More in Privacy and compliance
Still have a question?
Could not find it? A person reads every message, usually within a few hours on business days.
Chat with usHow a visitor is counted without a cookie
On the default tier, TapCub separates visitors with an HMAC of the IP address and user agent, combined with a salt. The script itself writes nothing to the browser — no cookie, no local storage. The address is used for that hash and for geography, then discarded; it is never stored on the event row.
Two presets change how long the pseudonym lasts:
- Balanced keeps a site-level salt, so a returning visitor can be recognized across days and "new vs returning" works.
- Strict rotates the salt every day. Nobody is recognized across days; returning visitors are not reported.
Choose on ConfigurationSettingsPrivacy. Rows already stored are not rewritten when you switch.
The three collection tiers
| Tier | Name | What is collected |
|---|---|---|
| 1 | Anonymous aggregate | Daily rotating salt, no persistent ID of any kind. Autocapture and identity calls are dropped. Pageviews and custom events are stored. |
| 2 | Cookie-free pseudonym | The default above. No cookie; visitors separated by HMAC. |
| 3 | Identified | A device ID and a login may be used. Requires identified mode and a plan that includes it. |
The project default is tier 2. Regional rules can lower the tier for visitors from specific places — the built-in rule for the EEA and the UK is tier 2 with consent required. The compliance center guide covers how to change these.
Do I need a consent banner?
That depends on where your visitors are and which tier you use; this is not legal advice. In practice:
- Tier 1 and tier 2 store no identifier in the browser, which is the condition most regulators attach to the cookie-banner requirement. Many TapCub sites run tier 2 without a banner outside the EEA.
- For EEA and UK visitors the default rule requires consent. If your site has no banner, those visitors are stored at tier 1 automatically: pageviews and events still count, but there is no returning-visitor recognition and no autocapture.
- Tier 3 writes a device ID and therefore needs consent in most jurisdictions. Pass the analytics purpose from your banner to the script; the consent API is in the developer docs.
Do Not Track and Global Privacy Control
When the browser sends DNT: 1 or Sec-GPC: 1, the TapCub script does not load at all, and a hit that arrives anyway is stored at tier 1 with consent bits cleared. You can disable the DNT check with data-respect-dnt="false" on the script tag, but GPC is always honored at the collector. This is why a developer with privacy flags on sometimes sees no POST in the network panel — see install problems.
What this means for your numbers
- Visitor counts are lower than cookie-based tools when those tools counted bots or multiple tabs, and higher when a banner blocked them. Trends match; totals do not — see Why UV never matches.
- Sessions still work on every tier; they are cut by idle time, not by a cookie.
- Funnels across days work on Balanced and on tier 3; on Strict each day is a fresh start.
- Heatmaps and autocapture need tier 2 or 3.