Skip to content

How cookieless tracking works

Cookieless analytics counts visits without storing a PureMetrix identifier in the visitor’s browser. Here is how PureMetrix does it and what it means for WordPress site owners.

Daily salt hashing

When an event arrives, the server combines the IP address, browser type and hostname with a random value that changes every day (the salt) and turns them into a hash, a one-way checksum. The raw IP address and User-Agent are not kept in the event database, and nothing is stored in the browser.

What the browser does

Loads a script under 3 KB, sends events, and can optionally use the same-origin /px proxy on your own domain.

Sessions and bounce rate

Calculated from the incoming events. Session, bounce rate, unique visitors.

WordPress settings

  • Exclude user roles (e.g. admins)
  • Connection to your PureMetrix account
  • Server-side WooCommerce purchases
  • Shared links

Limits

No reliable tracking of one person across devices. Never put personal data (names, email addresses) into event names. You still need a data processing agreement (DPA) for your records.

Migrating from GA4

Compare trends on the same landing pages. Migrate from GA4, why numbers differ.

Daily salt and what “unique” means

Cookieless tools usually recognise a visitor only for a short time, using details from the request plus a server-side salt that keeps changing. PureMetrix changes the salt every day, so a “unique visitor” is counted per day, not for years via a cookie ID. That is a deliberate privacy trade-off: visits on different days can’t be linked, but you can truthfully say “we don’t set an ID cookie.”

Expect counts to differ from GA4. Compare trends and goals, not whether visitor numbers match exactly.

What is still sent to the server

The page URL, the referrer (the page someone came from), the browser type and event details are still sent to PureMetrix. With the same-origin /px proxy, that request goes to your own domain. Check that your privacy policy describes this accurately—including server-side WooCommerce purchases if your shop uses them.

Limits you should state honestly

Visitors counted per day can’t be turned into a 13-month remarketing audience. Journeys across several devices stay approximate. PureMetrix is built for reliable website figures with privacy in mind—not for identifying people for ads. Tell clients this upfront so they don’t expect GA4 features that depend on permanent user IDs.

Server-side WooCommerce tracking still reports the order value when the browser drops out (e.g. after a payment redirect). It records the sale; it does not replace a cookie.

Setup checklist

Check that the snippet or plugin connection is installed, the optional /px proxy responds, staff roles are excluded and goals point to your thank-you pages. If the tracking script doesn’t load, nothing can be counted.

Events beyond pageviews

Goals, outbound clicks, downloads and WooCommerce purchases are simply events with a few details attached. Going cookieless changes how long a visitor is recognised, not what an event is. Send only what you need—URL, revenue, campaign—so your privacy policy stays accurate.

For purchases, prefer server-side tracking, because browsers often drop out after payment redirects.

Bots and scrapers

Cookieless tools still see bots. Rely on PureMetrix’s bot filtering and your own firewall (WAF)—a long-lived cookie would not stop scrapers either. Look at sudden spikes from one browser type or waves of 404 errors separately from real visitors.

If a scraper opens your thank-you pages, goal numbers go up—protect those pages and limit form submissions. PureMetrix records the requests it receives; it cannot judge the intent behind them.

Track purchases server-side so your shop figures don’t depend on whether an automated browser kept a cookie it never needed.

How developers should think about it

Request → hash with daily salt → aggregated figures. There is no permanent browser ID to find in your browser’s developer tools. If a tester asks “where is my cookie?”, show them: there is no PureMetrix cookie, only a network request. Exclude staff roles so internal tests don’t inflate visitor numbers.

Mention the daily salt rotation in your security FAQ so reviewers don’t assume a long-lived pseudonymous ID exists—it doesn’t.

In app WebViews, check that the snippet loads. Some WebViews handle cookies differently, but PureMetrix doesn’t need cookies—only the script has to run.

Company proxies that rewrite the User-Agent can change the hash during the day. Keep that in mind if you see an odd one-day spike in unique visitors.

Related reading

More guides HTML snippet WordPress Shopify Next.js

Last updated: September 2026