Open your Google Tag Manager container and look for a tag named after an agency you stopped paying two years ago. It is still there. It still fires on every page load. Shopify sunset the additional scripts box on the Thank you and Order status pages on 28 August 2025. Plenty of those old snippets moved into the container rather than into the bin.
A tag is a piece of code that Google Tag Manager drops into your store. A container is the box that holds them all. A ghost tag is one whose owner has left, whose job nobody can state, and which nobody will delete. CPA, your cost per acquisition, is what you pay in ads for one new customer.
The short answer. Ghost tags inflate your cost per acquisition by reporting the same sale twice. Your dashboard shows double the return, so you raise budget on a number the bank never confirms. Google Tag Manager governance fixes that with one rule: every tag has a named owner, a stated job and a review date.
A container full of dead tags costs you budget, and it costs your week. Autonomous Technologies builds and runs the systems behind Shopify stores, for founders and operators who own the store after launch. Container cleanup is part of our analytics work because it is a spend decision, not a housekeeping task. You act on what the dashboard says. If the dashboard counts one sale twice, you spend twice.
Who this is for. You own a Shopify or Shopify Plus store. You or your team can log into Tag Manager. Several agencies have touched the container over the years. Who this is not for. Stores with one tag installed by a theme. Anyone who wants a compliance ruling, because your privacy counsel signs that off, not your analytics setup.
Nobody is ever paid to delete a tag, so the container only grows
Every new vendor arrives with a request: add this snippet. Nobody leaves with one. No agency sends a final email asking you to remove their tracking. So the container fills up.
That leaves names like Criteo_2021_DO_NOT_TOUCH sitting in a live container. The operations lead will not touch it, in case a revenue stream depends on it. The fear is fair. Leaving it alone is not safe either.
Google is plain about this. There is no hard limit on how many tags you can deploy. What Google does publish is a size indicator, a percentage showing how full the container is. Google’s guidance says: “If the Size indicator value is above 70%, you should take steps to optimize your container configuration.” An unused tag “is taking up space in your container unnecessarily”.
The old version of this article told you to worry past 50 tags. It also told you to watch for a warning at 98%. Neither number is in Google’s documentation. The published number is 70%, checked on 21 September 2026, and it measures size, not tag count.
| What you are checking | The vendor's figure | Source | Status |
|---|---|---|---|
| Container size indicator | 70% | Google Tag Manager Help | checked 21 Sep 2026 |
| Meta window for dropping a duplicate | 48 hours | Meta Conversions API docs | checked 21 Sep 2026 |
| Consent mode settings | 4, since November 2023 | Google tag platform docs | checked 21 Sep 2026 |
| Additional scripts, Thank you page | ended 28 August 2025 | shopify.dev | 1 year passed |
| Script tags, non-Plus stores | ended 26 August 2026 | shopify.dev | 3 weeks passed |
Two purchase tags turn one sale into two, and you scale on the gap
This is where the money leaves. An old Purchase tag from one agency and a new one from the next both fire on the same order confirmation. The ad platform receives two conversions for one sale.
Google Ads counting settings decide what happens next. On “Every conversion”, Google Ads “counts every conversion (per tracked conversion action) that happens after an ad interaction”. Both copies count. Return on ad spend is the revenue a platform credits to each dollar you spend. Two copies of one sale make it look roughly double.
| What you look at | Your Shopify admin | The ad platform |
|---|---|---|
| Sales that day | 1 order | 2 conversions |
| Conversions against reality | 100% | 200% |
| Reported return on ad spend | 2.0x | 4.0x |
Meta handles this differently, and only if you set it up. A pixel’s eventID has to match the Conversions API event_id. Meta then drops the copy, but only if it arrives “within 48 hours of when we receive the first event”. Miss the shared identifier and the duplicate stands.
Marketing data has a half-life. A tag that was accurate two years ago is likely inaccurate today. Governance is not a one-time clean-up, it is a standing discipline.Autonomous Technologies
The reverse failure is quieter and just as costly. That is the subject of signal loss in Facebook ads. Inflated data makes you spend more. Missing data makes you stop spending on something that works.
A tag you forgot still collects your customers’ data
Site speed is the boring reason to clean a container. The reason that should hold your attention is simpler. You are responsible for every script that runs on your domain.
Consent mode is how Google tells its tags what a visitor agreed to. It defines four settings: ad_storage, analytics_storage, ad_user_data and ad_personalization. Google’s own page notes that consent mode “was updated in November, 2023 and now contains two additional parameters”. It also warns that “consent mode doesn’t save consent choices”. Something else in your stack has to store the answer.
Shopify’s Customer Privacy API applies consent choices to Shopify surfaces, pixels included. It covers four purposes: preferences, analytics, marketing, and sale of data. A tag added outside that path does not inherit those choices.
Shopify is also direct about who carries the risk. Its custom pixels page says that “adding and using custom pixels is unsupported by Shopify”. It adds that “compliance with applicable laws, consents, code security, troubleshooting, and updates are your responsibility”. A dead vendor’s tag on your checkout is your exposure, not theirs.
