What cookieless analytics actually changes — consent banners, ITP, and ad blockers
More analytics tools now call themselves “cookieless.” But what actually changes when you drop cookies, and what stays the same? Whether you still need a consent banner, how Safari’s ITP and ad blockers fit in, and how “users” get counted differently — laid out for ecommerce operators.
- Privacy
- Tracking
This post is for anyone who has read “no cookies” or “no consent banner” on an analytics tool’s page and thought, “Really? What’s the difference?” NextRise Analytics uses cookieless tracking too, but this is not a product pitch — it explains what actually changes at the level of the mechanism.
Why traditional analytics uses cookies
To know that “the same person came back.” A traditional analytics tag writes an identifier (a client ID) into the browser as a cookie on the first visit, reads it on the next visit, and concludes “this is their second time” or “they were here last week too.” User counts, new vs. returning, and repeat rate are all built on top of that identifier.
Convenient as it is, storing an identifier on the device is itself what became subject to consent in many countries and regions, starting with the EU’s ePrivacy Directive — the act of “writing to or reading from the device” is the regulatory trigger. Japan’s amended Telecommunications Business Act (2023) requires disclosure of what is sent to third parties regardless of cookies, and other jurisdictions have similar disclosure duties. Because this is a separate obligation from the consent banner, the safe course even with cookieless analytics is to spell out what your tracking collects in your privacy policy or equivalent.
Without cookies, how do you tell it’s the “same person”?
The standard way to avoid writing anything to the device is a daily-rotating hash. In NextRise Analytics, the visitor identifier is a hash of the following ingredients combined:
hash(salt that changes daily + site ID + IP address + user agent)
- The salt changes every day, so the same person gets a different ID tomorrow. There is no tracking across days.
- The site ID is mixed in, so a visit to a different site can’t be linked.
- The IP address and user agent are not stored. They are discarded once the hash is computed.
Nothing is written to the device, and the only thing stored is a hash that can’t be reversed — that is the basis for saying the tag can be installed without showing a consent banner.
What changes and what doesn’t
| Cookie-based analytics | Daily-hash analytics | |
|---|---|---|
| Consent banner | Required in many regions | Generally not required (see the caveat below) |
| Sessions, pageviews | Same | Same |
| Users and new/returning within a single day | Available | Available |
| Users and repeat rate across days | Available | Not available (the same person on a different day is counted as a different person) |
| Impact of Safari’s ITP | Cookies get cleared after 1–7 days, so returning visitors turn into new ones | No impact — there was never any tracking across days |
| Ad blockers | Some sends are blocked | Some sends are blocked just the same (cookies have nothing to do with it) |
| Revenue, CVR, traffic source and per-page analysis | Same | Same |
Two takeaways.
- The numbers you need for ecommerce revenue analysis barely change. Which page, from which source, sold how much — session-level data is enough for that.
- The one thing whose definition changes is “users across multiple days.” Monthly user counts come out higher on cookieless. When comparing tools, line them up on sessions rather than users.
Common misconceptions
“No cookies means ad blockers don’t affect you either” — Not true. Blockers don’t stop cookies; they stop the send to the analytics domain, so cookieless tracking has some loss too (a few percent in practice). For revenue and transactions, where you need the exact count, build them from order data.
“You will never need a consent banner” — The analytics tag on its own may not need one, but if other tags on your site (ad remarketing, chat widgets, A/B testing, and so on) write cookies, you still need the banner. Make that decision for the site as a whole. And as noted above, even where no banner is needed, disclosing “what is being sent” may be required separately.
“Cookieless means no personal data is handled at all” — The IP address is handled for an instant as an ingredient of the hash (it is not stored). The accurate phrasing is not “never handled” but “never stored, and can’t be reversed.”
Choose by whether “what is collected and what isn’t” is published
Plenty of tools now call themselves cookieless, but the implementations vary. When choosing one, we recommend checking whether these three points are published in a way that matches the actual implementation:
- How the identifier is built (what goes into it, and how often it rotates)
- Whether the IP address and user agent are stored
- Whether the full URL query string is sent, or only UTM parameters (it is not unusual for a store to have email addresses or customer names appear in URLs)
NextRise Analytics documents all three, exactly as implemented, in Our approach to privacy and Tracking data and privacy. Use them as material for your decision.
Related articles
- September 9, 2026We checked 114 major Japanese ecommerce sites. 96% run GA4 — and 46% still carry a dead tag — What's really installed: tracking tags, consent banners, and load times
We opened the home page of 114 major Japanese ecommerce sites across 14 categories, one by one, in a real browser. GA4/GTM adoption 96%, leftover Universal Analytics on 46%, a median of 7 marketing tags per site, cookie consent banners on 25%, median load time 3.9 seconds. Here's what the numbers say about "installed and forgotten" — and how to check your own store.
- September 7, 2026The only 5 numbers an ecommerce store needs to check in GA4 each week — where they live, and what to decide after you look
GA4 has too many screens, and the numbers that move ecommerce revenue get buried. Five are enough for a weekly check — sessions, conversion rate, average order value, cart-to-purchase rate, and product-page add-to-cart rate. Here's where each one lives in GA4, how to split it against last week, and what to decide once you've looked.