Cookieless tracking covers measurement methods that work without cookies or any other identifier stored on the visitor's device. Instead of a cookie ID, they rely on things like short-lived anonymous hashes or server-side signals.
How does cookieless tracking work?
There are several approaches:
- Anonymous counting with a hash: a hash is built from request attributes plus a regularly rotating salt. Visits within a day can be grouped without recognising the visitor long term.
- Server-side tracking: events go from a server to the ad platforms instead of relying on browser cookies. Personal data still needs a legal basis, though.
- Aggregated measurement and modelling: platforms estimate conversions from samples, for example through Google Consent Mode v2.
Note that cookieless does not automatically mean anonymous. Fingerprinting works without cookies too, but it is still tracking and generally requires consent under the GDPR and ePrivacy rules.
What does cookieless tracking mean for advertisers?
Cookie-based measurement keeps getting less reliable: third-party cookies are blocked, Intelligent Tracking Prevention shortens first-party cookie lifetimes, and many visitors decline in the cookie banner. Cookieless tracking gives you a more complete picture of reach and visit volume. To optimise campaigns on Meta or Google, though, you still need signals collected after consent.
Example
Out of 1,000 visitors, 600 accept marketing tracking. Without cookieless counting, you only see 600 visits. With it, you count all 1,000 anonymously and know your real consent rate.
Cookieless Tracking with LeadSignal
LeadSignal counts pre-consent visits with a daily-rotating salted hash, and nothing is stored on the device. In this state no ad pixels load and no persistent identity is created. If the visitor later gives consent, their earlier anonymous visits are stitched to that identity. Your dashboard shows the resulting consent rate. Our guide to GDPR-compliant tracking shows how it fits together.