New · A dedicated AI SEO channel: see conversions from ChatGPT, Perplexity, Claude & Gemini →
← Blog
Part of: SEO Conversion Tracking: Measure Conversions and Value from Organic Search →

Cookieless Tracking: How It Works, Methods, Consent and Accuracy

Portrait of Samy ThuillierBy ··12 min read
Diagram of cookieless tracking connecting a visit, landing page and conversion without a browser cookie

Cookieless tracking measures what visitors do on your site without storing an identifier in a cookie on their device. Instead, the visit is tied together on the server, with a short-lived hash of request details, a session-only ID, server-side event collection or a login ID. It counts visits, sources and conversions well, and counts unique people only approximately.

That last sentence is the whole trade. This guide covers how each method identifies a visitor, what you gain and lose, when consent still applies, how to pick a tool, and how to check your numbers after you switch, including a worked example and a debugging table that most guides skip.

Cookieless tracking in 30 seconds
  • No identifier is written to the browser, so there is nothing for the visitor, a private window or a browser cap to delete.
  • Visits, pageviews, sources, landing pages and conversion rates stay reliable.
  • Unique visitors, returning visitors, cross-device journeys and long attribution windows get weaker.
  • “Cookieless” does not mean anonymous or consent-free. The method and the data decide that.

What cookieless tracking means

A classic analytics tag writes a random ID into a first-party cookie the first time you visit. Every later pageview reads that ID back, so the tool can say “this is the same browser as last Tuesday.” Ad tech went further with third-party cookies, set by a vendor domain embedded on many sites, which let one company follow a browser across the web.

Cookieless tracking removes the stored ID. Two things are worth separating:

  • Cookieless analytics: measuring your own site without cookies. This is what Plausible, Fathom, Matomo’s cookieless mode and similar tools do.
  • Cookieless advertising: targeting and measuring ads without third-party cookies, through first-party data, contextual targeting, clean rooms, shared IDs and server-to-server conversion APIs.

They share a name but solve different problems. Most of this article is about the first, since that is where you control the setup. The advertising side gets its own section below.

Why teams move to cookieless tracking

Cookie-based measurement loses data in four ways, and none of them depends on a single deadline:

  • Browser limits. Safari’s Intelligent Tracking Prevention deletes cookies created in JavaScript, and all other script-writeable storage, after 7 days without user interaction with the site, and caps them at 24 hours when the visitor arrives through a decorated link, per WebKit’s tracking prevention documentation. A weekly visitor on Safari can look like a new person every time.
  • Consent refusal. Where a banner gates analytics cookies, visitors who decline are not counted by a tag that waits for consent.
  • Blockers and privacy tools. Extensions and privacy browsers block known tracking scripts and cookies.
  • Clearing and private windows. Anyone who clears site data or browses privately resets their ID.

What changed with Chrome (the sources disagree)

Several top-ranking guides still say Chrome is phasing out third-party cookies. That is out of date. In its October 17, 2025 Privacy Sandbox update, Google said Chrome will maintain its current approach of offering users third-party cookie choice. So the pressure to go cookieless comes from Safari and Firefox defaults, consent rules, blockers and user behavior, not from a Chrome shutdown date. Third-party cookies in Chrome mostly matter to advertisers anyway; first-party analytics cookies were never in scope of that plan.

How cookieless tracking works: the five methods

Every analytics tool has to answer one question: are these two pageviews from the same visitor? Cookieless tools answer it in one of five ways. The vendor label matters less than which of these it actually uses.

1. Server-derived hash

The browser sends a hit. The server takes data that already arrives with every request, mainly the IP address and the user agent, adds the site domain and a secret salt, and runs a one-way hash. The raw IP is discarded and the event is stored against the hash. Tools that rotate the salt daily make the same person look new the next day by design. Hash inputs and rotation period vary by vendor, so ask.

2. Session-only identifier

The script holds a random ID in page memory for the length of one visit and never writes it to the device. Pageviews, clicks and form submits within that visit are tied together. When the tab closes, the ID is gone. This is the cleanest option for conversion reporting, because source, landing page and conversion all sit in the same session.

3. Server-side collection

Events are sent from your server, or from a server container on your own subdomain, instead of straight from the browser to vendors. This is how postbacks, conversion APIs and server-side GTM work. Server-side is about where data flows, not about cookies: many server-side setups still set a first-party cookie (for example a first-party device ID, the “FPID cookie” you see in related searches). It is only cookieless if the identifier it uses is.

