That’s pretty clever. I think if you really want to keep it privacy respecting, you should stop counting at 1 - so you can distinguish the first vs subsequent visits, but you can’t tell if someone has visited 2 or 200 times.
If 100 people visited once, and one person visited twice... then a new request with visitCount=3 is that second person.
Your argument seems to be that this timestamp in the header could possibly be used as a lookup key in a database of visitors. I think that's a stretch, but in any case that database would be the privacy violating thing. This header is completely anonymous.
Maybe only one user will have over 100 visits, and then you can uniquely identify them.