How to track users for analytics in a privacy-first, cookie-less future
narrator.ai
narrator.ai
Edit: I honestly have no idea, I haven't read the regulations and I'm curious if any experts know. Seems sleazy regardless!
I mean my gut feeling is that you're correct, but I kind of wonder about this case.
edit: A cursory reading of this site makes me think you are correct:
Data protection regulations (esp. GDPR) are totally unconcerned with the distinction between first and third party cookies. They are concerned with data collection permissions and scopes, regardless of the technology used.
If you are capturing information which is not essential to the service/product you are offering at that moment and in that session, then you need specific permission - even for your own cookies. And if you did not have that permission at the time it was collected then you cannot merge it into records after conversion.
Let's say that I'm on a desktop browsing a shopping site. I'm on shopping.site/product/coolthing.html?tracker=12345. I share this with my friend on a mobile device because it looks like something of interest to them.
Now how do you handle the other person having the same tracker as the initial person? You end up with a scenario where two different people, with different interests, are browsing the site. Even if they convert you have situations along the lines of: no conversions, person A converts, person B converts, both convert. How do you handle this?
With cookies the sharing of the URL would avoid this scenario since cookies would be separated between people.
I should also point out that the url tracker isn't meant to be persisted across page views. It's only done once at the moment that the user identifies themselves to your service.
Even if they identify themselves via ordering something, is it an unusual workflow to share a link after? For example "I got this new coffee, I'm excited, here's the link to what I ordered my friend!"
So in the example you gave, the user who opens that links becomes tied to that cookie from the time they open the order to the next linked event. This is really critical because it will continue to stitch the users identity over time.
If link sharing is happening a lot, you can choose to not use that linkage foe identity resolution.
Does this help clarify the approach?
AFAIK, they are starting to standardize the sharing of referrer. For most people, this is limiting the sharing. However, they used to have an easy to find GUI option to just opt out of referrers in general. That is no longer the case.
When companies talk about how they anonymize data before uploading it to the cloud, so it can’t be traced back to you, they should get sued. It is so easy to connect data to their sources with just a little bit more information
Yes, that is in fact the point.
Look, I know there are strong financial incentives to build individual user profiles and doing it this way may not violate the letter of the law, but it sure as hell violates the spirit. If we ask a user if they're willing to be tracked and they do everything in their power to tell us no then I'm not sure how comfortable we should be doing it anyway.
If I'm reading correctly it's basically saying 'once a user has identified themselves to you, then you can go back and figure out the steps they took before that'
As a person, if a company knows what I did right before I bought their product (say in that session) I think I'm ok with that. If they follow me onto other websites or other devices then that feels a lot more invasive.
All data that is collected whilst a user is anonymous was done so under the condition of anonymity. Breaking that anonymity by assigning unknown-user data to the now-known user is retroactively changing that user's consent without getting their agreement. Like saying "I know you chose not to be tracked, but now we've had some interaction with you we don't think you meant it". But on what basis?
Not only is this morally/ethically incorrect, it is probably illegal as it is a clear violation of data collection laws. Consent was not given for those prior activities to be tracked. Current consent does not change that.
Edit: Even the suggestion that the stitching together of the data could use the non-PII that was obtained does not get around the fact that permission was not given and by joining the sessions/activity that way you would in fact be de-anonymising (non-PII gets associated with PII).
1. The government can always use the excuse of "public safety." However,
2. A company that's selling brooms shouldn't have all kinds of access to tracking people. The public doesn't benefit from that.
Some activities and cookies are allowed by GDPR without requesting consent, and anonymous analytics (even google analytics) is included in this, so you don’t actually even need a cookie banner to do what you’re trying to do here...
I think from a legal standpoint this is no better than cookies, it doesn’t change whether you need consent or not.
Ultimately, the site is not allowed to collect data without your consent, but many sites illegally set cookies or store your data in logs before you consent, or even if you decline. With cookies, it is easy to detect bad actors, but not so much with logging.
And how wait to for their one mistake to retrace all their steps and then identify their history without their consent
---------
Track me on your website alright. Tracking me everywhere without my consent? You're a creep and nothing less
As an example, think of a Shopify check out flow. Every user has a unique checkout url. Once they purchase you can use that checkout ID in your warehouse to join with the page view that had the anonymous Id on it. So you’ll have a page view with the anonymous Id with a url with a unique checkout Id that you can use to join to the ultimate identified user (assuming all your page view and Shopify data are in one place, your data warehouse).
Let me know if I understood your question!
If a person has jumped through hoops to say they don't want to be tracked, why look for ways to still do it?
It's like putting up curtains to keep people from looking in my window, but then you realize you can still see inside if you crouch down really low and look through the 1/8" space between the bottom of the curtain and the window sill.
This puts me in a difficult position of supporting legislation that might be overly harsh like the Do Not Call list back in the 1990s. It pretty much killed off telemarketing for a while. Sad, but the public got fed up with an entire industry that showed it had no regard for the public.
I've got friends who are in marketing and ad-tech and I care about them, their business and success. But when I want to withdraw my consent to be tracked, I want that same level of care and respect.
This extends to support. I hate submitting a support ticket to just be told to go view the docs that I already viewed, or try things I have already done. As a customer, I want you to know I did that and to help me.
All this is trying to do is allow company to understand their customer within their own platform and own data.
This is not trying to fingerprint users or track everything they do on all websites like Facebook and other platforms.
I hope this clears up the motivation. In short, it is to resolve issues in using the data that a company has internally and is not about creeping on users across the internet.
I don't disagree that price gouging occurs in many markets - and I agree that an international GDPR would be beneficial to people - but good pricing also doesn't just occur naturally it's a product of experimentation.
Sometimes that's razor-thin margins. Sometimes it lets you get away with high margins.
For example this quote from the article: "Add a unique identifier to all urls on your site when you know who the user is."
I don't see how our legal would allow us to do this with European customers without explicit opt-in consent since this kind of tracking and data processing cannot be deemed a legitimate requirement for the core function of the service.
If the same service can be given to the visitor without the unique identifier in the URL, then I see no way to avoid asking for consent.
https://gdpr.eu/recital-30-online-identifiers-for-profiling-...
If you look at the examples given they're more like identifiers to something else -- an order id or subscription id.
Wouldn't tracking something like an order (but not the user directly) be ok with GDPR?
Example: if you buy a lawnmower, the seller may he required to notify you of any safety recalls for many years (depending on location). GDPR does not change this requirement for saving personal contact data with the order data, even if the buyer later says “forget me”.
At this point the tracking of the online identifier has certainly passed the threshold into tracking an individual for reasons not directly related to the service.
https://gdpr.eu/article-4-definitions/
"1. ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;"
The order number in this case falls under "an identification number" and "an online identifier" at the very least.
"2. ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;"
What is happening is at the very least processing, recording, storing, dissemination, combination of that data.
What is the EU going to do anyway? I've yet to see any meaningfull challenge from EU about GDPR.