Organisation & tools
Cookie-free analytics— can you really understand your visitors without tracking them?
You want to know how many people visit your site, where they come from, which pages hold their attention and whether they eventually get in touch.
Nothing extraordinary so far.
But to get those answers, do you really need to follow each visitor from page to page, try to recognise them when they come back, drop several trackers on their device and slowly build a history of their behaviour?
Not necessarily.
For a long time, analytics sat on a fairly simple idea: the more data we collect, the better we will understand our visitors.
That logic is worth questioning now.
Because between measuring nothing and wanting to know everything, there is a third option: measure what is actually useful.
And for a great many independents and businesses, that is more than enough.
Let’s start with a question: what do you actually need to know?
When you install an analytics tool, it is tempting to look straight at everything it is capable of measuring.
Visitor numbers, sessions, devices, browsers, location, pages viewed, time spent, events, journeys, new or returning visitors, campaigns…
The list can become very long.
But the useful question is not:
“What can this tool collect?”
It is:
“Which information can actually help me make a decision?”
If you work independently and the main job of your site is to generate quote requests, you may mainly need to know how many people arrive, which sources bring those visits, which pages hold their attention and how many enquiries are finally sent.
If you publish regularly, you will probably also want to know which articles attract traffic and which then lead readers towards your offers.
If you invest in several campaigns, you will need to be able to compare them.
You do not necessarily need to know that visitor no. 847 came back three times this week before clicking your contact page.
That information can be interesting.
Interesting is not always the same as necessary.
Analytics and cookies are not quite the same thing
There is a frequent confusion between analytics and cookies.
An analytics tool measures how a site is used; a cookie is one of the technical mechanisms that can be used, notably to store or retrieve certain information on a user’s device.
The two are not synonyms.
An analytics system can use cookies to recognise a browser across several pages or several visits; other approaches can work without dropping that kind of persistent identifier.
That is what now makes it possible to design systems that answer a great many useful questions without necessarily trying to recognise each visitor over time.
And that difference changes a great deal.
What can you know without following each person individually?
Rather more than people imagine.
Depending on the tool and how it is configured, a privacy-respecting analytics system can, among other things, show the number of visits, the pages viewed, the main entry pages, traffic sources, campaigns, certain events or conversions, and limited, aggregated technical or geographic information.
You can perfectly well discover that article A attracts a lot of traffic from Google; that page B receives fewer visits but generates more enquiries; or that a particular campaign brings visitors who look especially at your premium offer.
You can also measure that a button was used, that a form was sent or that an important page was viewed.
In other words, you can answer a large part of your commercial questions without necessarily knowing who sits behind each behaviour.
That distinction is fundamental.
Understanding a group does not always mean recognising each individual
Imagine that 500 people arrive on a service page this month.
Of those 500 visits, 80 people start your form and 25 send it.
You already learn something: the page generates interest; some of the visitors start the expected action and a smaller share finish it.
You can then compare those figures with another period, another page or another traffic source.
To make that decision, do you really need to know that Marie came on Monday at 14:32, viewed three pages, came back on Wednesday from her phone and finally sent the form on Friday?
Probably not.
You need to understand the overall behaviour of the journey.
That is precisely where aggregated analytics becomes interesting: it turns behaviours into trends without necessarily turning each visitor into an individual file.
So what do you lose?
It is only fair to be clear: choosing a less intrusive approach sometimes means giving up certain information.
If your system does not try to recognise a browser over time, it becomes harder — even impossible, depending on the setup — to reconstruct precisely the same person’s journey across several days, devices or sessions.
You may be able to know that 100 visits came from Google, that 30 people looked at an offer and that 5 enquiries were sent; but not necessarily to claim that a particular enquiry came from someone who had read a given article three weeks earlier.
You lose some of the individual granularity.
The real question is:
Would that granularity have changed your decision?
If the answer is no, you may not have lost anything that mattered.
More precision can also create an illusion of certainty
There is an interesting paradox in analytics.
The more a dashboard contains, the more it can give the impression that we understand user behaviour perfectly.
That is not always true.
Someone opens your site on their phone, comes back from their work computer, refuses certain trackers, changes browser, uses a blocker or later clicks another link.
Depending on the technologies used, part of the journey can become hard to stitch together correctly.
Conversely, some systems can attribute several behaviours to the same technical identifier without knowing the person’s real intention.
The data can be extremely precise technically and still imperfect commercially.
Knowing exactly where someone clicked does not mean knowing why they clicked.
That is an important limit to keep in mind.
Analytics cannot read the minds of the people who find you
Imagine two visitors who look at exactly the same four pages.
The first is extremely interested and is comparing your services before asking for a quote.
The second is a curious competitor.
