://webkit.org/blog/8613/intelligent-tracking-prevention-2-1/
- Intelligent Tracking Prevention 2.3. Apple WebKit, September 23, 2019. https://webkit.org/blog/9521/intelligent-tracking-prevention-2-3/
- iOS 14.5 Offers App Tracking Transparency. Apple, April 26, 2021. https://www.apple.com/newsroom/2021/04/ios-14-5-offers-app-tracking-transparency-and-more-on-iphone-and-ipad/
- Meta Q4 2021 Earnings Call Transcript. Meta Platforms, February 2, 2022. https://s21.q4cdn.com/399680738/files/doc_financials/2021/q4/Meta-12.31.2021-Exhibit-99.1-FINAL.pdf
- iOS 17 Link Tracking Protection. Apple Developer, June 2023. https://developer.apple.com/videos/play/wwdc2023/10053/
- A new path for Privacy Sandbox on the web. Google Privacy Sandbox, July 22, 2024. https://privacysandbox.com/news/privacy-sandbox-update/
- EasyList. EasyList project. https://easylist.to/
- Server-side Tagging in Google Tag Manager. Google Tag Manager. https://developers.google.com/tag-platform/tag-manager/server-side
- About the Conversions API. Meta for Developers. https://developers.facebook.com/docs/marketing-api/conversions-api/
- Snowplow Raises $40M Series B. Snowplow, January 18, 2022. https://snowplow.io/news/snowplow-raises-40m-series-b
- RudderStack Raises $56M Series B. RudderStack, February 1, 2022. https://www.rudderstack.com/blog/rudderstack-series-b-funding/
- Twilio to Acquire Segment for $3.2 Billion. Twilio, October 12, 2020. https://investors.twilio.com/news/news-details/2020/Twilio-to-Acquire-Customer-Data-Platform-Leader-Segment-for-3-2-Billion/default.aspx
- Imperva 2024 Bad Bot Report. Imperva, 2024. https://www.imperva.com/resources/resource-library/reports/bad-bot-report/
- HubSpot State of Marketing Report 2024. HubSpot, 2024. https://www.hubspot.com/state-of-marketing