Skip to main content
Guide

Server-Side Tracking Pricing: How to Compare

How server-side tracking is priced, the models you will encounter, and the way to compare quotes on 12-month total cost instead of the headline number.

9 min read

Compare server-side tracking pricing on the total 12-month cost at your projected event volume, not on the headline subscription price, because implementation fees, BAA terms, destination limits, and overage rates routinely move the real number more than the monthly line does. Curve is HIPAA-compliant ad tracking and analytics for healthcare, priced in tiers with a signed BAA included on every plan rather than sold as a separate compliance add-on. The comparison method below works regardless of who you are evaluating, and it is built to make quotes that look different actually comparable.

The four pricing models you will encounter

Almost every quote in this category resolves to one of four shapes, or a blend of two. Identify the shape first, because it determines what happens to your bill when the business grows.

Per-event or usage-based

You pay for volume: events ingested, events forwarded, or conversions delivered. The appeal is that a small site pays little. The problem is that the meter runs on the exact thing you are trying to increase. A campaign that doubles traffic doubles the tracking bill, and page views are usually the largest event category by an order of magnitude, so most of what you pay for is not conversion data at all. Ask three questions of any usage model. What counts as a billable event? Is a single conversion forwarded to five destinations one event or five? And is the meter on ingestion, on forwarding, or both? Those three answers can produce a fivefold difference in cost for identical traffic.

Per-seat

You pay per user with dashboard access. This model is common in analytics tools and it fits poorly with tracking infrastructure, because the value has nothing to do with how many people log in. It penalizes exactly the behavior you want, which is your agency, your compliance officer, and your practice managers all being able to see what is being collected and forwarded.

If a per-seat quote is otherwise attractive, price the seats you will actually need in a year rather than the seats you need on day one, and check whether read-only or auditor access counts as a seat.

Flat-rate tiers

You pay a fixed price for a tier defined by a volume ceiling and a feature set. The advantage is predictability, which matters more than it sounds when tracking sits between your ad budget and your compliance posture. The thing to check is what happens at the ceiling: whether you are upgraded, throttled, billed for overage, or silently dropped.

Percentage of ad spend

Less common for infrastructure, more common when tracking is bundled into an agency relationship. The cost scales with budget rather than with usage or value delivered, and it makes the tracking layer expensive precisely in the months you scale. It also creates an awkward incentive structure if the same party manages the spend.

The costs that live outside the subscription line

This is where quotes that look similar stop being similar. Ask about each of these explicitly, in writing, before you compare anything.

  • Implementation and onboarding fees. One-time setup charges are normal in this category and vary widely. Establish whether the fee covers configuration of your destinations and events, or only an account and a script.
  • BAA fees or BAA gating. Some vendors sign a BAA only on higher tiers, or charge for it. In healthcare that turns the BAA tier into your actual entry price, so compare from that tier rather than the advertised one.
  • Per-destination or per-connector charges. If you run Meta, Google, TikTok, and Microsoft, a per-integration fee multiplies quietly. Confirm whether adding a fifth platform next quarter is a configuration change or a contract change.
  • Overage rates. Get the number, and get the mechanism. Overage billed at a punitive multiple of the base rate is a different product than overage that bumps you into the next tier.
  • Support tiers. Whether a human helps you when a destination starts rejecting conversions is a cost question, not a service question. Ticket-only support has a real price measured in weeks of degraded campaign data.
  • Contract length, auto-renew, and price escalators. A multi-year term with a built-in annual increase and a 90-day non-renewal window is a materially different commitment from a 12-month term.
  • Data export and exit. Whether you can get your historical event data out, in what format, and at what cost, belongs in the pricing conversation rather than the offboarding conversation.

Build the comparison on 12-month total cost

Vendors present pricing in whichever unit flatters them. Normalize everything into one number before you compare.

  1. Project your event volume for 12 months, not today's volume. Take your current monthly events, apply your actual growth rate, and use the month-12 figure as the number that has to fit. Tracking systems are painful to switch, so buy for where you will be.
  2. Count events the way the vendor counts them. Page views usually dominate. If page views are billable, your event count is far higher than your conversion count suggests.
  3. Add the one-time fees and amortize them across the term you are actually committing to.
  4. Add the BAA tier premium if compliance features sit above the entry plan.
  5. Model one bad month. Take your best campaign month from last year, double it, and calculate the bill. That is your realistic ceiling, and it is where usage-based pricing surprises people.
  6. Add the internal cost. Engineering hours for setup and maintenance are real money. A cheaper tool that needs a developer every time a platform changes its API is not cheaper.

Two quotes are comparable only after all six steps. Before that you are comparing a subscription line to a subscription line, which is the comparison every vendor is hoping you make.

Questions worth asking on the pricing call

Short questions with specific answers. Vague answers are themselves information.