In your analytics, their journeys can look almost identical.
The same goes for time on a page: someone can stay eight minutes because they are reading your article carefully… or because they put their phone down to make coffee.
The data show observable behaviours.
They do not automatically give you their meaning.
That is why analytics should remain a decision-making tool, not a machine supposed to explain human beings perfectly.
UTM parameters become particularly useful
Choosing to limit individual tracking does not mean you have to give up on understanding your campaigns.
UTM parameters can become very useful here.
You can, for example, use a specific link for an Instagram post, another for a newsletter, another for an advertising campaign and another still for a partner.
When a visit arrives, the system can then understand where the click came from thanks to the information in the link.
You do not need to know the person’s identity to know that:
Campaign A
320 visits and 12 conversions.
Campaign B
800 visits and only 3 conversions.
That information is already enough to ask an excellent commercial question:
Why does the campaign that attracts fewer people seem to attract better enquiries?
That is exactly the kind of question that good analytics should let you ask.
Traffic and conversion need to be kept apart
A privacy-respecting approach does not mean limiting yourself to the number of page views either.
You can define the events that actually matter for your business.
A click on “Request a quote”, a successfully sent form, a booking, an account created or a resource downloaded can, depending on your architecture, be measured as events.
That lets you move from:
Volume
This page received 700 visits.
Result
This page received 700 visits and 38 enquiries were sent.
The second piece of information is obviously much more interesting.
The aim is not to collect less for the sake of collecting less.
It is to collect more intentionally.
Can you tell where a quote request came from?
Yes, in some configurations.
Imagine that someone clicks a campaign identified by UTM parameters, arrives on your site and sends a form during that visit.
Depending on how it is designed, your architecture can associate certain source information with the conversion.
You could then know that an enquiry arrived from a given campaign without necessarily building a permanent behavioural history of the visitor.
If, on the other hand, the person discovers your site today, comes back three weeks later by another route and contacts you then, attributing the conversion precisely to their very first contact becomes much harder without a mechanism that can link the different visits.
That is one of the limits you have to accept.
But again:
Do you really need to reconstruct every individual journey to know whether your strategy is working?
For a great many businesses, the answer is no.
“Cookie-free” does not automatically mean “GDPR-compliant”
This is probably the most important nuance in this article.
You sometimes come across formulations such as:
“We don’t use cookies, so our analytics is 100% GDPR.”
The reasoning is too quick.
GDPR does not regulate cookies as such; it frames the processing of personal data. Other European and national rules also cover the use of certain technologies that store information on a user’s device or access it.
A tool can work without cookies and still process personal data.
An IP address, certain identifiers or a combination of technical information can, depending on the circumstances, fall within the scope of personal data.
You have to look at what the tool actually does, not only check whether it drops a file called a cookie.
The word “anonymous” also deserves some caution
Another frequent shortcut:
“The data are anonymous.”
Anonymisation has a much more demanding meaning than people often imagine.
Simply removing the name and email address does not automatically turn a piece of data into anonymous data; if a person can still be identified, directly or indirectly, from the information available and the means reasonably likely to be used, the data-protection question remains relevant.
You also need to distinguish anonymisation from pseudonymisation.
A pseudonymised piece of data generally remains personal data when there is a way of linking the pseudonym back to a person.
For a business, the right attitude is not to hunt for the most reassuring label.
It is to understand what is actually collected and what can be done with it.
And consent?
This is where things become more technical.
The fact that a tool is presented as “cookieless” is not, on its own, enough to conclude that no consent is needed.
The answer depends, among other things, on the technologies used, the information stored or accessed on the device, the nature of the data processed, the purpose of the processing, the configuration chosen and the rules that apply in the country concerned.
In Belgium as elsewhere in the European Union, it is worth avoiding automatic conclusions of the kind:
no cookies = no banner = compliant.
A genuinely privacy-respecting setup is judged on how it actually works.
That is less seductive than a three-word promise.
But much more serious.
A “privacy-friendly” tool does not spare you from thinking
Choosing a solution designed around privacy can simplify a number of decisions considerably.
But the name of the tool never replaces your own configuration.
Before integrating an analytics solution, several questions are worth asking: what data are collected? For how long? Are they used for other purposes? Where are they hosted and processed? Which providers are involved? Are there international transfers? Which configuration options are switched on? Which events have you yourself decided to send?
That last question is particularly important.
Even a relatively sober tool can receive useless data if your own implementation sends it too much.
Privacy depends both on the tool and on the way you use it.
Do not put personal data in your URLs
This is a technical detail that can have important consequences.
URLs and their parameters can appear in various logs, analytics systems or technical tools.
It is better to avoid placing information such as an email address, a phone number, a full name or other personal data there simply to make tracking easier.