If it has no owner, it dies. A tag with no named owner cannot be checked and cannot be defended. Do not pause it and hope. Write down who asked for it, what it sends, and the date you look at it again.
Three checks that take five minutes inside Tag Manager
You do not need a developer for the first pass. You need twenty minutes and the will to write names down.
Check the size indicator, not the tag count. Google’s threshold is 70%. Above that you are carrying weight you cannot justify. The fix starts with anything unused.
Read the tag names out loud. Names like “Facebook Pixel Copy” or “Update 2” tell you nobody documented a change. A workable rule is vendor, job, owner, date, on every tag from today.
Open the Overview page and look at unpublished changes. A workspace is a draft copy of the container. Edits sitting there for months are abandoned work. They are the first thing to surprise the next person who publishes.
Two checks in Admin that are security, not housekeeping
The Admin section is where governance exists or does not. Tag Manager permissions come in levels: Read, Edit, Approve and Publish on a container, plus User and Administrator on the account. Publish is the level that changes what runs on your store.
Check who still holds Publish. Former staff and former agencies turn up here constantly. Google’s page describes removing someone from the Container permissions list with Remove. Do that today for anyone off the project.
Check who is Administrator. Administrator can create containers and change permissions. That seat can restore the access you just removed. It belongs to you, or to someone whose employment you control.
Tag Manager also has a consent overview. It sorts tags into “Consent Not Configured” and “Consent Configured”. Read that list before you touch anything. It is the fastest map of which tags nobody ever thought about.
The old way is speed. The way that survives is ownership
Cleaning tags to shave load time is worth doing. It is not the argument that gets the work approved. The argument is that unowned code reports numbers you spend against, and collects data you answer for.
| The old way | The way that survives an audit |
|---|---|
| Focus: page load time | Focus: what the tag sends and who approved it |
| Rule: do not touch it if it works | Rule: no named owner, no tag |
| Metric: how many tags fire | Metric: how many tags have an owner and a review date |
| Outcome: a container everyone fears | Outcome: a container anyone can be handed |
Change control is the dull version of this, and it holds. A pull request is a proposed change that somebody has to approve before it goes live. Thirty-seven pull requests reached Sene’s order systems between 14 July and 8 September 2026, and a named person accepted every one. We wrote that up in the human gate on agent authored features. The same rule works on a tag container.
What breaks when you start deleting, and who owns it
The fear of the delete button is not irrational. Deleting the wrong tag can stop a live conversion feed. You find out in a weekly report, not an alert. Here is how to take that risk off the table.
Work in a new workspace, not the live container. Publish once, with a version name that says what you removed. Take one week of figures before and after: orders in Shopify, conversions in Google Ads, purchases in Events Manager. If the store number holds and a platform number moves, you removed something that was reporting.
Clean data is also what makes any outside team useful, which is the point of marketing data hygiene and client retention. Nobody can improve a campaign against a feed they cannot trust.
| What breaks | How you see it | Who owns it |
|---|---|---|
| A live conversion feed stops | Platform conversions fall, Shopify orders do not | Whoever publishes the container |
| Duplicate purchase tags survive | Reported return stays above what the bank shows | You, on the weekly number |
| A tag fires without consent | Nothing visible, until someone asks | You, with your privacy counsel |
| A former agency keeps Publish | Changes you did not request appear in versions | You, in Admin, today |
| Old snippets left in checkout code | Silence since 28 August 2025 on those pages | Your theme or checkout owner |
Common questions
How many tags is too many in one container?
Google publishes no maximum tag count. It publishes a size indicator, and says to optimise the container above 70%. Judge the container on whether every tag has an owner and a job. Tag count is not the measure.
Will deleting an old tag break my conversion tracking?
It can, so work in a new workspace and publish once with a named version. Compare one week of Shopify orders against platform conversions, before and after. If orders hold and a platform number drops, that tag was reporting something real.
How do duplicate tags actually raise my CPA?
They hide it rather than raise it. Two tags report one sale, so reported return looks roughly double. You raise budget on that number, and your real cost per acquisition climbs while the dashboard stays green.
Does consent mode remove the need to clean up tags?
No. Google states that consent mode does not save consent choices, so another system has to store and replay them. A tag nobody owns is still a tag nobody set consent for.
My old tracking lived in the Shopify additional scripts box. Where is it now?
Gone from the Thank you and Order status pages. Shopify sunset checkout.liquid and additional scripts there on 28 August 2025. Script tags ended for non-Plus stores on 26 August 2026. Anything custom now runs as a web pixel in Shopify’s sandbox.
Vendor documents checked on 21 September 2026. Google: container size and efficiency, Tag Manager permissions, consent settings in Tag Manager, consent mode parameters and Google Ads conversion counting. Shopify: custom pixels, the Customer Privacy API and checkout.liquid deprecation. Meta: deduplicating pixel and server events.



