How to track referrals without cookies
Almost every guide to a partner program starts with a cookie. It needs consent, in Safari it lasts seven days and it does not survive a change of device. We show how we do it without one.
Article contents
A partner program, a referral link, a commission on a sale. Almost every guide to building one of these starts the same way: set a cookie. It is a habit twenty years old and today it is also the weakest link in the whole system. Legally and technically.
We will show why that is, and above all how a referral can be tracked without a single cookie. This is not theory: it is how we built it in our own product.
How it is usually done, and where it cracks
A typical partner program works like this: the partner gets a link with an identifier, for example ?ref=novak. When somebody clicks it, a script stores a cookie in the browser. When that person buys something a week later, the system reads the cookie and credits the commission.
The whole construction rests on the cookie surviving in the browser and being readable. Both are less certain today than they look.
The legal side
In Slovakia this is governed by § 109 (8) of Act No. 452/2021 Coll. on Electronic Communications, in force since 1 February 2022. It says that anyone who stores, or gains access to, information held in a user's terminal equipment may only do so if the user has given demonstrable consent. The act follows the ePrivacy Directive, specifically its Article 5(3).
The act does allow an exception, but it is narrower than companies often assume: consent is not needed when the storage is unconditionally necessary to provide a service the user has explicitly requested, or when its sole purpose is to transmit a message over the network.
A cookie carrying a partner identifier does not fall under that exception. The visitor did not ask you to remember who sent them. It is your commercial need, not their service. So you need consent, and that means a banner, refusals, and a share of referrals lost before anything else happens.
The technical side
And even when you have consent, the cookie may not survive. Since ITP 2.1, released in February 2019, Safari caps the lifetime of persistent cookies set from a script through document.cookie to seven days. It does not affect session cookies, nor those that already have a shorter lifetime. It affects exactly the ones partner programs are built on.
Add to that ad blockers, which often stop the script carrying the partner code before it even runs, a private window, where the cookie disappears when it is closed, and the most ordinary case of all: somebody clicks the link on a phone and buys in the evening on a computer. The cookie is on another device.
The ninety day referral window that programs promise therefore often means, in practice, seven days, one device and one browser.
A different approach: let the person see the code, not the browser
The solution is simpler than it looks, and it is older than cookies. Let the referral code travel in the address and end up in the form the customer is filling in anyway.
In our product MeaReal it looks like this. The partner gets an address in the form meareal.com/p/NOVAK and can rewrite the code to anything they will remember. When somebody clicks it, the registration form shows a visible field for the referral code and it is already filled in. Nothing is stored on the device: the code travels in the address and from there straight into the form.
This has three consequences and all three are in the partner's favour:
- It works without consent for cookies, because nothing is stored on or read from the terminal equipment. The question of consent never arises.
- It works even without clicking the link. Anyone who got the code by word of mouth, on a business card or from a flyer types it into the same field by hand and the referral counts just the same.
- It works across devices, because what decides is the moment of registration, not which browser the click happened in.
The attribution happens once, when the customer registers, and does not change afterwards. It is one record in the database next to their account, not a trace in their browser.
What you give up
To be fair: it is not free and you really do give something up.
The customer sees that somebody referred them. The code field is visible, so there is no pretending they arrived on their own. We consider that an advantage rather than a flaw, but you have to count on it.
You will not learn who clicked and did not buy. With a cookie you can count clicks and the conversion rate. Here you only know what ended in a registration. If you need to measure clicks as well, they can be counted on the server during the redirect from /p/KOD, without storing anything in the browser.
Anyone who retypes the address or passes it on some other way loses the code. That is why it pays for the code to be short and memorable. The partner can then simply read it out.
The same principle elsewhere: forms without a session
Once you stop treating a cookie as the first answer, you find that more things manage without one.
An example from the websites we built for Optik Petrík and for InGlory: protecting forms against spam usually needs a session, which means a cookie again. Instead of one, we put into the form a signed timestamp. On submission the server verifies it with its own key, so it cannot be forged or shifted. From it the server knows when the page was rendered, and it recognizes a submission within two seconds as a bot.
The result is a form with spam protection that needs to store nothing on the visitor's side. No cookie, no session, no consent.
Traffic can be measured the same way. This website uses a tool that works without cookies, which is why our banner asks for nothing about it. What can be counted on the server does not have to go through the browser.
What to check on your own website
Whether you run a partner program or are joining one, four questions are worth asking:
- Does the website ask for consent before it records the referral? If it does, every refusal of the banner is a lost referral. You can find out by refusing the banner, going through a referral link and registering.
- Do you see a code field at registration? If not, the system rests on something you cannot see and that your browser may delete.
- Does the referral work when you type the code by hand? This is the quickest test. If the code can be entered without clicking the link, the program does not rest on cookies.
- Does the referral survive a change of device? Click the link on a phone and finish the registration on a computer. With a cookie that will not go through.
If you are not sure what your website stores in the browser, our free audit goes through the home page and lists, among other things, which third party scripts and files it loads.
In short
A cookie is not the only way to remember who referred whom. For partner programs it is in fact the worse way: it needs consent, in Safari it lasts seven days, blockers stop it and it does not survive a change of device.
It is one of the things you will not get on a hosted platform. When such a store is worth building custom and when it is not, we cover in our article Custom online store or a platform.
A code that travels in the address and ends up in a visible form field has none of those problems. It is less elegant in the sense that the customer knows about the referral. But the partner is credited for what they really brought in, and the operator does not have to deal with consent for something they do not store.
Did the article help you? Send it to a colleague or to whoever looks after your website.
FAQ
Questions on this topic
How long does a referral cookie last in Safari?
Seven days. Since ITP 2.1, released in February 2019, Safari caps the lifetime of persistent cookies set from a script through document.cookie to seven days. It does not change session cookies or those with a shorter lifetime.
A program promising 30 or 90 days is therefore promising some of its visitors something their browser will not allow.
How do I track a referral without cookies?
Let the code travel in the address, for example /p/NOVAK, and at registration put it into a visible form field that fills itself from the link. The attribution happens once, at registration, and is saved next to the customer's account, not in their browser.
The advantage is that the code can also be entered by hand and the referral survives a change of device.
Can a form be protected against spam without cookies?
Yes. Instead of a session, a timestamp signed with the server's key is placed in the form. The server verifies it on submission, so it cannot be forged or shifted, and from it the server knows when the page was rendered.
That is how it works on the Optik Petrík and InGlory websites: protection against bots without a single cookie and without a session.
You will find more answers in the section FAQ.