Multi-touch attribution: what it is and how to build it in 5 steps
Multi-touch attribution splits a sale's revenue across every click that led to it. See how 4 rules split credit, what they miss and how to build it in 5 steps.
Muzahid Maruf, FounderUpdated
On this page
- 01How multi-touch attribution works
- 02Which multi-touch attribution model to use
- 03Benefits of multi-touch attribution
- 04What multi-touch attribution can't tell you
- 05How to set up multi-touch attribution in 5 steps
- 06Multi-touch attribution without cookies
- 07Test the pipeline with a known journey
- 08Multi-touch attribution in TrackRev
Explore with AI
Opens this article inside the chosen assistant with a ready-made prompt.
Multi-touch attribution divides the revenue from one sale among every recorded touchpoint before it, where single-touch rules give the whole amount to the first or last click.
A SaaS buyer who clicks a podcast link on day 1, a LinkedIn post on day 9, a newsletter on day 16 and an affiliate's review link on day 24, then pays $1,200 for an annual plan on day 28, produces 4 credits that add back up to $1,200.
Setting it up takes 5 steps in a fixed order: capture each click on your own server, give the visitor an ID, link it to a person at signup, store every touch as its own row, and join the payment.
Pick the credit rule last, since any rule can be read from the same stored touches.
Key takeaways
- Multi-touch attribution divides one sale's revenue across every recorded touch, and the shares add back up to the sale. A $1,200 plan with 4 touches gives each $300 under linear and $480, $120, $120 and $480 under U-shaped.
- The build is 5 steps in a fixed order: server-side click capture, a visitor ID, an identity link at signup, one stored row per touch, and a payment join. The credit rule comes last.
- Safari deletes cookies created in JavaScript after 7 days without a visit to the site, so set the visitor ID from your own server and carry it into checkout.
- TrackRev offers last touch (the default), first touch and linear on paid plans from $39 a month, with a lookback window of 1 to 365 days that defaults to 30.
How multi-touch attribution works
Every rule takes 2 inputs: one buyer's touches in order, with timestamps, and a conversion with a dollar value. For a subscription, use the first paid charge as the conversion, since a free signup has no revenue to divide.
Google Analytics Help defines an attribution model as "a rule, a set of rules, or a data-driven algorithm" for assigning credit along the path. The shares sum to the charge, so the report ties back to what your processor collected.
One $1,200 sale under 4 rules
| Touch | Day | First touch | Last touch | Linear | U-shaped |
|---|---|---|---|---|---|
| Podcast link | 1 | $1,200 | $0 | $300 | $480 |
| LinkedIn post | 9 | $0 | $0 | $300 | $120 |
| Newsletter | 16 | $0 | $0 | $300 | $120 |
| Affiliate review link | 24 | $0 | $1,200 | $300 | $480 |
| Total | 28 | $1,200 | $1,200 | $1,200 | $1,200 |
Illustrative journey for an annual plan paid on day 28. U-shaped gives 40% to each end and shares the other 20% between the 2 middle touches.
First touch and last touch put $1,200 on 1 row, so the podcast is the whole story under one rule and worthless under the other. Linear gives every row $300.
How credit thins from 3 to 10 touches
The same $1,200 sale spread over 3 to 10 touches. Linear slices shrink in proportion, and U-shaped middle slices shrink faster because the 2 ends keep $480 each.
| Touches | Linear, each touch | U-shaped, each end | U-shaped, each middle touch |
|---|---|---|---|
| 3 | $400 | $480 | $240 |
| 4 | $300 | $480 | $120 |
| 5 | $240 | $480 | $80 |
| 6 | $200 | $480 | $60 |
| 8 | $150 | $480 | $40 |
| 10 | $120 | $480 | $30 |
Which multi-touch attribution model to use
Pick the rule by the decision it feeds. First touch shows where buyers first met you, last touch shows what closed, and linear gives every channel that appeared a share.
| Rule | Credit split | Where it is offered |
|---|---|---|
| First touch | 100% to the first touch | TrackRev, HubSpot |
| Last touch | 100% to the last touch | TrackRev, HubSpot, Google Analytics 4 (as last click) |
| Linear | Equal shares across all touches | TrackRev, HubSpot |
| U-shaped | 40% first, 40% lead conversion, 20% between | HubSpot |
| W-shaped | 30% each to first, contact-creating and deal-creating, 10% between | HubSpot |
| Data-driven | Estimated from your conversion paths | Google Analytics 4 |
As documented by HubSpot and Google, October 2026. Google removed first click, linear, time decay and position-based from Google Analytics 4 in November 2023.
At 20 paid conversions a month, 1 customer is 5% of the month's revenue, so position weights are fitted to a handful of journeys.
I would read first touch and last touch side by side first, then add linear once most journeys have 3 or more touches. The attribution models comparison covers time decay and data-driven credit.
Benefits of multi-touch attribution
Journey openers become visible. In the $1,200 example the podcast earns $0 under last touch, so a team reading only last touch would cut it, while first touch gives it $1,200 and linear $300.
