Glossary · Privacy & compliance
What is cookieless tracking?
Cookieless tracking is web analytics that counts visitors without storing any identifier on the visitor's device — no cookies, localStorage or similar — typically by deriving a short-lived anonymous id on the server instead.
It exists mainly because of the EU's ePrivacy Directive: storing or reading an identifier on someone's device generally needs consent, so analytics that stores nothing can often run without a consent banner.
Also called: Cookie-free analytics, Cookieless analytics
Updated
How does cookieless tracking work?
visitor id = hash(site id + IP address + user agent + daily secret salt)
The most common approach, used by several privacy-focused tools, computes a one-way hash on the server from the site, the visitor's IP address and user agent, and a secret salt that rotates every 24 hours. The same browser gets the same id for the rest of the day, so unique visitors and sessions work within a day. When the salt rotates, the old one is deleted and yesterday's ids can't be linked to today's. The IP and user agent are used as inputs and not stored.
What you give up without cookies
| Metric | With a first-party id | Cookieless (daily hash) |
|---|---|---|
| Pageviews, sources, pages, countries, devices | Full | Full |
| Unique visitors within a day | Full | Full (people sharing an IP and browser can merge) |
| Returning visitors, retention | Full | Anyone returning after 24h counts as new |
| Multi-day journeys and attribution | Full | Same day only, unless your app stores the first touch |
| Cross-domain tracking | Supported | Not available |
Cookieless tracking example
Someone reads your blog on Monday from a Google search and signs up on Thursday after typing your URL. With a first-party id, the sign-up is credited to Google. With cookieless tracking, Thursday's visit is a new visitor, and the sign-up is credited to Direct — unless your sign-up form captured Monday's source and sent it back. Weekly unique visitors will also read higher than with cookies, since the same person counts once per day.
Do you need a cookie banner with cookieless analytics?
Often not, under the ePrivacy consent rule, because nothing is stored on or read from the device for identification. But GDPR still applies: the IP address is personal data while it's being hashed, so you need a lawful basis (usually legitimate interests) and a privacy-policy mention. The EDPB's Guidelines 2/2023 take a broad view of what counts as accessing a device, so check with counsel for your situation. This is general information, not legal advice.
How VisitTrack does cookieless tracking
VisitTrack offers three modes. Standard keeps an anonymous first-party id for multi-day accuracy. Cookieless writes no cookie, localStorage or sessionStorage entry and derives the visitor id from a hash of the site, IP and user agent with a salt that changes daily (UTC); the IP is never stored. Hybrid is cookieless for visitors in the EU/EEA, UK and Switzerland and standard elsewhere. To keep first-touch attribution across days without cookies, your app can store window.visitrack.attribution() at sign-up and send it back. Bot filtering works the same in every mode. Full details in cookieless mode.
Frequently asked questions
Is cookieless tracking GDPR compliant?
It can be, but cookieless doesn't mean GDPR doesn't apply. Hashing an IP address is still processing personal data, so you need a lawful basis such as legitimate interests and a mention in your privacy policy. What cookieless tracking mainly avoids is the ePrivacy consent requirement for storing identifiers on the device.
How accurate is cookieless analytics?
Pageviews, sources, pages and same-day unique visitors are as accurate as with cookies. Returning visitors, retention and multi-day attribution are limited, because the same person gets a new id each day.
Does cookieless tracking use fingerprinting?
Not in the usual sense. Fingerprinting builds a stable, long-lived identifier from many device attributes. A daily-salted hash of IP and user agent changes every day, can't be linked across days or sites, and isn't stored on the device.
Related terms
- First-party vs third-party cookiesA first-party cookie is set by the website you are visiting, under its own domain; a third-party cookie is set by a different domain embedded in that page — such as an ad network or social widget — and can follow you across every site that embeds it.
- Consent bannerA consent banner, or cookie banner, is the notice a website shows to ask visitors for permission before storing or reading non-essential cookies and similar identifiers on their device, and to record their choice.
- ePrivacy DirectiveThe ePrivacy Directive (Directive 2002/58/EC, amended in 2009) is the EU law on privacy in electronic communications whose Article 5(3) requires consent before storing information on, or reading it from, a user's device — which is why it's called the "cookie law."
- GDPRGDPR, the General Data Protection Regulation (Regulation (EU) 2016/679), is the European Union law that governs how personal data about people in the EU is collected, used and stored, in force since May 25, 2018.
- Browser fingerprintingBrowser fingerprinting is a technique that identifies or tracks a device by combining many of its observable characteristics — user agent, screen size, installed fonts, time zone, graphics hardware, audio and canvas rendering — into an identifier that persists without cookies.
- IP anonymizationIP anonymization is the practice of removing, truncating or otherwise obscuring a visitor's IP address in an analytics or logging system so the stored data can't be traced back to a specific connection.
Tools and guides
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.