Glossary · Privacy & compliance

What is browser fingerprinting?

Browser fingerprinting is a technique that identifies or tracks a device by combining many of its observable characteristics — user agent, screen size, installed fonts, time zone, graphics hardware, audio and canvas rendering — into an identifier that persists without cookies.

Also called: Device fingerprinting, Fingerprinting

Updated

How does fingerprinting work?

fingerprint = hash(user agent + screen + fonts + time zone + language + canvas + WebGL + audio + …)

A script reads dozens of attributes and hashes them into an id. Each attribute is common on its own, but the combination is often unique: research such as the EFF's Panopticlick and later Cover Your Tracks projects found most browsers tested were uniquely identifiable. Canvas and WebGL fingerprinting render hidden images and measure tiny hardware-specific differences.

Why fingerprinting is controversial

  • Users can't see or clear it the way they clear cookies.
  • It works across sites and survives private browsing.
  • Under the EU's ePrivacy rules, reading device information to identify someone generally needs consent, just like a cookie; regulators including the UK's ICO have criticized fingerprinting for tracking as unfair to users.
  • Google's ads platform policy began permitting fingerprinting techniques in February 2025, a change the ICO publicly called irresponsible.

How browsers defend against it

Safari reduces the attributes it exposes and, since Safari 17, adds Advanced Fingerprinting Protection in private browsing. Firefox blocks known fingerprinting scripts by default and adds further protections in its strict mode. Brave randomizes many values per site and session. Chrome limits some high-entropy data through user-agent reduction.

Fingerprinting vs other identification methods

MethodStored on deviceLastsCross-site
Third-party cookieYesUntil cleared/expiredYes
First-party cookieYesUntil cleared (Safari caps some at 7 days)No
FingerprintNoUntil attributes changeYes
Daily-salted server hashNo24 hoursNo

Does VisitTrack use fingerprinting?

No. VisitTrack doesn't build device fingerprints. To tell humans from bots, the script sends a handful of browser signals once per visit (whether webdriver is on, language and plugin counts, core count, memory, screen size, time zone); they're used for the human-or-bot verdict and thrown away, never stored, so they can't become a fingerprint — see bot filtering. The cookieless visitor id is a server-side hash with a salt that changes daily, so it can't follow anyone across days or sites.

Frequently asked questions

Is browser fingerprinting legal?

It depends on the jurisdiction and purpose. In the EU and UK, fingerprinting to identify or track users generally requires consent under ePrivacy rules and must comply with data protection law; using it to bypass a refusal of cookies is particularly risky.

Can you block browser fingerprinting?

Partly. Firefox, Safari and Brave include fingerprinting protections, and privacy extensions block many known scripts, but no browser fully prevents it. Using a common, up-to-date browser configuration also helps.

Related terms

Tools and guides

See which channels actually bring paying customers

VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.