Two rules side by side sort channels: high under first touch and low under last touch marks an opener, and the reverse marks a closer.
The model also matches how long SaaS buyers take. In TrackRev's Q2 2026 attribution benchmarks, the median time from first tracked click to first paid charge is 6.3 days across 4,217 workspaces.
The 75th percentile is 21.0 days and the 90th is 48.2, so 1 buyer in 10 takes longer than about 7 weeks, with room for many touches a last-click report never sees.
Commission rules get an explicit basis. On the sale above, an affiliate program paying 20% of credited revenue owes these amounts, so the rule belongs in the partner terms:
| Rule | Affiliate's credit | Payout at 20% |
|---|---|---|
| First touch | $0 | $0 |
| Linear | $300 | $60 |
| U-shaped | $480 | $96 |
| Last touch | $1,200 | $240 |
What multi-touch attribution can't tell you
Credit follows a fixed rule, so it can't show whether a channel caused a sale.
Google Ads describes Conversion Lift as an incrementality experiment: 1 audience sees your ads, a control group does not, and the gap in conversions is the lift the ads caused.
A multi-touch report has no control group, so test large budget moves with a holdout.
It also sees only recorded touches. A private recommendation, a conference conversation or an unlinked podcast mention leaves nothing to credit and lands under Direct.
Asking buyers directly catches some, and the self-reported versus tracked attribution guide covers weighing the answers.
1. Capture every click on your own server
Send every link you control through a 302 redirect on a domain you own: newsletters, ads, partner links, QR codes. The redirect writes the click before it forwards the visitor, so a blocked script can't lose it.
Store the visitor ID, link, channel, timestamp, user agent and a bot flag.
The first click mints the visitor ID, a random UUID set as a 365-day cookie in the redirect's response and appended to the destination URL as a parameter such as _vid.
A pixel on your site reads it, so the click and later page views share 1 identity. Accept only values shaped like your own IDs, or a crafted link can plant someone else's.
<script async src="https://app.trackrev.io/p.js" data-id="YOUR_WORKSPACE_ID"></script>2. Link the visitor to a person at signup
Anonymous clicks become usable once the visitor ID sits beside something a payment carries, usually an email. With the TrackRev pixel that is 1 call on the signup success page, after the pixel's trk:ready event fires.
Every earlier click from that browser then belongs to a named account.
window.trk.identify("buyer@example.com");3. Keep every touch as its own row
Store 1 row per click and never update one. A source field on the user, rewritten at each visit, is last-touch data under a multi-touch label.
Flag bot clicks when you write them and filter on the flag, or link-preview crawlers and email security scanners collect credit as if they were buyers.
4. Join the payment to the visitor
A log tied to signups ranks channels by signups, and joining the payment ranks them by revenue. Carry the visitor ID into checkout, and fall back to the customer's email. Each processor has its own field.
| Checkout | Field that carries the ID | What the docs say |
|---|---|---|
| Stripe Payment Links | client_reference_id URL parameter | Up to 200 characters; sent in the checkout.session.completed webhook |
| Stripe Checkout Sessions | client_reference_id field | A unique string, such as a customer ID or cart ID, for reconciling the session |
| Paddle Billing | customData in Paddle.Checkout.open() | Copied to the subscription and its later transactions |
| Lemon Squeezy | checkout[custom] URL parameters | Returned in the webhook's meta.custom_data |
| Polar | reference_id query parameter | Attached to the checkout session's metadata |
Fields as each processor documents them, October 2026.
Decide here how renewals inherit credit and make refunds reverse their credit. The Stripe Payment Links attribution guide shows the wiring.
5. Choose the credit rule and the lookback window
The window decides which touches are eligible, because a click older than it earns nothing. Set it past the 90th percentile of your own days from first tracked click to first charge.
Google Analytics 4 attribution settings default to 90 days for most key events and offer 30, 60 or 90.
| Window | Workspaces using it | Buyers who pay inside it |
|---|---|---|
| 7 days | 22% | Just over 50% (median is 6.3 days) |
| 14 days | 18% | 50% to 75% (75th percentile is 21.0 days) |
| 30 days | 41% | 75% to 90% (90th percentile is 48.2 days) |
| 60 days | 12% | 90% to 95% (95th percentile is 73.5 days) |
| 90 days or longer | 7% | Over 95% |
From TrackRev's Q2 2026 benchmarks across 4,217 workspaces, where the median window is 27 days. Percentiles are bounded by each workspace's own window, so the real tail is longer.
Multi-touch attribution without cookies
Safari's Intelligent Tracking Prevention is the best-documented source of cookie loss. WebKit's tracking prevention policy includes 3 caps that touch attribution.
| What is capped | Cap | Trigger |
|---|---|---|
| JavaScript cookies, LocalStorage and IndexedDB | Deleted after 7 days | No interaction with the site in that time |
| JavaScript cookies on a landing page | Expire after 24 hours | ITP detects link decoration, such as click IDs in the landing URL's parameters |
| Cookies in third-party HTTP responses | Expire after 7 days | The request uses CNAME or IP address cloaking |
Intelligent Tracking Prevention as WebKit documents it, October 2026.