The same logic applies to UTM parameters: they are there to identify a source, a medium or a campaign.
Not a person.
utm_campaign=spring_launch makes sense.
Using a parameter to write in the recipient’s email address so you know exactly who clicked raises an entirely different question.
Measuring a campaign does not necessarily mean identifying its reader.
Watch the events you create as well
Custom events are extremely useful.
But their name or their content needs to be thought through.
You can perfectly well create an event quote_form_sent to know how many forms have been submitted.
You do not necessarily need to send, with that event, the full set of answers given by the person.
The same goes for a members’ area: knowing that a feature was used can be useful; automatically transmitting the content consulted, the user’s identity and several extra pieces of information is not always.
Once again, the right question remains:
What do we actually need to answer our question?
Analytics should start with your decisions, not with your tool
That is probably the best way to build a sober system.
Before installing anything, write down the decisions you would like to be able to take.
For example:
I want to know which channels deserve more investment.
You then need to measure sources and certain conversions properly.
I want to know which SEO articles attract people interested in my services.
You need to understand entry pages, traffic from search engines and certain actions taken after reading.
I want to know whether my form puts people off.
You need to measure it being opened, possibly certain relevant steps, and it being sent successfully.
I want to know whether my new service page works better than the old one.
You need to define what “works better” means, then compare the relevant indicators.
At no point was the first question:
“How do we follow each visitor?”
The right dashboard can be surprisingly small
For a premium service business, a genuinely useful dashboard could sometimes fit on a single page.
You might find there the number of visits, the main sources, the entry pages, the most viewed content, the important actions, the conversions and how they evolve over time.
Then a few filters that let you go deeper when a figure deserves your attention.
That is all.
You do not necessarily need 70 charts.
The point of a dashboard is not to prove that your system is sophisticated.
The point is to let you understand quickly what is going on.
Less data can also make the analysis clearer
That sounds paradoxical.
You might think that the more data we have, the better decisions we can take.
In reality, too much information can produce the opposite effect: you start watching dozens of metrics, hunting for an explanation for every variation and spending a great deal of time on figures that will have no influence on the business.
A more sober approach forces you to choose.
Which five or ten pieces of information actually matter?
Which movements deserve a reaction?
From what point do we need to go deeper?
That constraint can end up improving the analysis itself.
Useful data is not what you can collect; it is what helps you decide.
And for a business that really needs a very advanced analysis?
Not every business has the same needs, of course.
A large e-commerce site, a platform with millions of users, a complex digital product or a company investing considerable budgets in acquisition can need much more sophisticated analysis.
In that context, understanding journeys, cohorts, attribution or certain behaviours in detail can represent genuine economic value.
That does not mean those analyses are bad.
It simply means that the level of collection should match the real need.
The problem appears when a small business adopts, by default, an extremely complex tracking infrastructure simply because it has become the norm.
Your architecture should be proportionate to your activity.
Start with five questions
If you want to rethink the analytics of your site, start simply here:
- Which decisions do we want to take thanks to our data?
If a metric cannot influence any decision, ask yourself why you are collecting it. - Which data are actually necessary to take those decisions?
Not everything that might be interesting; what you need. - Do we need to recognise a visitor across several visits?
In some models, yes. In a great many others, far less than people think. - What does our tool actually do?
Cookies or not, look at the data collected, their processing, their retention, their hosting and the providers involved. - What are we ourselves sending to the tool?
Because a privacy-respecting architecture can be compromised by an implementation that sends unnecessarily too much information.
Those five questions already make it possible to move from a logic of automatic collection to a much more intentional one.
You do not need to know everything to understand
That is probably the most important idea.
A good analytics system is not necessarily the one with the greatest quantity of information on each person.
It is the one that gives you enough visibility to understand what works, what deserves your attention and what you could improve.
You can know that an article attracts the right people without knowing their names; understand that a campaign works without following each reader for three weeks; detect that a form creates friction without recording the full behaviour of each person who finds you.
There are, of course, trade-offs.
Less individual tracking sometimes means less attribution, less granularity and less certainty about certain journeys.
In exchange, you get a more sober architecture, often easier to understand and more aligned with a simple principle:
collect only what has a genuine reason to exist.
At by Noreliam, that is how we prefer to think about analytics: we do not start by asking how far it is technically possible to follow a visitor.
We start with another question:
“What do you actually need to understand?”
Then we look for the most proportionate way of getting that answer.
Because understanding your visitors and respecting their privacy are not necessarily two opposing aims.
Do you know what your site actually measures today?
In a 30-minute clarity conversation, we can look at the data your business actually needs, the events worth measuring and how to build analytics that is more readable and proportionate to your aims.
Let's talk about your project →