4. Login or customer ID

When a visitor signs in, your own user ID identifies them across sessions and devices. It is exact, but only for signed-in users, and the session that carries it usually needs a login cookie, which is strictly necessary for the service rather than for tracking. This is the method behind “cookieless tracking login” searches and CRM-based identity resolution.

5. Fingerprinting

The script collects screen size, fonts, timezone, plugins, canvas output and similar traits, and hashes them into a device ID. Nothing is stored, but the visitor also cannot see, clear or refuse it. Regulators treat it as tracking, and it tends to persist across sites. Some vendors call this cookieless; it is closer to a cookie the user cannot delete. Avoid it for analytics.

MethodWrites to device?IdentifiesGood forWeak at
Server-derived hashNoA browser for a short window (often a day)Visits, sources, rough unique countsReturning visitors, multi-day journeys
Session-only IDNoOne visitConversions and landing page attributionAnything across visits
Server-side collectionOnly if it sets a cookieWhatever ID you feed itData control, ad conversion APIsNot cookieless on its own
Login / customer IDLogin cookie onlyA person, across devicesSigned-in products, CRM matchingAnonymous visitors
FingerprintingNoA device, often across sitesFraud and bot detectionPrivacy, consent, fairness

One method that is not on this list: swapping the cookie for localStorage or sessionStorage. Both write to the device just like a cookie, and Safari’s 7-day rule deletes script-writeable storage too. It changes the storage API, not the privacy or legal picture.

What you gain and what you lose

Metric or useCookie-basedCookieless
Visits and pageviewsMissing declined, blocked and expired visitorsClose to complete (blockers still apply)
Traffic sources and landing pagesReliable for counted visitsReliable
Conversions in the same sessionReliable for counted visitsReliable
Unique visitorsInflated by cleared and expired cookiesEstimate: shared networks merge people, network changes split them
Returning visitors and retentionPossible until the cookie goesWeak or impossible beyond the hash window
Cross-device journeysOnly with loginOnly with login
Multi-touch attributionPossible, already leakyLimited to what one session or login shows
Retargeting audiencesPossibleNot possible without an ad platform ID

The practical upshot: if your decisions run on sources, landing pages and conversions, cookieless tracking is usually as good or better. If they run on user-level journeys over weeks, you need logins or a consented cookie for that part.

How accurate is cookieless tracking?

Accuracy depends on which number you look at:

  • Visits and events: accurate, often more complete than a consent-gated tag, because nobody is excluded for declining a banner.
  • Unique visitors: an estimate that errs both ways. Several people in one office on the same browser version can collapse into one hash. One person moving from Wi-Fi to mobile data, or updating the browser, can become two.
  • Returning visitors: limited to the hash window. With a daily rotating salt, every day starts from zero.
  • Conversion attribution: accurate within the session, blind across visits. A visitor who finds you through search on Monday and comes back by typing your URL on Friday converts as Direct.

Treat unique-visitor numbers as a trend line, not a headcount, and build your reporting on sessions and conversions.

Does cookieless tracking need consent?

Sometimes. Vendor pages that promise “no banner needed, anywhere” and consent vendors that call cookieless a myth both overstate it. Two separate questions apply in the EU and UK:

  • Device access rules (ePrivacy). The rule covers storing or reading information on the visitor’s device, not just cookies. A script that reads device properties can be in scope even if it stores nothing. Some countries allow narrow exemptions for first-party audience measurement under strict conditions.
  • Data protection (GDPR). A hash of IP and user agent is pseudonymous, not anonymous, so it is usually still personal data and needs a lawful basis. Aggregate counting is easier to justify than per-visitor profiles.

Outside Europe, US state privacy laws mostly focus on the sale and sharing of personal data rather than on device storage, and some require you to honor opt-out signals such as Global Privacy Control. This is not legal advice: check your own method, data and visitor locations with counsel.

Google’s own cookieless mode: consent mode pings

If you use GA4, you may already send cookieless data without knowing it. Google’s consent mode documentation describes two setups:

Basic consent modeAdvanced consent mode
Before the visitor choosesGoogle tags do not load; nothing is sentTags load with consent defaulted to denied
If the visitor declinesNothing is sentCookieless pings are sent
What a ping carriesn/aTimestamp, user agent, referrer, consent state, a random number per page load, and whether an ad-click ID is in the URL
What GA4 does with itGeneral modelingAdvertiser-specific modeling of conversions and behavior

Two consequences. First, GA4 numbers for declined visitors are modeled, not observed, so they will never match a cookieless tool exactly. Second, advanced mode still sends data when someone declines, so it belongs in your consent review, not around it.