The click log needs no cookie, because the redirect records the click on your server before the destination loads. A cookie only links that click to a later purchase, and 3 carriers outlast the caps:
- A cookie your own server sets in an HTTP response. The caps name script-written cookies and cloaked third-party requests, and a redirect on your domain is neither.
- The ID in the URL, appended by the redirect, read by the pixel and carried into the payment by the checkout field from step 4. Apple's Link Tracking Protection strips some known parameters, and the iOS 17 link tracking guide covers which.
- The buyer's email or login, which no browser setting clears.
Probabilistic matching on IP address and browser fingerprints breaks on shared office networks and mobile data, so I would not pay commissions on it.
A first-party ID is still a persistent identifier, so for EU or UK visitors ask a legal adviser whether it needs consent.
The TrackRev pixel waits for window.trk.grantConsent() when its script tag carries data-requires-consent="true", and the affiliate compliance guide covers the rest.
Buyers who switch devices
A cookie lives in 1 browser, so a phone click and a desktop payment look like 2 strangers. Only a shared identity joins them: the email from a signup form, or a login.
Store the visitor ID with the email at signup, and credit that ID's clicks when a charge arrives with the same email.
The join fails when the signup email and the card email differ. Key on your own user ID instead, passed as client_reference_id when you create the Stripe Checkout Session, or collect the work email before the upgrade.
TrackRev's email fallback reads only the most recently active visitor with that email, so 2 identified journeys, one on a phone and one on a laptop, are not merged.
Test the pipeline with a known journey
Click 2 tagged links in 1 browser 1 day apart, sign up, then pay a small charge and refund it, once in Safari and once in Chrome. Each symptom points at 1 step:
- Safari loses early clicks and Chrome keeps them: the ID is written only by JavaScript, so Safari's 7-day cap applies.
- No earlier clicks on the signup: identify ran before the pixel loaded, or never ran.
- Only the last click appears: a source field is overwritten at each visit.
- A charge with no credit: checkout carried no ID and the card email differs from the signup email.
Multi-touch attribution in TrackRev
TrackRev covers the 5 steps on 1 data model. Tracked links redirect on your domain and log each click server-side with a visitor ID, partner links included.
A one-line pixel hands the ID to your site, window.trk.identify(email) ties it to a person, and charges from Stripe, Paddle, Polar and Lemon Squeezy match by the checkout's ID or, failing that, by email.
The rules are last touch (the default), first touch and linear, with a lookback window of 1 to 365 days that defaults to 30. A rule applies as each charge arrives, so changing it affects later charges only.
Renewals reuse the first charge's split, and refunds drop out of channel revenue. A visit that skips your tracked links counts as a page view, not a touch.
| Plan | Price | What it covers here |
|---|---|---|
| Free | $0 | Link tracking for 50 links and 1,000 events a month; no revenue figures |
| Starter | $39 a month | Revenue by channel, 3 credit rules, 1 workspace |
| Growth | $99 a month | The same, with unlimited workspaces |
| Scale | $199 a month | The same, with priority support |
Plans from the TrackRev pricing page, October 2026.
The revenue attribution page shows the channel report. Pick another tool for position-based, time-decay or data-driven credit, or when the decisive touches happen in meetings and email threads.
Found this useful? Share it.
Frequently asked questions
- It reports revenue by channel with every recorded touch before a sale receiving a share, where single-touch rules give 1 touch everything. The shares total the sale, so the report ties back to your processor's payout.
- Single-touch rules give 1 row the full amount and every other row $0, while multi-touch rules spread it. A buyer with exactly 1 touch gets the same answer from every rule, so they diverge from the 2nd touch onward.
- Linear is a sensible first multi-touch rule. It needs no tuning and you can audit it by hand: 4 touches on a $1,200 sale get $300 each. Its gap from last touch shows which channels you were under-crediting. HubSpot's U-shaped rule keys on the interaction that created the contact, and its W-shaped rule also on the one that created the deal.
- You need an identifier that survives from first click to payment, and a cookie is only 1 option. A server-set cookie, an ID in the URL carried into checkout, or the buyer's email or login can each do it, while Safari clears script-written cookies after 7 days without a visit.
- Partly. The TrackRev free plan tracks 50 links and 1,000 events a month, and revenue by channel starts at $39 a month. Google Analytics 4 is free, but it dropped its first click, linear, time decay and position-based models in November 2023.
- No. It shows which channels were present and divides the revenue by a fixed rule. To estimate cause, run a holdout test, such as Google Ads Conversion Lift where your account has it: hold 1 channel back from a region or audience for a few weeks and compare conversions.

Written by
Founder, TrackRev.io & Contant.io
Muzahid Maruf is the founder of TrackRev.io and Contant.io. He writes about marketing attribution, link tracking, and revenue analytics for SaaS teams.
Writes about Marketing attribution · Link tracking · Revenue analytics · SaaS growth
Stop guessing where your revenue comes from.
Set up TrackRev in about five minutes. The free plan covers 1,000 events a month, no card needed.
Start free