Critical Tracking & Analytics
Personal data or tokens in URL
- Severity
- Critical
- Impact
- High
- Effort to fix
- Medium
- Issue code
track_pii_in_url
Why it matters
The URL carries an email address, token or similar value. Analytics tools record full page URLs, so it ends up in GA4 (against Google's terms) and leaks through referrers and server logs.
How to fix it
Send these values in the request body or session instead of the URL. Redact them in GA4 (Data redaction for email and query parameters) until the site is fixed.
How it affects your score
Tracking issues have their own Tracking score and never lower the SEO site health score. They still appear in the Action Plan, the issues CSV, Slack messages and Linear tickets. Blocks indexing, breaks pages or loses traffic. Fix these first.
Find the affected URLs
Open Crawl > Issues and pick Personal data or tokens in URL. Each affected URL is listed with its evidence, and Copy URLs or Export URLs hands the list to a developer. The issue also appears in the Action Plan, ranked by impact (high) and effort (medium), and in the issues CSV under the code track_pii_in_url. After fixing, run a new audit and use Compare to confirm the URLs moved to fixed.
Guides that cover this issue
Related Tracking & Analytics issues
- CriticalGA4 sent by page code and by GTM
- CriticalGTM container not published or wrong ID
- CriticalPage view sent twice on one page load
- CriticalPixel initialised twice on the page
- CriticalTag loaded twice on the page
- CriticalTracking before consent
- WarningAnalytics tag missing on this page
- WarningDifferent GA4 ID than the rest of the site