Alice manufactures a product
- She displays the product info here:
alice.com/product-001 - She has set a button
[Purchase now]pointing to the checkout page.
Bob runs a checkout service
- Alice has contracted his services.
- Alice has configured product 001 in Bob's service
- Bob's system creates 2 relevant URLs:
- To initiate checkout:
bob.com/pay/product-001 - The thank-you page:
bob.com/thank-you/product-001
- To initiate checkout:
Charlie is an affiliate for this product
- Charlie has a Google Tag Manager with ID
GTM-999999 - Charlie agrees with Alice and Bob that his
affiliateIdwill be777. - Charlie wants to track the sales funnel at the 3 pages (product + checkout-init + checkout-complete) to optimize his budget.
- Both Alice and Bob agree to receive the affiliate ID in the URL.
- If
?affiliateId=777is added to any of the 3 pages, then Alice and Bob will display the tagGTM-999999along with their own GTMs if already in place.
This enables Charlie to send "pixel trackers" (*) to the pages. He can send the trackers of Facebook, Twitter, Google Analyics, etc. at his own will; as well as any other "pixel" he creates himself.
(*) We all know that the "pixel" name comes from the ancient times when we set a 1x1 transparent image. But now it's not an image. It's a javascript and therefore much more powerful. But also dangerous.
Question
If Alice and Bob render Charlie's GTM... will Charlie be able to inject ANY javascript at will (for example one for spying third-party cookies or re-rendering visible blocks of the page, or crawling the DOM to discover emails rendered there)? Or GTM "filters out" what can be sent or not to the browser?