# Tracker script attributes reference

> Every data- attribute the pa.js tracker reads from its script tag, with defaults and examples for modules, SPA mode, domains, exclusions and masks.

Attributes are read once, from the `<script>` tag that loads `pa.js`.
Boolean attributes must be the string `"true"`. Any other value (or no
attribute) means off.

| Attribute | Default | Description |
|---|---|---|
| `data-site` | required | Your site id, e.g. `pa_7Q2K9XH3AB`. Not a secret |
| `data-modules` | `engage` | Comma-separated modules: `engage`, `auto`, `vitals`, `clicks`. Setting it **replaces** the default, so include `engage` to keep time on page and scroll depth. `data-modules=""` loads none. See [Modules](/docs/tracker/modules) |
| `data-spa` | `auto` | `auto` or `history`: follow `history.pushState` and `popstate`. `hash`: follow `hashchange` and keep the `#fragment` in the path. `off`: only the initial page load. See [SPAs](/docs/tracker/spa) |
| `data-manual` | `false` | `true` turns off the automatic pageview on load. SPA navigations are still tracked unless `data-spa="off"`. See [Manual mode](/docs/tracker/manual-mode) |
| `data-domains` | None | Comma-separated hostnames to track on, e.g. `example.com,www.example.com`. On any other hostname nothing is sent. Exact match |
| `data-exclude` | None | Comma-separated path globs not to track, e.g. `/admin/*,/preview/*`. `*` matches any characters, including `/`. Matched against the path without the query string |
| `data-mask` | None | Comma-separated `pattern->replacement` rules, e.g. `/users/*/settings->/users/:id/settings`. The first matching glob replaces the whole path |
| `data-params` | None | Extra query parameters to keep in the URL sent, e.g. `page,sort`. Also add them to the site's **query parameter allowlist** (Site settings → Privacy) or the server drops them |
| `data-canonical` | `false` | `true` reports the URL of `<link rel="canonical">` instead of the address bar URL |
| `data-hash` | `false` | `true` keeps the `#fragment` as part of the path. Implied by `data-spa="hash"` |
| `data-api` | script origin | Where hits go and modules load from, e.g. `https://privatusanalytics.com`. Hits go to `{data-api}/api/event`, modules load from `{data-api}/js/pa.<module>.js`. Only needed when you host a copy of `pa.js` yourself. See [Versioning and SRI](/docs/tracker/versioning-and-sri) |
| `data-props` | None | Name of a global function that returns an object of properties to add to every pageview and event, e.g. `data-props="privatusProps"` |
| `data-namespace` | `privatus` | Name of the global object (`window.privatus`). Change it if the name is taken or you run two trackers |
| `data-debug` | `false` | `true` logs each hit to the console **instead of sending it**, and allows `localhost`. See [Debug mode](/docs/tracker/debug) |
| `data-allow-local` | `false` | `true` sends hits from `localhost`, `127.*`, `.local` hosts and `file://` |

## Always kept query parameters

Whatever `data-params` says, the tracker keeps these parameters so the
server can attribute the visit: `utm_*`, `ref`, `via`, `source`, and the
click ids `gclid`, `gbraid`, `wbraid`, `msclkid`, `fbclid`, `ttclid`.
Everything else in the query string is removed in the browser before
sending. The server then stores UTM values and `ref`, reduces click ids to a
yes/no "paid click" flag, and drops the rest (see
[data minimization](/docs/privacy/data-inventory)).

## Examples

A marketing site with automatic events, no admin pages and pretty paths:

```html
<script defer src="https://privatusanalytics.com/js/pa.js"
        data-site="pa_YOURSITEID"
        data-modules="engage,auto"
        data-exclude="/wp-admin/*,/preview/*"
        data-mask="/orders/*->/orders/:id"></script>
```

A hash-routed app that adds the plan to every hit:

```html
<script>
  function privatusProps() { return { plan: window.currentPlan || 'free' } }
</script>
<script defer src="https://privatusanalytics.com/js/pa.js"
        data-site="pa_YOURSITEID"
        data-spa="hash"
        data-props="privatusProps"></script>
```

## Not an attribute: Do Not Track and GPC

The tracker always reports whether the browser sends Do Not Track or
Global Privacy Control. Whether those hits are dropped is a site setting
(**Site settings → Privacy**): GPC is honoured by default, DNT is not. See
[DNT and GPC](/docs/privacy/dnt-gpc).
