Back in 2021, I released a Server-Side GTM Variable Template called Exclude or Whitelist Query String Parameters to solve a common challenge for analysts: Personally Identifiable Information (PII) and bloated tracking parameters leaking into Google Analytics and marketing pixels.
The concept was simple: create an Allowlist (Whitelist) or Blacklist (Exclude) for URL parameters.
Since then, Server-Side GTM has evolved. With the introduction of Transformations and more complex data collection requirements, this template has evolved from a simple “cleaner” into a comprehensive data governance tool.
I’ve completely rewritten the Exclude or Allowlist Query String Parameters template. Here is what could make the new version a useful addition to your SGTM container.

1. SGTM Transformations
You no longer need to manually configure “Cleaned URL” variables inside every single GA4 or marketing tag. Just plug the variable directly into an Augment Event Transformation. Set it up once, overwrite page_location, page_referrer, or link_url, and every tag in your container inherits the cleaned URLs.
2. Smart Click ID Mapping and Restoration
In scenarios where organizations pass custom or backup parameters for attribution routing (e.g., passing a custom backup_gclid), this template provides a safe way to map them back to standard parameter names server-side.
The template features “pre-scan” logic. If the standard parameter (gclid) is already present in the URL, the template ignores the backup to prevent duplicate parameters. If the standard parameter is missing, it renames the backup, ensuring your attribution data remains consistent.
3. Safe, Selective Lowercasing
Parameter matching can be difficult when campaign tags are inconsistent (e.g., arriving as ?UTM_Source one day and ?utm_source the next). The template allows you to force parameters to lowercase to clean up your data.
However, because many tracking tokens and Click IDs are case-sensitive and will break if lowercased, the template uses a opt-in approach. You can choose to lowercase only specific parameters (like your UTMs), ensuring that complex, case-sensitive IDs (like fbclid or gclid) remains intact.
4. Email Redaction
What happens if you allowlist a parameter like ?search_query=, but a user accidentally types their email into your site’s search bar? The template includes an independent RegEx safety net. Even if a parameter is allowlisted, if the template detects an email address format, it will redact the entire value to [EMAIL REDACTED], helping to prevent accidental privacy violations.
5. Built for Team Collaboration
Server-Side GTM setups are often managed by multiple people over several years, making documentation critical. When using the built-in table format for your Allowlist or Blacklist, you can utilize the Description column. This allows you to document exactly why a parameter is being kept or removed (e.g., “Facebook Click ID” or “Internal Search Term”). The documentation lives exactly where the logic lives, preventing knowledge loss over time.
6. Component-Level Decoding and Edge-Case Support
The template handles URL parsing carefully. It decodes at the component level to preserve complex encoded characters. Additionally, while hash fragments (#target) are typically ignored by standard analytics tools, they can be important for Single Page Applications (SPAs) or specific routing requirements. The template safely preserves these fragments when reconstructing the final URL, ensuring these edge cases are covered.
How to Get Started
You can add the updated template directly from the Google Tag Manager Template Gallery.
If you want to review the source code, or read the full technical documentation, you can find the complete repository on GitHub.

Be the first to comment on "The SGTM URL Cleaner: Better Data Governance and PII Protection"