Tracker script attributes reference
Every data- attribute the pa.js tracker reads from its script tag, with defaults and examples for modules, SPA mode, domains, exclusions and masks.
Attributes are read once, from the <script> tag that loads pa.js.
Boolean attributes must be the string "true". Any other value (or no
attribute) means off.
| Attribute | Default | Description |
|---|---|---|
data-site |
required | Your site id, e.g. pa_7Q2K9XH3AB. Not a secret |
data-modules |
engage |
Comma-separated modules: engage, auto, vitals, clicks. Setting it replaces the default, so include engage to keep time on page and scroll depth. data-modules="" loads none. See Modules |
data-spa |
auto |
auto or history: follow history.pushState and popstate. hash: follow hashchange and keep the #fragment in the path. off: only the initial page load. See SPAs |
data-manual |
false |
true turns off the automatic pageview on load. SPA navigations are still tracked unless data-spa="off". See Manual mode |
data-domains |
None | Comma-separated hostnames to track on, e.g. example.com,www.example.com. On any other hostname nothing is sent. Exact match |
data-exclude |
None | Comma-separated path globs not to track, e.g. /admin/*,/preview/*. * matches any characters, including /. Matched against the path without the query string |
data-mask |
None | Comma-separated pattern->replacement rules, e.g. /users/*/settings->/users/:id/settings. The first matching glob replaces the whole path |
data-params |
None | Extra query parameters to keep in the URL sent, e.g. page,sort. Also add them to the site's query parameter allowlist (Site settings → Privacy) or the server drops them |
data-canonical |
false |
true reports the URL of <link rel="canonical"> instead of the address bar URL |
data-hash |
false |
true keeps the #fragment as part of the path. Implied by data-spa="hash" |
data-api |
script origin | Where hits go and modules load from, e.g. https://privatusanalytics.com. Hits go to {data-api}/api/event, modules load from {data-api}/js/pa.<module>.js. Only needed when you host a copy of pa.js yourself. See Versioning and SRI |
data-props |
None | Name of a global function that returns an object of properties to add to every pageview and event, e.g. data-props="privatusProps" |
data-namespace |
privatus |
Name of the global object (window.privatus). Change it if the name is taken or you run two trackers |
data-debug |
false |
true logs each hit to the console instead of sending it, and allows localhost. See Debug mode |
data-allow-local |
false |
true sends hits from localhost, 127.*, .local hosts and file:// |
Always kept query parameters#
Whatever data-params says, the tracker keeps these parameters so the
server can attribute the visit: utm_*, ref, via, source, and the
click ids gclid, gbraid, wbraid, msclkid, fbclid, ttclid.
Everything else in the query string is removed in the browser before
sending. The server then stores UTM values and ref, reduces click ids to a
yes/no "paid click" flag, and drops the rest (see
data minimization).
Examples#
A marketing site with automatic events, no admin pages and pretty paths:
<script defer src="https://privatusanalytics.com/js/pa.js"
data-site="pa_YOURSITEID"
data-modules="engage,auto"
data-exclude="/wp-admin/*,/preview/*"
data-mask="/orders/*->/orders/:id"></script>
A hash-routed app that adds the plan to every hit:
<script>
function privatusProps() { return { plan: window.currentPlan || 'free' } }
</script>
<script defer src="https://privatusanalytics.com/js/pa.js"
data-site="pa_YOURSITEID"
data-spa="hash"
data-props="privatusProps"></script>
Not an attribute: Do Not Track and GPC#
The tracker always reports whether the browser sends Do Not Track or Global Privacy Control. Whether those hits are dropped is a site setting (Site settings → Privacy): GPC is honoured by default, DNT is not. See DNT and GPC.