How cookieless tracking works
Classic web measurement stores a small identifier in the browser and reads it back on the next page or the next visit. Cookieless approaches try to answer the same questions without that identifier surviving in the browser. In practice the label covers several very different techniques that get bundled together by vendors.
Some of it moves the work to your own server: the browser talks to an endpoint on your domain, and that server forwards events to ad and analytics platforms. Some of it replaces observed data with modelled data, where a platform estimates the conversions it could not see from the ones it could. Some of it leans on information the visitor gives you directly — a login, an order, an enquiry form — and matches on a hashed email address rather than a browser identifier. And some of it, honestly, is just server-side tracking that still sets a first-party cookie and has been renamed for the brochure.
Why cookieless tracking matters
Browsers have steadily reduced what cookies can do. Third-party cookies are blocked or restricted in most browsers, and even first-party cookies written by JavaScript can have their lifetime shortened by tracking prevention features. Add consent banners, where a visitor who declines leaves no identifier at all, and a meaningful share of activity is simply invisible to the old approach.
For a business that spends on ads, the practical effect is under-reported conversions and misattributed channels. Bidding algorithms learn from the conversions they receive, so missing data does not merely make reports look sad — it makes automated bidding worse. That is why the work is worth doing rather than being an abstract privacy exercise.
Where cookieless tracking goes wrong
The biggest error is believing the label. Moving tags to a server does not remove the need for consent, does not restore the visitors who declined, and does not make measurement complete. Anyone promising perfect tracking without cookies is selling something that browsers and privacy law have both spent years dismantling.
The second error is confusing modelled numbers with counted ones. Modelled conversions are estimates produced by the platform, and they are reasonable planning inputs, but they cannot be reconciled row by row against your sales records and should never be presented as though they were.
The third is drifting into fingerprinting — recognising a device by its characteristics rather than by stored data. Major ad platforms prohibit it in their terms, and privacy regulators treat it as tracking that needs consent like any other. It is not a clever workaround.
What to do about it
Fix consent first, because it decides how much data you are allowed to collect at all. A clear banner that people actually understand tends to produce better outcomes than one designed to confuse, and consent mode lets platforms model the gap that remains within their own rules.
Then improve the data you genuinely own. Capture an email address or phone number at the point of enquiry, pass hashed identifiers to ad platforms where their terms allow it, and import offline outcomes so a lead that became a customer is visible. Finally, measure the whole thing honestly: compare platform-reported conversions against your own records, note the gap, and manage the gap rather than pretending it does not exist. A structured tracking audit is the usual starting point.