Cookieless link tracking in 2026: what Safari, Chrome and Brave allow

Link tracking without cookies: record each click at the redirect, pass its ID along in the URL and into Stripe, and keep attribution past Safari's 7-day cap.

Muzahid Maruf — Founder of TrackRev.io

Muzahid MarufUpdated

Link tracking · 8 min read
On this page
  1. 01What browsers restrict
  2. 02Link tracking without cookies, from click to charge
  3. 03Ways to carry an ID
  4. 04Consent after the cookie is gone
  5. 05What a cookieless setup misses
  6. 06What TrackRev does at each step

Explore with AI

Opens this article inside the chosen assistant with a ready-made prompt.

Link tracking without cookies means logging each click on your own server at the redirect, then carrying a random visitor ID through the URL, your database and the Stripe payment.

The request already says which link was hit, from where, by which browser and when, so counting needs no cookie.

Cookies matter only for recognizing the visitor later and tying them to a charge 14 days on, a week past the 7-day limit Safari has put on script cookies since Intelligent Tracking Prevention 2.1 in February 2019.

Key takeaways

  • A redirect logs a click with no cookie, because the request itself names the link and the visitor's browser before the 302 fires.
  • Safari deletes a site's script-written cookies after 7 idle days, and Chrome keeps third-party cookies after Google's April 22, 2025 decision.
  • An ID on the user record and on the Stripe payment has no expiry date, so it outlasts a 14-day trial.
  • A 2024 EDPB guideline brings tracking links within Article 5(3) of the ePrivacy Directive, so dropping cookies does not settle consent.

What browsers restrict

Chrome still allows third-party cookies. On April 22, 2025 Google kept its current approach, where users choose, and dropped the standalone prompt, and on October 17, 2025 it retired the Attribution Reporting API and Topics.

RuleSourceWhat it reachesWhat it leaves alone
Script cookie limitsWebKit ITP 2.1, February 21, 2019; ITP 2.2, April 24, 2019; tracking prevention pageCookies created in JavaScript are deleted after 7 days without interaction (a 7-day cap since Safari 12.1, iOS 12.2), or capped at 24 hours after a classified domain sends the visitor to a URL with a query stringCookies set in an HTTP response
Third-party cookie blockWebKit, March 24, 2020Cross-site cookies, blocked by default in Safari 13.1 and iOS 13.4Cookies on the site the visitor is on
CNAME cloaking capWebKit, November 12, 2020Response cookies from a subresource that resolves through a third party's CNAME: 7 days in Safari 14Subdomains that resolve inside your own site
Bounce-tracking defenseWebKit, November 12, 2020 post and the tracking prevention pageAt 10 unique redirect destinations a domain's cookies become SameSite=Strict; a classified domain with no first-party interaction in 30 days loses all its website dataDomains that redirect to fewer sites or that visitors use directly
Link Tracking ProtectionApple, June 2023 (iOS 17)Tracking parameters in Messages, Mail and Safari Private Browsing; Apple names noneA short code in the URL path
Query strippingMozilla Firefox docs; Firefox 102, June 28, 20228 parameters in Strict mode, including fbclid, mc_eid and mkt_tokutm_ tags and other unlisted names
DebouncingBrave desktop 1.32Known tracking domains are skipped and the visitor goes straight to the destinationDomains off Brave's list
Hostname filtersuBlock Origin wikiA hostname filter blocks the site and its subdomains, main document includedHostnames on no enabled list

Redirect through your own subdomain: a shared short domain sending traffic to hundreds of sites looks like the 10-destination bounce pattern, and a subdomain that redirects to your own pages looks less like it, though I have measured neither.

WebKit offers no list of classified domains, so check the cookie's expiry in Safari Web Inspector after a click. A click that a blocker stops never reaches your database.

Take a 14-day trial with a click on day 0 and a payment on day 14. A page that rewrites the cookie moves these dates, as the Safari ITP guide shows.

Copy of the ID written on day 0Deleted onState at the day-14 payment
Script cookie under the 24-hour capDay 1Gone for 13 days
Script cookie under the 7-day ruleDay 7Gone for 7 days
Cookie your server sets with a 365-day Max-AgeDay 365351 days left
Row in your database or on the Stripe chargeNeverIntact on day 14

Follow someone who taps a tracked link in Apple Mail on an iPhone, starts the trial and pays on day 14 from a laptop. The ID can sit in 5 places, and 2 of them belong to the browser.

StepWhere the ID livesSafari's reachOn day 14?
Day 0, tapClick row written at the redirectNone, no script has runYes
Day 0, landing_vid in the URL, then a pixel cookie written by JavaScriptThe parameter if Apple lists it; the cookie after 7 days idleCookie probably not
Day 0, signupVisitor ID column on the user recordNoneYes
Day 14, checkoutStripe fields written from the user recordNoneYes
Day 14, paymentThe charge, joined to the click by the stored IDNoneYes

The redirect writes a row with the timestamp, link, referrer, user agent, IP address and visitor ID, then answers with an HTTP 302 before any JavaScript runs.

Its Set-Cookie header makes a server-set cookie, which WebKit exempts from the 7-day deletion unless the response comes through third-party CNAME or IP address cloaking.

Max-Age=31536000 is 365 days, inside the 400-day ceiling Chrome has applied since M104 in August 2022.

