Cookieless tracking
Measure aggregate activity without a persistent anonymous Graytower visitor ID.
Graytower offers two Website-level visitor identity modes. First-party cookie is the default and connects browser activity across visits. Cookieless measures aggregate activity without creating a persistent anonymous Graytower identifier in browser storage.
| Capability | First-party cookie | Cookieless |
|---|---|---|
| Pageviews, custom events, traffic sources | Available | Available |
| Visitor and session counts | Durable identity and browser sessions | Daily visitor and half-hour session estimates |
| Returning visitors and anonymous profiles | Available | Unavailable for new cookieless activity |
Browser identify, signup, and checkout_started | Available | Disabled |
| Stripe revenue totals | Available | Available |
| Long-range anonymous attribution and journeys | Available | Limited |
| Experiment continuity across visits | Available | Limited |
How the estimate works
After authorizing the Website, Graytower derives a Website-scoped daily pseudonymous key from the request IP address and User-Agent using a server secret. The key changes at UTC midnight. Session counts use fixed 30-minute UTC windows and are estimates, not inactivity-based sessions. If either network signal is absent, events receive independent random keys instead. Raw IP and User-Agent are not written to Graytower analytics events by this application. Network infrastructure may have separate request logs and retention policies.
The cookieless tracker does not create _gt_id or use browser storage for identity or session continuity. On initialization it removes existing Graytower visitor and experiment cookies and clears the prior tracker's session and pending-event storage keys. It does not decorate links with identity parameters. Explicit browser identity calls are ignored. The collector also discards a persistent visitor ID sent by an old tracker when the Website is configured as cookieless.
Server custom events remain available, but a supplied anonymous ID is ignored and each event is counted independently. Browser and server Stripe attribution calls that supply an anonymous visitor ID are rejected in cookieless mode; Stripe payment import and revenue totals continue. Application-supplied named customer identity in a separate Stripe server integration may still be personal data and needs its own privacy review.
Switch modes
- Open Website → Settings → Tracking → Visitor identity.
- Choose a mode and review the confirmation.
- Copy the updated installation snippet and deploy it on your site. Cookieless uses
/js/script.cookieless.js; first-party identity uses/js/script.js. - Use Verify installation. Settings reports the last observed tracker mode and flags a mismatch.
Saving the Website setting immediately changes server-side collection policy. The existing script on your site does not change until you deploy it. Historical analytics are retained. Switching back creates a new cookie ID; Graytower does not stitch older cookieless activity to it.
All accepted pageviews and custom events count toward the same tracked-event allowance in either mode. Stripe revenue continues syncing, while anonymous revenue matching and experiment attribution can have lower coverage in cookieless mode.
Privacy considerations
Cookieless describes the storage and identity behavior of this tracker; it is not a legal compliance certification or a promise that consent is unnecessary. IP-derived identifiers and request metadata can still be subject to privacy rules. Review your implementation, notice, lawful basis, jurisdiction, and infrastructure with appropriate counsel. The EDPB guidance on ePrivacy's technical scope discusses IP-based tracking and unique identifiers.
See the Privacy Policy and Data Processing Agreement for Graytower's processing terms.