Attribution without cookies: what you can and cannot know
An honest map of which attribution questions survive without cross-day visitor identity, which do not, and what each answer actually costs your visitors.
All posts
Most writing on this topic is either a vendor claiming nothing is lost, or a purist claiming attribution is impossible. Both are wrong, and the actual boundary is precise enough to draw.
The boundary
Attribution needs to connect a purchase to something that happened earlier. The only question that matters is how much earlier, because that determines how long the visitor must remain recognisable.
| Question | Identity needed | Works cookieless |
|---|---|---|
| Did revenue move with traffic this month? | None | Yes |
| Which channel produced this visit? | None | Yes |
| Which channel produced this sale, same visit? | Within one visit | Yes |
| Which channel produced this sale, three days later? | Across days | No |
| What was the first touch, six weeks ago? | Across weeks | No |
| How does this cohort retain over a year? | Across months | Only for signed-in users |
Everything above the line in that table is available with no cookie, no consent banner and no stored identifier. Everything below requires remembering a person across a gap, and that is what the consent rules exist to govern.
How cookieless recognition actually works
If nothing may be stored, identity has to be derived from the request itself:
- Take stable request attributes — website id, IP address, user agent, screen size, language.
- Hash them with a secret salt that rotates daily.
- Use the result as the visitor identifier for that window.
When the salt rotates, the old identifiers cannot be regenerated. Monday’s visitor and Friday’s cannot be linked, by anyone, including the vendor holding the data. That expiry is the point, not a limitation to be engineered around.
There is one refinement worth knowing: a visit in progress when the salt rotates would otherwise split into two visitors, so the previous salt is briefly consulted to stitch that single visit together. The window is short and deliberate, and it does not extend to a visitor returning the next day.
What you genuinely lose
Stated plainly, because vendors tend to bury this:
Returning visitors count as new. Someone who visits Monday and Friday is two visitors. Your visitor counts are inflated relative to a cookie-based tool, and your “returning visitor” rate is not measurable for anonymous traffic.
Long-window first-click attribution is unavailable. The podcast that introduced someone six weeks ago cannot be credited, because nothing links that visit to this purchase.
Anonymous long-horizon retention is unavailable. You can measure retention of signed-in users through their account, which is a first-party relationship rather than tracking. You cannot measure it for anonymous visitors.
What you keep, which is more than expected
Everything within a visit. Landing page, path through the site, funnel steps, time on page, and whether that visit converted.
All channel reporting. Referrers and UTM parameters arrive with the request. They have nothing to do with cookies and never did.
Aggregate revenue. Read from your payment provider’s API, which knows what arrived without any browser involvement. This is the single most useful revenue view and it costs nothing in privacy.
Same-visit conversion attribution. Which covers most impulse purchases, most direct-response advertising, and a surprising share of self-serve software signups.
Funnels, geography, devices, pages, campaigns. None of these ever needed identity.
The techniques that claim to solve this
Three appear regularly, and it is worth being clear about what each actually is.
Fingerprinting. Identify the device from its characteristics instead of stored data. It works, it persists, and regulators treat it the same as a cookie — the EDPB has confirmed the ePrivacy consent requirement reaches it. It is also worse than a cookie from the visitor’s side, because there is nothing to clear. See browser fingerprinting.
Server-side tracking. Move collection to your server. This changes the transport, not the data: an identifier set from the server is still storage on the device, and an IP address collected server-side is still personal data. Used specifically to evade browser protections, it is the pattern regulators have criticised. See server-side tracking.
Modelled attribution. Estimate the missing journeys statistically from the ones you observed. Legitimate and useful at scale, but it produces estimates presented with the same confidence as measurements — and at small volume it is fitting noise.
None of these makes the trade disappear. Two of them make it invisible, which is worse.
Making the decision honestly
The question is not “cookies or no cookies”. It is: what is the longest window you genuinely need, and is that answer worth what it costs your visitors?
For most sites the honest answer is shorter than assumed. If your product is bought within a session or two, cookieless attribution loses you nothing at all. If your sales cycle is six weeks, you have a real decision — and the right way to make it is to name the trade, not to buy a tool that hides it.
sonex takes the cookieless side by default: the aggregate revenue view needs no identity at all, and the Attribution report offers first-click, last-click and linear over a conversion event you fire, within the window that daily rotation allows. What we will not do is claim there is no window.
If you want to see how much a consent banner is costing you today, our cookie banner impact calculator puts a number on it.
Frequently asked questions
- Can you do marketing attribution without cookies?
- Partly, and the boundary is precise. Aggregate revenue beside traffic and same-visit conversion attribution both work without any cross-day identity. Crediting a sale to a touchpoint from weeks earlier does not — that requires remembering the visitor across that gap.
- What exactly do you lose without cookies?
- Cross-day and cross-session visitor identity. Returning visitors are counted as new, multi-week journeys cannot be reconstructed, and first-click attribution over a long window is unavailable. Everything within a single visit is unaffected.
- Is there a way to get long-window attribution without a consent banner?
- Not honestly. Any technique that recognises the same person weeks later is doing what the consent rules are about — including fingerprinting, which regulators treat the same as a cookie despite the absence of storage.
- How does cookieless visitor recognition work?
- A hash of request characteristics combined with a secret salt that rotates on a schedule, typically daily. Within the window the same visitor produces the same identifier; once the salt rotates the identifier cannot be reproduced by anyone, including the vendor.
sonex is privacy-first web analytics. No cookies, no consent banner, no personal data. Drop one script and read realtime visitors, funnels and a world map in seconds.
Try sonex free