Check what a redirect sends (example output)
$ curl -sI https://go.example.com/spring-launch
HTTP/2 302
location: https://www.example.com/pricing?utm_source=newsletter&utm_medium=email&_vid=3f0c9b1e-5d2a-4c7e-9a41-0b6e8d1f2c34
set-cookie: vid=3f0c9b1e-5d2a-4c7e-9a41-0b6e8d1f2c34; Max-Age=31536000; Path=/; SameSite=Lax; Secure

The redirect adds the ID to the destination URL, and the landing page saves it on the first page view.

Apple publishes no parameter list, so put what you cannot lose in the link path, as the iOS 17 guide explains.

At signup, save the ID on the user record in the same request as the email, before the 7-day ITP 2.1 cookie dies.

At checkout, copy the ID from the user record into the 3 Stripe Checkout fields below. The Stripe metadata attribution setup post maps them.

Stripe fieldHoldsLimit
client_reference_idOne string on the Checkout Session200 characters
metadataKey-value pairs on the session50 pairs, keys up to 40 characters, values up to 500
subscription_data.metadataPairs saved on the Subscription, since session metadata does not copy thereThe same 50, 40 and 500

Ways to carry an ID

Plausible's data policy counts visitors with a daily hash of salt, domain, IP address and user agent, and deletes the salt every 24 hours. That suits traffic counts and cannot join a click to a later payment.

MethodHow long the ID lastsJoins a day-1 click to a day-14 payment?
Daily hash, as in Plausible24 hoursNo
ID in the URL1 page viewOnly if saved at once
Server-set cookie365 daysYes, unless deleted or never sent
Account ID in your databaseUntil you delete itYes
Payment recordPermanentYes

The EDPB's Guidelines 2/2023 (Version 2.0, adopted 7 October 2024) put tracking links under Article 5(3) of the ePrivacy Directive.

An identifier appended to a web address is collected when the URL is visited, which the Board treats as gaining access to the visitor's device, and its example is a store giving partners tracked links to pay commissions.

Section 3.1 says that holds even when the storage is brief, paragraph 56 leaves consent or an exemption to a case-by-case assessment, and paragraphs 54 and 55 say IP-only tracking can fall under the same article.

I'm not a lawyer, so check your own case with counsel; the affiliate compliance guide covers partner programs.

What a cookieless setup misses

A buyer who signs up with one email and pays with another breaks an email join, so the ID goes onto the payment. A phone click and a laptop payment with no login look like 2 visitors.

A podcast mention never reaches your server, so ask "How did you hear about us?" at signup.

A missing ID shows up in the report: a $1,500 newsletter placement brings 12 customers at $49 a month, and 5 of them arrive in Safari with no source and land in Direct.

Customers with a sourceCost per customer12-month revenueRevenue per $1 spent
12 of 12$125.00$7,056$4.70
7 of 12$214.29$4,116$2.74

Illustrative numbers: a $1,500 placement, 12 customers paying $49 a month for 12 months.

The placement now looks 71% more expensive per customer ($214.29 against $125.00), and a team with a return threshold may cut a channel that works.

What TrackRev does at each step

TrackRev is SaaS affiliate software with link tracking built in. Its redirect sets a 365-day vid cookie, adds a _vid parameter and ties the click to revenue from Stripe, Paddle Billing, Polar, Lemon Squeezy, Creem or Dodo Payments.

StepBehavior
RedirectNeeds no script on your site. Logs channel, referrer, device, browser, OS, country and city, flags bot traffic and sends a 302 from the shared short domain or a custom tracking domain (one CNAME to cname.trackrev.io, SSL through Let's Encrypt)
Cookie and handoffShared short domain: a random vid cookie in the 302, 365 days, SameSite=Lax. Every redirect adds UTM tags and a _vid parameter
PixelOne script tag reads _vid, accepts only a UUID and writes its own copy as a cookie with JavaScript, so Safari's 7-day rule applies to it
Bindingtrk.identify(email) ties the visitor to an email, and the pixel stamps the visitor ID onto Stripe Payment Links and Buy Buttons
SyncHourly, with an optional webhook; matches on charge metadata, then Checkout Session reference or metadata, then customer email (Stripe integration)
Window30 days by default, adjustable from 1 to 365; renewals credit the original click

The Free plan covers 50 links and 1,000 tracked events a month for link tracking, with revenue figures hidden. Revenue by channel needs a paid plan, from Indie at $29 a month (pricing).

A daily-hash analytics tool is simpler if you only want traffic counts, and a link that ends on an App Store listing logs the click but has no pixel or checkout of yours to carry the ID onward.

The first-party tracking page shows the product.

Found this useful? Share it.

PostLinkedIn

Frequently asked questions

Muzahid Maruf — Founder of TrackRev.io

Written by

Muzahid Maruf

Founder, TrackRev.io & Contant.io

Muzahid Maruf founded TrackRev.io, SaaS affiliate software with no limit on tracked revenue, and Contant.io. He writes about affiliate programs.

Writes about Marketing attribution · Link tracking · Revenue analytics · SaaS growth

Stop guessing where your revenue comes from.

Set up TrackRev in about five minutes. The free plan covers 1,000 events a month, no card needed.

Start free