Which method fits which job

Pick by the decision you need to make, not by the label on the tool:

JobGood fitWhy
Traffic and content reportingServer-derived hashCounts every visit, rough uniques are enough
Conversions and value by channel or landing pageSession-only ID, plus server-side for purchasesSource, page and conversion live in one session
Ad platform optimizationServer-side conversion APIs with consented first-party dataPlatforms need their own click or customer IDs
RetargetingConsented cookies or customer listsRequires recognizing a person later; cookieless cannot
Product analytics for signed-in usersLogin IDExact across sessions and devices
Long B2B journeysLogin ID or CRM matching, plus self-reported sourceSessions alone miss the first touch

Cookieless advertising vs cookieless analytics

On the advertising side, “cookieless” usually means a mix of these:

  • First-party data: emails, accounts and purchase history you collect directly, uploaded to ad platforms as customer lists.
  • Conversion APIs: your server reports conversions to Meta, Google and others, often with hashed customer details, instead of relying on a browser pixel.
  • Contextual targeting: ads matched to the page topic instead of the person.
  • Clean rooms and shared IDs: controlled environments or common identifiers for matching data between companies.

These rely on identity, so they need consent where the law requires it. A cookieless analytics tool will not replace them, and they will not replace honest site analytics.

Worked example: what changes in your reports

All numbers here are illustrative. A B2B site gets 10,000 organic search sessions a month. It shows a cookie banner, 60% of visitors accept, and GA4 runs in basic consent mode. The team runs a cookieless tool in parallel for a month.

One month, organic search only (illustrative)
GA4 (consented visitors only): 6,000 sessions, 120 demo requests, 2.0% conversion rate
Cookieless tool (all visitors): 10,000 sessions, 190 demo requests, 1.9% conversion rate
CRM: 196 demo requests from forms with organic as the recorded source

Three things to read from this:

  • Volume went up, rate barely moved. The cookieless tool saw 70 more requests, because visitors who declined the banner also convert. The rate is slightly lower because the extra 4,000 sessions include more quick visits that never had a chance to convert. Do not read 2.0% to 1.9% as a drop in performance.
  • The CRM is the referee. 190 of 196 is 97% coverage. The 6 missing are most likely blocked scripts or visitors who left and came back on another visit, which session-scoped tracking credits to Direct.
  • Value follows the landing page. If a demo request is worth $80 (see how to calculate conversion value), the month is worth 190 × $80 = $15,200, and the split shows where it comes from:
Organic landing pageSessionsDemo requestsConv. rateValue at $80
/pricing2,000703.5%$5,600
/guides/setup6,000601.0%$4,800
/compare/alternatives2,000603.0%$4,800
Total10,0001901.9%$15,200
Value per 1,000 sessions = value ÷ sessions × 1,000 → /pricing $2,800, /guides/setup $800, /compare $2,400

The guide brings the most traffic but the least value per visit, and none of that required recognizing anyone across visits. For more on reading this table, see landing page conversion rate and our guide to cookieless conversion tracking for SEO.

Debugging a parallel run: why the numbers disagree

Run old and new tools side by side for at least two full weeks. Expect differences; the job is to explain each one. Compare sessions and conversions, never “users”, because the two tools define a user differently.

SymptomLikely causeCheckFix
Cookieless sessions far above GA4Consent gating in GA4, or bots counted by the new toolCompare against your banner acceptance rate; check user agents of top hitsExpected if near the decline share; otherwise enable bot filtering
Cookieless sessions below GA4Script blocked, loaded late, or missing on some templatesView source on each template; test with a blocker onLoad the script in the head on every page; use a first-party path if offered
Single-page app shows one pageview per visitRoute changes not trackedClick through the app with the network tab openEnable history or route-change tracking
Conversions doubledForm submit and thank-you page both counted, or tag fires twiceSubmit a test form and count the requestsKeep one conversion definition per action
Too much Direct trafficReferrer stripped by redirects, apps or a strict referrer policyCheck landing URLs for redirects; test from an app linkFix redirects; tag your own links with UTM parameters
Unique visitors far apartDifferent definitions (cookie lifetime vs hash window)Compare sessions insteadStop reporting uniques as a headline metric

How to switch to cookieless tracking

  1. Record a baseline. Last full month of sessions, conversions, conversion rate and revenue by source and landing page, plus the matching CRM or order count.
  2. Decide what you still need cookies or logins for. Use the job table above. Retargeting and long user journeys may keep a consented setup.
  3. Install the new script and define conversions. Forms, calls, email clicks, signups and purchases, each with a value.
  4. Run in parallel and debug. Two weeks minimum, reconciled against the CRM.
  5. Update your banner and privacy notice. Describe what the new tool collects. Whether it can run outside the banner is a legal call for your jurisdictions.
  6. Change what you report. Lead with sessions, conversions and value by channel and landing page. Annotate the switch date so nobody reads the jump as growth.

How to evaluate a cookieless tracking tool

Ask every vendor the same questions and expect written answers:

  • Which of the five methods do you use, and what are the exact hash inputs?
  • How long does one visitor keep the same identifier, and what resets it?
  • Do you write anything to the device for any feature (A/B tests, chat, feature flags)?
  • Do you read device properties beyond the request headers?
  • Is the raw IP stored, truncated or discarded, and where is data hosted?
  • Can you track conversions with a value and report them by source and landing page?
  • Do you honor Global Privacy Control and Do Not Track?
  • How do you filter bots?

Tools fall into rough groups: lightweight traffic analytics (Plausible, Fathom, Simple Analytics), configurable suites with a cookieless mode (Matomo, which uses cookies by default), product analytics with daily hashes, server-side tag platforms, and conversion-focused trackers. For the conversion end, SEOConversion is a first-party, cookieless tracker that reports conversions and their value from Google, Bing and AI assistants by landing page, and honors GPC and DNT. Our marketing attribution tools guide covers how to test any of them.

Checking tracking cookies yourself

People Also Ask on this query is full of visitor-side questions. Here is the short version, which also helps you audit your own site.

See which cookies a site sets

  1. In Chrome or Edge, open the site, press F12 and go to Application, then Storage, then Cookies.
  2. In Firefox, press F12 and open the Storage tab. In Safari, enable the Develop menu, then open Web Inspector and go to Storage.
  3. Look at the domain column. Cookies from your own domain are first-party; any other domain is third-party. Long expiry dates and random ID values signal tracking.
  4. Check Local Storage too, since some “cookieless” scripts move the ID there.

Turn cookies off or clear them

Every major browser has a privacy section in settings where you can block third-party cookies, block all cookies (which breaks logins and carts), or clear cookies and site data for one site or all of them. To audit a cookieless claim on your own site, clear everything, reload and confirm no new identifier appears.

Cookieless tracking is one piece of a measurement setup. For the full picture of tying organic visits to leads and revenue, start with SEO conversion tracking.

FAQ

Are cookies tracking?

Some are, most are not. Many cookies keep you logged in, hold a cart or remember a language. A cookie becomes a tracking cookie when it stores an identifier used to recognize you across visits or across sites, usually for analytics or advertising. Third-party cookies set by ad and data vendors are the ones built for cross-site tracking.

Does GDPR require cookie consent?

The consent rule for cookies comes mainly from the ePrivacy rules, with GDPR setting what valid consent means. Storing or reading information on a visitor’s device needs consent unless it is strictly necessary for the service they asked for, and some countries add narrow exemptions for audience measurement. Removing cookies does not settle the question by itself, because the rule covers other ways of reading device information too. Get legal advice for your setup.

How do I get rid of a tracking cookie?

Open your browser’s privacy settings and clear cookies and site data, either for all sites or for the one site you care about. To stop new ones, block third-party cookies in the same settings. Clearing a cookie only removes that identifier; it does nothing against server-side hashing or fingerprinting.

How can I browse privately without being tracked?

A private window drops cookies when you close it, but sites still see your IP address and browser details during the session. Blocking third-party cookies, using a browser with tracking protection, turning on Global Privacy Control and using a tracker-blocking extension together cut most tracking. No setting makes you invisible to the site you are visiting.

Is cookieless tracking legal?

It can be, but legality depends on what data you collect and where your visitors are, not on the absence of cookies. A one-way hash of IP and user agent is still usually personal data under GDPR. Fingerprinting draws the most regulatory objection. Review the method, the data and the jurisdiction with counsel.

Is there a cookieless tracking app for mobile?

Native mobile apps do not use browser cookies at all, so “cookieless” is the normal state there. Apps rely on device or app instance identifiers and on login-based IDs, which raise their own consent and platform rules. Web tools marketed as cookieless are about browsers, not apps.

Track conversions without cookies, by landing page.

SEOConversion is a first-party, cookieless tracker that shows which conversions and how much value come from Google, Bing and AI assistants, per landing page. One script, and it honors GPC and DNT.

Start free