VisitorType
← All posts

Cookieless analytics that's actually cookieless (a checklist for the skeptical)

privacyanalyticsgdpr

"Cookieless analytics" has become a marketing word that means three incompatible things: no cookies but fingerprinting instead (worse), no cookies but IP-based visitor stitching (grey), or genuinely no persistent identifier at all (rare). If privacy is why you're switching, the label tells you nothing — the mechanism does. Here's how to audit it.

The trick to watch for: identifier laundering

A cookie is just a persistent identifier stored in the browser. Removing the storage while keeping the identifier — by hashing IP + user-agent + screen size into a daily "visitor hash," or by canvas/font fingerprinting — changes the compliance paperwork, not the privacy reality. Regulators have been increasingly explicit that fingerprinting requires the same consent cookies do. If a vendor's docs say "no consent banner needed" and their dashboard shows returning-visitor rates, ask precisely how both can be true at once. Someone is identifying you.

What genuinely cookieless looks like

Honest cookieless measurement accepts real limits:

  • No persistent identifier: nothing stored client-side, no fingerprint derived. A session can be grouped (e.g. a random in-memory/session-scoped id that dies with the tab); a person cannot be recognized next week.
  • No cross-site anything: by construction.
  • Consequences you should expect: no true "returning visitors" metric, no cross-device journeys, conversion attribution limited to same-session. If a "cookieless" tool still shows those, return to the previous paragraph.

We built our own measurement on this basis — sessionStorage-scoped grouping, no cookies, no fingerprinting, Global Privacy Control honored, EU-hosted — and yes, that costs us returning-visitor stats. That's the trade, made honestly. (Details in our GDPR notes.)

The audit checklist

Ask any "cookieless" vendor these, in writing:

  1. What exactly is stored client-side? (localStorage and IndexedDB count. "Nothing" should mean nothing persistent.)
  2. Is any identifier derived from device/browser characteristics? If yes, it's fingerprinting — different word, same mechanism.
  3. How do you compute unique/returning visitors? The load-bearing question; vague answers here decide the audit.
  4. Do you honor Global Privacy Control? A one-bit test of whether privacy is architecture or copywriting.
  5. Where is data processed and stored? EU hosting simplifies GDPR materially.
  6. Is IP address stored? Transient use (geo lookup, bot verification) differs fundamentally from storage; the answer should be explicit.

A vendor that answers all six crisply is telling the truth about something. Evasion on question 3 is the tell.

The part nobody mentions: bots corrupt cookieless data more

Cookie-era analytics accidentally filtered some automation (many bots didn't persist cookies). Cookieless tools count requests or sessions — and in 2026 an enormous share of those are machines: on our own site, humans were a single-digit percentage of events in a recent 30-day window. Cookieless analytics without serious bot classification doesn't give you privacy-respecting human stats; it gives you privacy-respecting noise. Whatever tool you pick, ask what it does with the ninety-something percent of traffic that isn't a person — because after the cookie banner disappears, that's the number quietly deciding whether your dashboard means anything.

See which AI agents visit your site — free.

Start with VisitorType