TapCub is live — analytics, insights and live chat, free on one platform
Help center

Cookieless analytics and consent

By default the script writes no cookie and no local storage. Here is how visitors are still counted, what the three tiers change, and when a banner is needed.

Privacy and compliance6 min readLast updated Sep 19, 2026TapCub team

How a visitor is counted without a cookie

On the default tier, TapCub separates visitors with an HMAC of the IP address and user agent, combined with a salt. The script itself writes nothing to the browser — no cookie, no local storage. The address is used for that hash and for geography, then discarded; it is never stored on the event row.

Two presets change how long the pseudonym lasts:

  • Balanced keeps a site-level salt, so a returning visitor can be recognized across days and "new vs returning" works.
  • Strict rotates the salt every day. Nobody is recognized across days; returning visitors are not reported.

Choose on ConfigurationSettingsPrivacy. Rows already stored are not rewritten when you switch.

The three collection tiers

TierNameWhat is collected
1Anonymous aggregateDaily rotating salt, no persistent ID of any kind. Autocapture and identity calls are dropped. Pageviews and custom events are stored.
2Cookie-free pseudonymThe default above. No cookie; visitors separated by HMAC.
3IdentifiedA device ID and a login may be used. Requires identified mode and a plan that includes it.

The project default is tier 2. Regional rules can lower the tier for visitors from specific places — the built-in rule for the EEA and the UK is tier 2 with consent required. The compliance center guide covers how to change these.

That depends on where your visitors are and which tier you use; this is not legal advice. In practice:

  • Tier 1 and tier 2 store no identifier in the browser, which is the condition most regulators attach to the cookie-banner requirement. Many TapCub sites run tier 2 without a banner outside the EEA.
  • For EEA and UK visitors the default rule requires consent. If your site has no banner, those visitors are stored at tier 1 automatically: pageviews and events still count, but there is no returning-visitor recognition and no autocapture.
  • Tier 3 writes a device ID and therefore needs consent in most jurisdictions. Pass the analytics purpose from your banner to the script; the consent API is in the developer docs.
Before consent is given the script queues events in memory by default and sends them once allowed. You can switch that to drop in the compliance center.

Do Not Track and Global Privacy Control

When the browser sends DNT: 1 or Sec-GPC: 1, the TapCub script does not load at all, and a hit that arrives anyway is stored at tier 1 with consent bits cleared. You can disable the DNT check with data-respect-dnt="false" on the script tag, but GPC is always honored at the collector. This is why a developer with privacy flags on sometimes sees no POST in the network panel — see install problems.

What this means for your numbers

  • Visitor counts are lower than cookie-based tools when those tools counted bots or multiple tabs, and higher when a banner blocked them. Trends match; totals do not — see Why UV never matches.
  • Sessions still work on every tier; they are cut by idle time, not by a cookie.
  • Funnels across days work on Balanced and on tier 3; on Strict each day is a fresh start.
  • Heatmaps and autocapture need tier 2 or 3.

Was this guide helpful?

Your answer helps us decide which guides to expand next.

Thanks for the feedback. If something is still unclear, tell us what you were looking for.

See your data clearly. Find your growth.

Every click, backed by data. Install one line of code and see your first numbers in a minute.

No credit card · Free plans for analytics and chat · Cookieless analytics