← Back to blog
Blog

What cookieless analytics actually changes — consent banners, ITP, and ad blockers

More analytics tools now call themselves “cookieless.” But what actually changes when you drop cookies, and what stays the same? Whether you still need a consent banner, how Safari’s ITP and ad blockers fit in, and how “users” get counted differently — laid out for ecommerce operators.

5 min read
  • Privacy
  • Tracking

This post is for anyone who has read “no cookies” or “no consent banner” on an analytics tool’s page and thought, “Really? What’s the difference?” NextRise Analytics uses cookieless tracking too, but this is not a product pitch — it explains what actually changes at the level of the mechanism.

Why traditional analytics uses cookies

To know that “the same person came back.” A traditional analytics tag writes an identifier (a client ID) into the browser as a cookie on the first visit, reads it on the next visit, and concludes “this is their second time” or “they were here last week too.” User counts, new vs. returning, and repeat rate are all built on top of that identifier.

Convenient as it is, storing an identifier on the device is itself what became subject to consent in many countries and regions, starting with the EU’s ePrivacy Directive — the act of “writing to or reading from the device” is the regulatory trigger. Japan’s amended Telecommunications Business Act (2023) requires disclosure of what is sent to third parties regardless of cookies, and other jurisdictions have similar disclosure duties. Because this is a separate obligation from the consent banner, the safe course even with cookieless analytics is to spell out what your tracking collects in your privacy policy or equivalent.

Without cookies, how do you tell it’s the “same person”?

The standard way to avoid writing anything to the device is a daily-rotating hash. In NextRise Analytics, the visitor identifier is a hash of the following ingredients combined:

hash(salt that changes daily + site ID + IP address + user agent)
  • The salt changes every day, so the same person gets a different ID tomorrow. There is no tracking across days.
  • The site ID is mixed in, so a visit to a different site can’t be linked.
  • The IP address and user agent are not stored. They are discarded once the hash is computed.

Nothing is written to the device, and the only thing stored is a hash that can’t be reversed — that is the basis for saying the tag can be installed without showing a consent banner.

What changes and what doesn’t

Cookie-based analyticsDaily-hash analytics
Consent bannerRequired in many regionsGenerally not required (see the caveat below)
Sessions, pageviewsSameSame
Users and new/returning within a single dayAvailableAvailable
Users and repeat rate across daysAvailableNot available (the same person on a different day is counted as a different person)
Impact of Safari’s ITPCookies get cleared after 1–7 days, so returning visitors turn into new onesNo impact — there was never any tracking across days
Ad blockersSome sends are blockedSome sends are blocked just the same (cookies have nothing to do with it)
Revenue, CVR, traffic source and per-page analysisSameSame

Two takeaways.

  1. The numbers you need for ecommerce revenue analysis barely change. Which page, from which source, sold how much — session-level data is enough for that.
  2. The one thing whose definition changes is “users across multiple days.” Monthly user counts come out higher on cookieless. When comparing tools, line them up on sessions rather than users.

Common misconceptions

“No cookies means ad blockers don’t affect you either” — Not true. Blockers don’t stop cookies; they stop the send to the analytics domain, so cookieless tracking has some loss too (a few percent in practice). For revenue and transactions, where you need the exact count, build them from order data.

“You will never need a consent banner” — The analytics tag on its own may not need one, but if other tags on your site (ad remarketing, chat widgets, A/B testing, and so on) write cookies, you still need the banner. Make that decision for the site as a whole. And as noted above, even where no banner is needed, disclosing “what is being sent” may be required separately.

“Cookieless means no personal data is handled at all” — The IP address is handled for an instant as an ingredient of the hash (it is not stored). The accurate phrasing is not “never handled” but “never stored, and can’t be reversed.”

Choose by whether “what is collected and what isn’t” is published

Plenty of tools now call themselves cookieless, but the implementations vary. When choosing one, we recommend checking whether these three points are published in a way that matches the actual implementation:

  • How the identifier is built (what goes into it, and how often it rotates)
  • Whether the IP address and user agent are stored
  • Whether the full URL query string is sent, or only UTM parameters (it is not unusual for a store to have email addresses or customer names appear in URLs)

NextRise Analytics documents all three, exactly as implemented, in Our approach to privacy and Tracking data and privacy. Use them as material for your decision.

Related articles