  • What exactly counts as a billable unit, and is a conversion forwarded to four destinations billed once or four times?
  • Is the BAA included at this tier, and can I read it before signing?
  • What is the overage rate, and what happens the first time I exceed the ceiling?
  • Is implementation included, and what specifically is delivered?
  • What does it cost to add a destination we are not currently running?
  • What is the renewal price, and is there a contractual escalator?
  • If we leave, what data can we export, in what format, and how long do we have?

Price is a proxy for a design decision

The pricing model a vendor chooses tells you what their system is optimized for. Usage-based pricing implies infrastructure costs that scale with volume, and it also implies the vendor benefits from your event count rising. Flat tiers imply the vendor absorbs volume variance and would rather sell predictability.

For healthcare specifically, there is a second signal. A vendor that charges extra for the BAA is treating compliance as an upsell rather than as the product. In this category compliance is not a feature that some customers need. It is the reason the category exists, because Meta and Google do not sign BAAs for their advertising products, which is what forces the server-side layer into the architecture in the first place.

How Curve prices

Curve is HIPAA-compliant ad tracking, marketing attribution, and analytics for healthcare, sold in three flat tiers rather than metered per event, so a good traffic month does not produce a surprise invoice.

A signed BAA is included on every plan, including the entry plan. There is no compliance tier, because the compliance behavior is the product: the tracking script installs in place of the Meta Pixel and Google tag, events go to Curve's US-hosted infrastructure rather than directly to the ad platforms, per-destination field mapping means nothing forwards to a given platform unless it is explicitly mapped, identifiers are SHA-256 hashed to each platform's conversion API requirements, and neutral event aliases keep the service line out of the ad platform interface.

Destination access is a plan feature rather than a per-connector charge, which matters if you run several platforms or expect to add one. Curve supports Meta CAPI, Google Ads Enhanced Conversions, TikTok Events API, Microsoft and Bing UET, LinkedIn CAPI, GA4, Amazon Ads, Premion, and VWO as server-side destinations.

Implementation is handled by Curve's team rather than billed as an engineering project on your side, which is the cost line most tracking comparisons leave out entirely. For what that setup involves, see our guide to HIPAA-compliant conversion tracking setup across Google, Meta, and Microsoft.

Pricing red flags

The BAA is quoted separately. In healthcare that is not an add-on, it is the precondition for using the product at all.

Overage rates are not disclosed until contracting. If the vendor will not put the overage number in the proposal, assume it is unfavorable.

"Custom pricing" for a standard deployment. Enterprise complexity justifies a custom quote. A single-location practice with four destinations does not.

Implementation quoted as an estimate with no scope. Ask what happens if setup takes longer than estimated, and who pays.

No written answer on data export. A vendor that is comfortable with your exit is a vendor confident you will not want one.

Frequently asked questions

Is usage-based pricing always worse?

No. For low-traffic sites with modest growth it can be the cheapest option, and it aligns cost to activity honestly. It becomes a problem when growth is the plan, when page views are billable, or when the same conversion is metered once per destination.

Should the BAA affect which tier we price from?

Yes. If a vendor signs a BAA only from the second tier upward, that tier is your actual entry price and the advertised entry price is not available to you. Compare from the lowest tier you can lawfully use.

How do we estimate event volume before we have a tracking system?

Use your existing analytics as a floor. Take monthly page views, add form submissions and other interactions, then add a margin, because server-side collection typically records more events than a client-side tool that ad blockers and browser tracking protection were suppressing.

Are implementation fees negotiable?

Often, especially against a longer term or a higher tier. The more useful negotiation is on scope: get the specific deliverables written down, including which destinations are configured and which events are mapped, rather than negotiating the number alone.

How much should we budget for internal engineering time?

It depends entirely on the vendor's model. Some products expect your developers to build and maintain the server-side layer, in which case engineering time is the dominant cost. Others handle setup and platform API changes for you. Ask directly which one you are buying, because the subscription price alone will not tell you.

Does cheaper server-side tracking mean weaker compliance?

Not necessarily, but compliance is a specific set of behaviors rather than a price point. Check for the concrete mechanisms: a signed BAA, per-destination field mapping with a deny-by-default posture, identifier hashing, and neutral event naming. Verify those exist rather than inferring them from cost.

Where to start

Before you take a single pricing call, pull your projected 12-month event volume and write down the destinations you run today plus the ones you expect to add. Those two facts turn every quote into a comparable number, and they prevent the most common outcome, which is buying for today's volume and renegotiating in month seven.

Then read the BAA. Its scope and its availability at your tier will tell you more about whether a vendor is built for healthcare than any feature list. Curve includes a signed BAA on every plan, prices in flat tiers rather than per event, and configures destinations and event mappings as part of onboarding. Run our free compliance scanner to see what your site is currently sending and to which third parties, read why client-side pixels create a HIPAA violation for the architectural background, or visit curvecompliance.com.

Reviewed August 2026. This is general information, not legal or procurement advice. Pricing structures change, so confirm current terms directly with any vendor you evaluate.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit