How it works
Ordinary tracking gives each browser a random id, saves it on the device and reads it back at the next visit. Cookieless tracking skips the saving. For each request it combines a few things the request already contains, typically the network address and the browser's description, with a secret value that changes every day, and runs them through a one-way hash. The result is used as the visitor's id for that day and then discarded.
Because the secret rotates, the same person gets a different, unrelated hash tomorrow. Nobody can use the stored hashes to follow a person from day to day or from one site to another. In trckable only today's and yesterday's secrets are kept, the network address itself is not stored, and the region and city are dropped; the country stays.
What you give up
Not recognising a returning visitor has consequences, and a tool should say so where the numbers are.
- A unique visitor is new each day, so multi-day totals run higher than they would with an id.
- Journeys across days and new-versus-returning are not available.
- A session cannot cross the day boundary.
- Revenue attribution works within a day: a sale can be credited only to a visit from the same day. If your customers decide in one sitting, that may be enough. If they take days, you may want the cookie, with consent.
What it does not settle
Cookieless is often described as "no consent needed". That is too strong. The ePrivacy rules cover reading information from a device as well as storing it, and European regulators have said that the scope includes more than cookies. A script that sends the page address, referrer, screen size and language is reading the device. Whether that needs consent depends on the country and on the conditions of any exemption there. Our guide to cookie banners for analytics sets this out country by country.
What cookieless does do is remove the storage, shrink the personal data involved, and make the remaining question smaller and easier to answer.
When to choose it
Pick cookieless when you value the simplicity: nothing to ask, nothing stored, little to explain in a privacy notice, and counts that are right within a day. Keep a stored id, with consent, when you need multi-day behaviour, such as retention or long sales cycles. Many sites are well served by cookieless alone.
How to check a tool's claim
Open your browser's storage panel on a page with the script running and see whether anything was written. Read the tool's description of how its hash is made and how often the secret changes. Ask whether the setting is enforced on the server or only in the script, since a script cached in someone's browser could keep sending an old id. These three checks tell you more than the word "cookieless" on a pricing page.
Try it in trckable
Cookieless mode is one switch in the site's settings. It applies to every visitor wherever they live, and the server enforces it. Read the cookieless guide
Related terms
Read more
The newsletter
Notes on measuring what matters.
Occasional emails from Albi: new posts, one chart worth reading, what changed in trckable.
We send one email to confirm your address, and nothing more until you confirm. Every newsletter has a link to leave. What we keep, and who sends it: privacy.