# Exclude pages and mask URLs in the tracker

> Exclude pages and mask URLs in the browser: control which hostnames and paths are tracked and which URL is recorded, including query parameters.

Everything on this page happens **in the browser**, before anything is
sent. The server applies its own rules afterwards (site domains,
[traffic rules](/docs/privacy/traffic-rules), path masks, the query
parameter allowlist and the [PII scrubber](/docs/privacy/pii-scrubbing)).

## Only some hostnames: `data-domains`

```html
data-domains="example.com,www.example.com"
```

Nothing is sent on any other hostname: staging servers, preview
deployments, translation proxies, copies of your site. The match is exact, so
list each hostname you use.

The server also drops hits whose hostname isn't one of the site's domains
(or a subdomain of one), so `data-domains` is mostly useful when your
staging hosts are subdomains of your main domain.

## Skip paths: `data-exclude`

```html
data-exclude="/admin/*,/preview/*,/account/*"
```

Comma-separated globs matched against the path (no query string). `*`
matches any characters, including `/`, so `/admin/*` excludes everything
under `/admin/`. `/admin` itself needs its own entry.

Excluded pages send nothing at all: no pageview, no events.

## Rewrite paths: `data-mask`

Group URLs that contain ids into one page, and keep ids out of your data:

```html
data-mask="/users/*/settings->/users/:id/settings,/orders/*->/orders/:id"
```

Each rule is `glob->replacement`. The first matching rule replaces the
whole path. `*` matches any characters.

Prefer **server-side path masking** (Site settings → Privacy) when you
can: it applies to every collection method (tracker, pixel, server-side
API), and its `*` matches exactly one path segment. Client-side masks are
useful when the id itself must never leave the browser.

## Keep query parameters: `data-params`

By default the tracker keeps only campaign parameters (`utm_*`, `ref`,
`via`, `source`) and click ids, and drops everything else before sending.

```html
data-params="page,category"
```

keeps `page` and `category` too. The server stores a query parameter only
if it's also on the site's **query parameter allowlist** (Site settings →
Privacy), so add it there as well. Parameters are then part of the page
path in reports: `/search?category=shoes`.

## Canonical URLs: `data-canonical`

```html
data-canonical="true"
```

Reports the `href` of `<link rel="canonical">` instead of the address bar
URL. Useful when the same content lives under several URLs (tracking
parameters, print views, pagination). Campaign parameters from the address
bar are lost when the canonical URL doesn't carry them.

## Hash routing: `data-hash`

```html
data-hash="true"
```

Keeps the `#fragment` in the path (`/#/settings`). `data-spa="hash"`
turns this on and also tracks `hashchange` navigations. Without it, the
fragment is always dropped.
