Cookieless Tracking localStorage Still Writes a Key
Vendors love saying "no cookies." Half the time I open DevTools and find a key under Local Storage anyway. That pattern is cookieless tracking localStorage: the cookie jar is empty, the browser still has a session id. I need that for a SaaS funnel. Pricing and the signup click have to stay one visit. A salt that resets at midnight will not.
If you only wanted the short definition of how cookieless tracking works, stop on the glossary. This page is what I actually click through when someone says cookieless and I am about to install the script.
Salt vs a key in the browser
Some tools write nothing on the device. The server hashes what the request already sends, often with a salt that rotates, then throws the salt away. PostHog's cookieless mode works like that: no cookies, no localStorage, id computed on the server. Plausible and Fathom are in that camp for traffic. You see visits and referrers. You do not get a same-visit id you can hang a funnel on.
EventDash is the other camp. No HTTP cookie from the tracker. An anonymous id still sits in localStorage. MDN says that store sticks around until something clears it. So a cookie and that key are both "stuff written on the device," even if the homepage only mentioned cookies. Snowplow even has localStorage as a real stateStorageStrategy next to cookies. They do not pretend those are the same switch.
I picked the localStorage path on purpose. The privacy docs say so: session id in localStorage, plus browser, OS, screen, timezone, language, and rendering hashes to keep the anonymous id stable. That is not a daily salt. I am not going to market it like one.
What I look at in DevTools
- Clear site data for the origin.
- Reload with the tracker on.
- Open Application → Local Storage and Cookies.
Empty cookies and empty localStorage? Storage-free, or the script never loaded. Empty cookies and a key in localStorage? That is cookieless tracking localStorage. A _ga cookie? You were sold the wrong sentence.
On eventda.sh I expect eventdash_session and eventdash_anonymous_id after reload. If they are gone, I broke the install. The homepage claim does not get a vote.
Why the funnel cares
Traffic charts are fine on a daily salt. Signup paths usually are not. Pricing and the button often share one URL. A form that fails validation may never navigate. If tomorrow's hash is a new person, those steps never line up.
That is why cookieless conversion funnels put data-ed-goal on the click and keep the session in localStorage. EventDash vs Plausible is the same fight: visits versus the signup step. What I will not promise about banners is on privacy first analytics.
Only need visits? Get the storage-free tool. Need which step died? Keep the key, and say that out loud.
Limits
No cookies on the tracker path. PII filtering. Do Not Track. About 11 KB gzip. Funnels and HTML goals. Free is 100k events/month. The session id is still in localStorage. Device signals help build the anonymous id. Clear site data and it resets.
I do not say that removes a consent banner. Chat widgets and ads pixels on the same page can still set cookies. Read the privacy docs with whoever owns that call. Not on the site yet? Signup.
Sources
- Window: localStorage property (MDN)
- Cookies and local storage for the web trackers (Snowplow)
- How to do cookieless tracking with PostHog (PostHog)
Related
Key takeaways
- Cookieless tracking localStorage = no HTTP cookie, and a key under Application → Local Storage anyway.
- A daily salt with an empty Application tab is a different product. Fine for visits. Bad for a signup path that shares one URL.
- Clear site data, reload, look. Skip arguing with the homepage.
- On EventDash you should see eventdash_session and eventdash_anonymous_id. The glossary still owns the short how-it-works definition.
FAQ
- What is cookieless tracking localStorage?
- It means the analytics script does not set an HTTP cookie, but it still puts a key in localStorage. Cookies can look empty while Application → Local Storage has a session id. That is how two pages in one visit stay connected. Clear site data and you start over.
- Is cookieless tracking the same as storage-free tracking?
- No. Storage-free tools write nothing on the device and usually hash the request with a salt that rotates. Cookieless tracking localStorage skips cookies and still uses browser storage. Vendors call both cookieless. Only one of them can hold a funnel step that never changes the URL.
- How does cookieless tracking work if there is no cookie?
- Either the server hashes IP and user agent with a daily salt and stores nothing in the browser, or the script writes an anonymous id to localStorage. EventDash does the second so pricing and signup can stay one visit. The short definition lives on the cookieless analytics glossary page.
- Does EventDash claim cookieless tracking removes the consent banner?
- No. We do not set cookies. We store an anonymous session id in localStorage, and the privacy docs list device signals used to keep that id stable. Other scripts on the page can still set cookies. Banner rules depend on your stack and where you operate. I am not giving legal advice here.