Cookieless link tracking in 2026: what Safari, Chrome and Brave allow
Link tracking without cookies: record each click at the redirect, pass its ID along in the URL and into Stripe, and keep attribution past Safari's 7-day cap.
Muzahid Maruf, FounderUpdated
On this page
Explore with AI
Opens this article inside the chosen assistant with a ready-made prompt.
Link tracking without cookies means logging each click on your own server at the redirect, then carrying a random visitor ID through the URL, your database and the Stripe payment.
The request already says which link was hit, from where, by which browser and when, so counting needs no cookie.
Cookies matter only for recognizing the visitor later and tying them to a charge 14 days on, a week past the 7-day limit Safari has put on script cookies since Intelligent Tracking Prevention 2.1 in February 2019.
Key takeaways
- A redirect logs a click with no cookie, because the request itself names the link and the visitor's browser before the 302 fires.
- Safari deletes a site's script-written cookies after 7 idle days, and Chrome keeps third-party cookies after Google's April 22, 2025 decision.
- An ID on the user record and on the Stripe payment has no expiry date, so it outlasts a 14-day trial.
- A 2024 EDPB guideline brings tracking links within Article 5(3) of the ePrivacy Directive, so dropping cookies does not settle consent.
What browsers restrict
Chrome still allows third-party cookies. On April 22, 2025 Google kept its current approach, where users choose, and dropped the standalone prompt, and on October 17, 2025 it retired the Attribution Reporting API and Topics.
| Rule | Source | What it reaches | What it leaves alone |
|---|---|---|---|
| Script cookie limits | WebKit ITP 2.1, February 21, 2019; ITP 2.2, April 24, 2019; tracking prevention page | Cookies created in JavaScript are deleted after 7 days without interaction (a 7-day cap since Safari 12.1, iOS 12.2), or capped at 24 hours after a classified domain sends the visitor to a URL with a query string | Cookies set in an HTTP response |
| Third-party cookie block | WebKit, March 24, 2020 | Cross-site cookies, blocked by default in Safari 13.1 and iOS 13.4 | Cookies on the site the visitor is on |
| CNAME cloaking cap | WebKit, November 12, 2020 | Response cookies from a subresource that resolves through a third party's CNAME: 7 days in Safari 14 | Subdomains that resolve inside your own site |
| Bounce-tracking defense | WebKit, November 12, 2020 post and the tracking prevention page | At 10 unique redirect destinations a domain's cookies become SameSite=Strict; a classified domain with no first-party interaction in 30 days loses all its website data | Domains that redirect to fewer sites or that visitors use directly |
| Link Tracking Protection | Apple, June 2023 (iOS 17) | Tracking parameters in Messages, Mail and Safari Private Browsing; Apple names none | A short code in the URL path |
| Query stripping | Mozilla Firefox docs; Firefox 102, June 28, 2022 | 8 parameters in Strict mode, including fbclid, mc_eid and mkt_tok | utm_ tags and other unlisted names |
| Debouncing | Brave desktop 1.32 | Known tracking domains are skipped and the visitor goes straight to the destination | Domains off Brave's list |
| Hostname filters | uBlock Origin wiki | A hostname filter blocks the site and its subdomains, main document included | Hostnames on no enabled list |
Redirect through your own subdomain: a shared short domain sending traffic to hundreds of sites looks like the 10-destination bounce pattern, and a subdomain that redirects to your own pages looks less like it, though I have measured neither.
WebKit offers no list of classified domains, so check the cookie's expiry in Safari Web Inspector after a click. A click that a blocker stops never reaches your database.
Take a 14-day trial with a click on day 0 and a payment on day 14. A page that rewrites the cookie moves these dates, as the Safari ITP guide shows.
| Copy of the ID written on day 0 | Deleted on | State at the day-14 payment |
|---|---|---|
| Script cookie under the 24-hour cap | Day 1 | Gone for 13 days |
| Script cookie under the 7-day rule | Day 7 | Gone for 7 days |
| Cookie your server sets with a 365-day Max-Age | Day 365 | 351 days left |
| Row in your database or on the Stripe charge | Never | Intact on day 14 |
Link tracking without cookies, from click to charge
Follow someone who taps a tracked link in Apple Mail on an iPhone, starts the trial and pays on day 14 from a laptop. The ID can sit in 5 places, and 2 of them belong to the browser.
| Step | Where the ID lives | Safari's reach | On day 14? |
|---|---|---|---|
| Day 0, tap | Click row written at the redirect | None, no script has run | Yes |
| Day 0, landing | _vid in the URL, then a pixel cookie written by JavaScript | The parameter if Apple lists it; the cookie after 7 days idle | Cookie probably not |
| Day 0, signup | Visitor ID column on the user record | None | Yes |
| Day 14, checkout | Stripe fields written from the user record | None | Yes |
| Day 14, payment | The charge, joined to the click by the stored ID | None | Yes |
The redirect writes a row with the timestamp, link, referrer, user agent, IP address and visitor ID, then answers with an HTTP 302 before any JavaScript runs.
Its Set-Cookie header makes a server-set cookie, which WebKit exempts from the 7-day deletion unless the response comes through third-party CNAME or IP address cloaking.
Max-Age=31536000 is 365 days, inside the 400-day ceiling Chrome has applied since M104 in August 2022.
$ curl -sI https://go.example.com/spring-launch
HTTP/2 302
location: https://www.example.com/pricing?utm_source=newsletter&utm_medium=email&_vid=3f0c9b1e-5d2a-4c7e-9a41-0b6e8d1f2c34
set-cookie: vid=3f0c9b1e-5d2a-4c7e-9a41-0b6e8d1f2c34; Max-Age=31536000; Path=/; SameSite=Lax; SecureThe redirect adds the ID to the destination URL, and the landing page saves it on the first page view.
