Glossary · Privacy & compliance
What is browser fingerprinting?
Browser fingerprinting is a technique that identifies or tracks a device by combining many of its observable characteristics — user agent, screen size, installed fonts, time zone, graphics hardware, audio and canvas rendering — into an identifier that persists without cookies.
Also called: Device fingerprinting, Fingerprinting
Updated
How does fingerprinting work?
fingerprint = hash(user agent + screen + fonts + time zone + language + canvas + WebGL + audio + …)
A script reads dozens of attributes and hashes them into an id. Each attribute is common on its own, but the combination is often unique: research such as the EFF's Panopticlick and later Cover Your Tracks projects found most browsers tested were uniquely identifiable. Canvas and WebGL fingerprinting render hidden images and measure tiny hardware-specific differences.
Why fingerprinting is controversial
- Users can't see or clear it the way they clear cookies.
- It works across sites and survives private browsing.
- Under the EU's ePrivacy rules, reading device information to identify someone generally needs consent, just like a cookie; regulators including the UK's ICO have criticized fingerprinting for tracking as unfair to users.
- Google's ads platform policy began permitting fingerprinting techniques in February 2025, a change the ICO publicly called irresponsible.
How browsers defend against it
Safari reduces the attributes it exposes and, since Safari 17, adds Advanced Fingerprinting Protection in private browsing. Firefox blocks known fingerprinting scripts by default and adds further protections in its strict mode. Brave randomizes many values per site and session. Chrome limits some high-entropy data through user-agent reduction.
Fingerprinting vs other identification methods
| Method | Stored on device | Lasts | Cross-site |
|---|---|---|---|
| Third-party cookie | Yes | Until cleared/expired | Yes |
| First-party cookie | Yes | Until cleared (Safari caps some at 7 days) | No |
| Fingerprint | No | Until attributes change | Yes |
| Daily-salted server hash | No | 24 hours | No |
Does VisitTrack use fingerprinting?
No. VisitTrack doesn't build device fingerprints. To tell humans from bots, the script sends a handful of browser signals once per visit (whether webdriver is on, language and plugin counts, core count, memory, screen size, time zone); they're used for the human-or-bot verdict and thrown away, never stored, so they can't become a fingerprint — see bot filtering. The cookieless visitor id is a server-side hash with a salt that changes daily, so it can't follow anyone across days or sites.
Frequently asked questions
Is browser fingerprinting legal?
It depends on the jurisdiction and purpose. In the EU and UK, fingerprinting to identify or track users generally requires consent under ePrivacy rules and must comply with data protection law; using it to bypass a refusal of cookies is particularly risky.
Can you block browser fingerprinting?
Partly. Firefox, Safari and Brave include fingerprinting protections, and privacy extensions block many known scripts, but no browser fully prevents it. Using a common, up-to-date browser configuration also helps.
Related terms
- Cookieless trackingCookieless tracking is web analytics that counts visitors without storing any identifier on the visitor's device — no cookies, localStorage or similar — typically by deriving a short-lived anonymous id on the server instead.
- User agentA user agent is the text string a browser, app or bot sends in the User-Agent HTTP header to identify its software, version and platform to the server it's requesting from.
- First-party vs third-party cookiesA first-party cookie is set by the website you are visiting, under its own domain; a third-party cookie is set by a different domain embedded in that page — such as an ad network or social widget — and can follow you across every site that embeds it.
- Bot trafficBot traffic is any website visit made by automated software rather than a person — search crawlers, AI crawlers, uptime monitors, scrapers, headless browsers and spam bots.
- ePrivacy DirectiveThe ePrivacy Directive (Directive 2002/58/EC, amended in 2009) is the EU law on privacy in electronic communications whose Article 5(3) requires consent before storing information on, or reading it from, a user's device — which is why it's called the "cookie law."
Tools and guides
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.