GTM Kit 2.21: customer details that wait for consent, and a read-only view for AI assistants
GTM Kit 2.21.0 changes one thing every store that sends customer details with the purchase event should know about: those details now wait for the visitor’s advertising consent. The release also lets AI assistants connected to your site read how GTM Kit is set up, and it makes the dashboard, Site Health and the GTM4WP import say more clearly what is going on with the Google tag gateway, Stape’s loader and your consent defaults.
What changed
Customer details on the purchase event now follow advertising consent
If you switched on sending customer details with the purchase event (under Commerce → WooCommerce: User Data), GTM Kit adds the buyer’s email, phone, name and address to the event, hashed or not, so Google Ads can use them for Enhanced Conversions. Google expects that data only from visitors who have granted advertising consent. Until now, GTM Kit added it regardless.
From 2.21, GTM Kit adds those details only once the visitor has granted both ad_storage and ad_user_data. In practice:
- Consent already granted when the order confirmation page loads: the purchase is sent straight away, with the details.
- Consent granted during a short wait: the purchase is held for up to three seconds while your consent platform loads and answers. If the visitor grants consent in that time, the purchase is sent with the details.
- Consent denied, or a denying default not lifted within three seconds: the purchase is still sent, without the details. You never lose the conversion itself.
- No consent found: GTM Kit cannot see a consent answer, so it treats consent as unknown rather than denied. It waits up to three seconds in case a consent platform loads late, then sends the purchase with the details, as before.
GTM Kit reads consent wherever it is set: its own data layer, dataLayer if that is a different one, and the consent state Google Tag Manager holds, so a consent platform that sets consent through its Google Tag Manager template counts too. A denial in any of them withholds the details. Only when GTM Kit finds no consent state at all does it treat consent as unknown. If you would rather withhold the details in that case too, a developer can use the gtmkit_consent_unknown filter (see Developer notes).
The decision is made in the visitor’s browser, not on your server, so it stays correct behind full-page caching. If the visitor leaves the page or switches apps during the wait, the purchase is sent immediately rather than lost.
If you do not send customer details with the purchase event, nothing changes: the purchase is pushed exactly as before, with no wait.
Read-only answers for AI assistants
WordPress 6.9 added the Abilities API, a standard way for plugins to describe what they can do so that tools, including AI assistants connected through the WordPress MCP Adapter, can call them. GTM Kit now registers three abilities:
- Get GTM Kit configuration: the container ID, data layer name, server-side tagging domain, which loader is in use, the Google tag gateway state and the active integrations.
- Get GTM Kit consent status: the Consent Mode defaults GTM Kit sets, the consent platform it detected, which source owns consent, and whether the defaults leave analytics with nothing to lift them.
- Get GTM Kit tracking health: the GTM Kit Site Health results you see yourself, plus the stored results of the gateway check and the daily check of a sample page.
So an assistant can answer “is GTM Kit set up correctly on this site?” from the same checks the settings screen and Site Health use, instead of guessing from page source.
They are deliberately narrow. Only users who can manage options (administrators) can run them. They only read; nothing can be changed through them. They make no outbound request and send nothing off your site, and they never return your GTM environment parameters or licence data.
Details: Let AI assistants read your GTM Kit setup.
The Google tag gateway and a custom server-side domain
The Google tag gateway and a custom server-side tagging domain both change the address your pages load Google’s scripts from, so GTM Kit can only use one of them. If both were set, the dashboard reported that the gateway was not working, which sent people looking for a fault that did not exist.
The dashboard now says the two cannot be used together and how to choose between them. The settings screen explains why one of the two is unavailable only while it actually is, and both fields stay editable when both are set, so you can clear whichever one you do not want.
More: Serve the Google tag from your own domain.
Stape’s loader switched on, but none stored
If you switched on the loader Stape issues (added in 2.20) but GTM Kit has no loader from Stape stored for your site, your pages quietly use the standard loader. The GTM Kit dashboard now tells you so, and points you to Server-side Tagging, where Refresh fetches the loader from Stape.
Site Health is more accurate about consent
Two cases where Site Health got consent wrong:
- Defaults that deny analytics, with nothing to lift them. If the Consent Mode defaults deny analytics storage and GTM Kit finds no consent platform that could grant it, every visitor is measured without cookies, indefinitely. Site Health used to call that “configured”. It now warns, recommends adding a consent platform or changing the defaults, and the Consent settings page shows the same warning.
- Defaults off because an integration handles consent. If the defaults are off because a consent integration, such as one using the WP Consent API, sets and updates the visitor’s consent, Site Health no longer reports consent as not configured.
Background: Turn on Google Consent Mode v2 defaults.
Importing from GTM4WP with a custom container path
When GTM4WP loads your container from a custom path, its server-side domain only works together with that path. Importing it alone gave GTM Kit a loader address that did not serve your container. The import now skips the domain in that case and says so, both under Tools and in the setup wizard, so you can set up server-side tagging deliberately afterwards.
More: Import settings from another GTM plugin.
Less JavaScript on classic-theme shops
On stores using a classic theme, shop, product and category pages without WooCommerce blocks no longer load GTM Kit’s block tracking script. Pages that show a WooCommerce block anywhere, including a Mini Cart block in a widget area, still load it, and block themes are unchanged.
Developer notes
- New filter
gtmkit_consent_unknown('allow'default, or'deny'). Decides what happens to the purchase’s customer details when the page holds no Consent Mode state forad_storageorad_user_dataat all. Return'deny'to withhold them on such sites. It applies site-wide and has no effect where a consent state exists. - New filter
gtmkit_abilities_enabled(bool, defaulttrue). Returnfalseto keep GTM Kit out of the Abilities API. WordPress builds the abilities registry once per request, so add it from a plugin or the theme’sfunctions.php. - Abilities: category
gtm-kit; abilitiesgtm-kit/get-configuration,gtm-kit/get-consent-status,gtm-kit/get-tracking-health. All read-only,manage_optionsto execute. window.gtmkit.events.consentHold. While a purchase waits for consent, this object reportspending(true while held, false once handed on) anduntil(the latest release time, inDate.now()milliseconds). It is only set when an event actually waits, soundefinedmeans “never held”.- Tag timing on the order confirmation page. When customer details are sent, the purchase push can arrive up to three seconds after page load. Fire purchase tags on the
purchaseevent, not on DOM Ready or Window Loaded. - The
gtmkit_datalayer_contentfilters still receive the full purchase payload, customer details included.
Upgrade notes
- Stores that send customer details with the purchase event: expect fewer purchases with customer details from visitors who decline advertising consent. That is the intended change. On sites without Consent Mode, the purchase now arrives up to three seconds later, still with the details.
- Everything else takes effect on update with no action needed.