Apple publishes no parameter list, so put what you cannot lose in the link path, as the iOS 17 guide explains.
At signup, save the ID on the user record in the same request as the email, before the 7-day ITP 2.1 cookie dies.
At checkout, copy the ID from the user record into the 3 Stripe Checkout fields below. The Stripe metadata attribution setup post maps them.
| Stripe field | Holds | Limit |
|---|---|---|
| client_reference_id | One string on the Checkout Session | 200 characters |
| metadata | Key-value pairs on the session | 50 pairs, keys up to 40 characters, values up to 500 |
| subscription_data.metadata | Pairs saved on the Subscription, since session metadata does not copy there | The same 50, 40 and 500 |
Ways to carry an ID
Plausible's data policy counts visitors with a daily hash of salt, domain, IP address and user agent, and deletes the salt every 24 hours. That suits traffic counts and cannot join a click to a later payment.
| Method | How long the ID lasts | Joins a day-1 click to a day-14 payment? |
|---|---|---|
| Daily hash, as in Plausible | 24 hours | No |
| ID in the URL | 1 page view | Only if saved at once |
| Server-set cookie | 365 days | Yes, unless deleted or never sent |
| Account ID in your database | Until you delete it | Yes |
| Payment record | Permanent | Yes |
Consent after the cookie is gone
The EDPB's Guidelines 2/2023 (Version 2.0, adopted 7 October 2024) put tracking links under Article 5(3) of the ePrivacy Directive.
An identifier appended to a web address is collected when the URL is visited, which the Board treats as gaining access to the visitor's device, and its example is a store giving partners tracked links to pay commissions.
Section 3.1 says that holds even when the storage is brief, paragraph 56 leaves consent or an exemption to a case-by-case assessment, and paragraphs 54 and 55 say IP-only tracking can fall under the same article.
I'm not a lawyer, so check your own case with counsel; the affiliate compliance guide covers partner programs.
What a cookieless setup misses
A buyer who signs up with one email and pays with another breaks an email join, so the ID goes onto the payment. A phone click and a laptop payment with no login look like 2 visitors.
A podcast mention never reaches your server, so ask "How did you hear about us?" at signup.
A missing ID shows up in the report: a $1,500 newsletter placement brings 12 customers at $49 a month, and 5 of them arrive in Safari with no source and land in Direct.
| Customers with a source | Cost per customer | 12-month revenue | Revenue per $1 spent |
|---|---|---|---|
| 12 of 12 | $125.00 | $7,056 | $4.70 |
| 7 of 12 | $214.29 | $4,116 | $2.74 |
Illustrative numbers: a $1,500 placement, 12 customers paying $49 a month for 12 months.
The placement now looks 71% more expensive per customer ($214.29 against $125.00), and a team with a return threshold may cut a channel that works.
What TrackRev does at each step
TrackRev is SaaS affiliate software with link tracking built in. Its redirect sets a 365-day vid cookie, adds a _vid parameter and ties the click to revenue from Stripe, Paddle Billing, Polar, Lemon Squeezy, Creem or Dodo Payments.
| Step | Behavior |
|---|---|
| Redirect | Needs no script on your site. Logs channel, referrer, device, browser, OS, country and city, flags bot traffic and sends a 302 from the shared short domain or a custom tracking domain (one CNAME to cname.trackrev.io, SSL through Let's Encrypt) |
| Cookie and handoff | Shared short domain: a random vid cookie in the 302, 365 days, SameSite=Lax. Every redirect adds UTM tags and a _vid parameter |
| Pixel | One script tag reads _vid, accepts only a UUID and writes its own copy as a cookie with JavaScript, so Safari's 7-day rule applies to it |
| Binding | trk.identify(email) ties the visitor to an email, and the pixel stamps the visitor ID onto Stripe Payment Links and Buy Buttons |
| Sync | Hourly, with an optional webhook; matches on charge metadata, then Checkout Session reference or metadata, then customer email (Stripe integration) |
| Window | 30 days by default, adjustable from 1 to 365; renewals credit the original click |
The Free plan covers 50 links and 1,000 tracked events a month for link tracking, with revenue figures hidden. Revenue by channel needs a paid plan, from Indie at $29 a month (pricing).
A daily-hash analytics tool is simpler if you only want traffic counts, and a link that ends on an App Store listing logs the click but has no pixel or checkout of yours to carry the ID onward.
The first-party tracking page shows the product.
Found this useful? Share it.
Frequently asked questions
- Yes, for counting. A redirect already knows which link was hit and by which browser, so one database row per click needs no cookie.
- Not by default. Compliance depends on what you collect, why and on what legal basis, and in the EU Article 5(3) of the ePrivacy Directive can apply without any cookie.
- Open one link in Brave 1.32 or later and in Chrome with uBlock Origin switched on, then look for a new row in your click log. No row means the request never arrived.
- A short code in the path has no query string for Apple's protection to remove. Apple says nothing about parameters a redirect adds, so test that hop from Messages, Mail and a Private tab.
- No. WebKit applies the same 7-day deletion to LocalStorage, IndexedDB, SessionStorage, media keys and service worker registrations, so only a value kept on your server avoids it.
- That varies with what you switch on. TrackRev's pixel sets a first-party cookie and can wait for your consent tool through the data-requires-consent attribute, while click capture adds no script.

Written by
Founder, TrackRev.io & Contant.io
Muzahid Maruf founded TrackRev.io, SaaS affiliate software with no limit on tracked revenue, and Contant.io. He writes about affiliate programs.
Writes about Marketing attribution · Link tracking · Revenue analytics · SaaS growth
Stop guessing where your revenue comes from.
Set up TrackRev in about five minutes. The free plan covers 1,000 events a month, no card needed.
Start free