Tracking
Session replays
Watch how real visitors use your site — opt-in, off by default, with every form field masked and nothing stored in the visitor's browser.
Session replays play back a visit the way it happened: page layout, mouse movement, clicks, scrolling and page changes. They're built to keep VisitTrack's promise — cookieless, no personal data, no cookie banner — so they're opt-in and off by default, and privacy is enforced in the visitor's browser, before anything is sent.
Turn it on
- Open Settings → Replays for your site (members and admins only).
- Switch on Record session replays and pick the share of sessions to record — 20% by default, anything from 1% to 100%.
- Save. Nothing changes in your script tag: the tracker you already installed picks it up on the next page load.
Recordings appear in the Replays tab a few seconds after a sampled visitor has spent 5 seconds on your site. From a visitor's profile in Users, each recorded session has a Watch replay link, and Journeys links to the replays that start on the page you're looking at.
How it loads
tracker.js doesn't contain a recorder and doesn't grow. When the first pageview of a visit reaches our server, it answers with a signed, short-lived token only if your site has replays on, the visit isn't classified as a bot, and the visit falls in the sampled share. Only then does the tracker load replay.js (about 24 KB gzipped, built on the open-source rrweb recorder). Every other visitor — and every visitor on sites without replays — never downloads it.
- Bots and automated browsers are never recorded — anything classified as a bot, and any browser reporting
navigator.webdriver. - Short visits are skipped — a visit that leaves within its first 5 seconds is never uploaded.
- Every session is capped — at 30 minutes and about 4 MB compressed; the recording stops there.
- Sampling is per session, so a sampled visit is recorded across all its pages and an unsampled one never is.
What's recorded — and what isn't
| Recorded | Never recorded |
|---|---|
| Page structure and styles, as they render | Anything typed into an input, textarea or select — always masked |
| Mouse movement, clicks, scrolling, viewport size | Passwords, emails, card numbers — masked like every other field |
| Page changes (path only) | Query strings and #fragments of page URLs |
| Visible page text (unless you mask it) | Content of blocked elements, iframes, video, audio and canvas |
| Network requests, console logs, fonts, cookies, local storage |
Nothing is stored in the visitor's browser
The recorder writes no cookies and nothing to localStorage or sessionStorage. The only link between a recording and a visit is the signed token our server issued for that session — so replays work the same in cookieless mode.
Mask or block your own elements
Form fields are always masked. Page text — a customer's name on an account page, an order summary — is recorded unless you mask it. Two attributes cover it in your markup:
<!-- Masked: the text is replaced with asterisks, layout stays visible -->
<div class="account-name" data-vt-mask>Jane Doe</div>
<!-- Blocked: recorded as an empty box of the same size, content never leaves the page -->
<section data-vt-block>
...billing details...
</section>No access to the markup? Add CSS selectors in Settings → Replays — *Block these elements* and *Mask text in these elements*, comma-separated (for example .customer-name, #billing-panel). Or switch on Mask all text to replace every piece of text on every page with asterisks while keeping layout, clicks and scrolling.
Retention and deletion
- Recordings are deleted automatically after 30 days, on every plan.
- Settings → Replays → Delete all recordings removes every recording for the site immediately.
- Turning replays off stops new recordings at once — a recorder already running on a page stops at its next upload.
- Deleting a site deletes its recordings.
- Replays are stored on VisitTrack's own infrastructure and are visible only to your team — never on a public dashboard.
- Replays never count toward your plan's event usage.
Your privacy notice
VisitTrack masks form fields and never records what visitors type, but page text you haven't masked can appear in a recording. If your pages show personal data, mask those elements, and mention session recording in your own privacy notice.
Something missing? Tell us.
AI agent or LLM? Read this page as markdown.