← All posts

Privacy · GDPR · Analytics

Cookieless analytics: how to track visitors without a cookie banner

How cookieless web analytics works, what you give up compared to cookies, and when you can skip the consent banner under GDPR.

NoirTrack team · · 3 min read

A browser window with a cookie crossed out and a clean analytics chart behind it

Cookie banners are everywhere, and almost nobody likes them. Visitors click them away, and many click "reject". Every reject is a visitor your analytics never sees, so the banner quietly shrinks your data.

Cookieless analytics takes a different route: count visitors without storing anything on their device. No cookie, so for analytics there is usually nothing to ask permission for.

Why analytics usually needs a cookie

To tell a new visitor from a returning one, a tool needs to recognise the same browser twice. The classic way is a cookie: a small file with a random id that lives on the visitor's device for months.

Under the EU's ePrivacy rules and GDPR, storing that kind of id generally needs consent when it is not strictly necessary for the site to work. Analytics is not strictly necessary, so the banner appears.

How cookieless analytics counts visitors

Instead of storing an id on the device, a cookieless tool builds a short-lived hash from request signals that do not identify a person on their own, and resets it every day. Two visits on the same day from the same browser produce the same hash, so they count as one visitor. The next day the hash is different.

The hash cannot be turned back into a person, and nothing is left behind on the device. That is the whole point.

What you give up

Cookieless tracking is not free. Be honest with yourself about the trade-off:

With a cookie Cookieless
Unique visitors per day Accurate Accurate
Returning visitors across days Recognised Counted as new each day
Long sales cycles Sale tied to the first visit Sale matched by email or counted as unknown
Consent banner Usually needed in the EU and UK Usually not needed

For most content sites and simple products, cookieless is plenty. If you sell something people think about for weeks, the cookie mode gives you better attribution, and you can show a consent banner only to visitors in regions that require it.

Turning it on in NoirTrack

NoirTrack uses a first-party cookie by default. To go cookieless, add one attribute to the script tag:

<script defer
  src="https://noirtrack.com/t.min.js"
  data-site="YOUR_SITE_KEY"
  data-cookieless></script>

If you keep cookie mode, NoirTrack has a built-in consent banner that can target only the EU, UK or California, so visitors elsewhere never see it. Both options are explained in GDPR & cookieless.

Is cookieless analytics GDPR compliant?

Cookieless analytics removes the device storage that triggers most consent requirements, and a good tool also avoids collecting personal data like names, emails or full IP addresses. That makes compliance much simpler, but it does not replace legal advice for your situation. Mention your analytics in your privacy policy either way.

Frequently asked questions

Do I need a cookie banner for cookieless analytics?

Usually not. Consent banners exist to ask permission to store data on the device or to process personal data. Cookieless analytics stores nothing on the device and avoids personal data, so for analytics alone you generally do not need one. Check with your own legal advice if you also run ads or other trackers.

Is cookieless tracking less accurate?

Daily visitor counts stay accurate. What you lose is recognising the same person across days, so returning visitors are counted as new each day and long customer journeys are harder to follow.

Can I use cookieless analytics with revenue tracking?

Yes. Sales are still matched to visitors, by the visitor id on the same day or by the buyer's email. Sales that cannot be matched still count toward your revenue as unknown.

What is a first-party cookie?

A first party cookie is set by the website you are visiting, not by an outside company. It is far less invasive than third party cookies, but in the EU it can still need consent when it is used for analytics.