Analytics without a cookie banner for EU SaaS founders

When sessionStorage-only counting is enough for indie SaaS, what GDPR conversations you still need, and what you should not promise visitors.

All guides on this topic: Cookieless analytics for EU founders

European founders hear two loud messages at once: you need analytics to know if marketing works, and you need a consent banner because GDPR exists. Both are partly true. Neither tells you what a ten-person SaaS actually needs on its marketing site.

This guide covers cookieless analytics guides guides. The honest version: many indie products can measure traffic and revenue without setting browser cookies, using sessionStorage for a per-tab session identifier. That choice removes a common trigger for cookie banners on first-party analytics. It does not remove legal judgment, does not make you invisible to regulators, and does not give you Google Analytics–grade cross-device identity.

If you sell B2B software from France, Germany, or anywhere in the EEA, you are probably not trying to build an ad network. You want to know whether Tuesday’s newsletter beat last month’s, whether /pricing converts better than /, and whether Stripe revenue moved with traffic. That is a narrower problem than enterprise MarTech, and the privacy tradeoffs are narrower too, as long as you describe them honestly.

What “cookieless” means in practice (and what it does not)

Cookieless in product copy usually means: the tracker does not call document.cookie. KiboData’s script follows that rule: it stores a generated session_id in sessionStorage, batches pageviews to your ingest endpoint, and exposes optional conversion events (signup, checkout_completed, and similar) without planting persistent identifiers in the cookie jar.

What remains:

  • Network requests to your analytics host (or your own domain proxy) with URL, referrer, and optional UTM parameters.
  • Session continuity only while the browser tab or window session lasts, close the tab, open a new one, and you are a new session for counting purposes.
  • Server-side logs at your CDN or host, which are separate from your product analytics and may have their own retention policies.

What cookieless does not automatically mean:

  • “No personal data.” IP addresses and full URLs can still be personal data in some interpretations; minimization and retention matter.
  • “No consent ever.” Some EU sites still show banners for analytics they classify as non-essential; others rely on legitimate interest or strictly necessary first-party measurement. We are not your lawyer. This article describes engineering reality so your counsel or DPO can map it to your policy.
  • “Accurate unique visitors forever.” Without cookies or logged-in identity, “unique visitor” is always an estimate.

Related deep dives: sessionStorage tradeoffs, France-focused practical notes, and what you cannot measure without cross-site IDs.

Why cookie banners became the default (and why SaaS sites chafe)

Large analytics stacks were built for advertising: persistent IDs, cross-site graphs, remarketing pools. Browsers responded with ITP, ETP, and cookie consent frameworks because those IDs followed people across sites.

A bootstrapped SaaS marketing site is a different animal:

  • One primary domain (maybe a docs subdomain).
  • Traffic from newsletter, social, SEO, and Product Hunt, not programmatic display.
  • Revenue from Stripe or Gumroad, not from selling the audience.

When your measurement goal is “did this traffic correlate with money on our domain?”, you do not need a third-party cookie that survives for a year. You need stable enough session counting to attribute a checkout webhook to the landing path and UTMs captured on first page load in that tab.

Removing cookies does not remove the psychological weight of analytics. Visitors still see a script load. Privacy-conscious users still block trackers. Your privacy policy should still say what you collect and why. The win is narrower: you are not running a surveillance graph for ads, and you are not training users to click “Accept all” out of habit on every indie tool they try.

sessionStorage as a session key, the engineering compromise

sessionStorage is same-origin, tab-scoped storage. A typical pattern:

  1. On first pageview, if no session_id exists, generate a random string and store it.
  2. Attach that session_id to each event in the batch sent to /api/track (or your self-hosted endpoint).
  3. On checkout, your server receives amount and metadata; you join on time window, session, or explicit metadata you passed, not on a cross-site ID graph.

Pros for EU indie SaaS:

  • No cookie banner solely because of a first-party analytics cookie (many teams still add a banner for other tools, audit your full tag list).
  • UTMs can live in sessionStorage for the session so internal navigation does not strip attribution reads.
  • Aligns with a “we only measure our own site” story.

Cons you must accept:

  • New tab = new session. Power users with many tabs inflate session counts.
  • Mobile backgrounding and some in-app browsers behave oddly; sessions can split or merge in ways that look like noise on small samples.
  • Returning tomorrow is a new session unless the user logs in and you tie events to account ID server-side (a different design).

KiboData is explicit about this: one lightweight script, no cookies, sessionStorage for session_id. It is built for founders who want traffic timelines, UTM breakdowns, and webhook revenue in one view, not for rebuilding Meta’s attribution layer.

GDPR-shaped questions founders actually ask

These come up in support channels and founder Slacks. Answers here are product and engineering shaped, not legal advice.

Do I need consent for first-party, cookieless analytics? Depends on jurisdiction, whether you use only first-party hosting, whether IPs are truncated, retention, and whether you combine data with other sources. Many micro-SaaS teams pair minimal first-party analytics with a short privacy policy and avoid third-party ad pixels entirely. Document your stack; do not copy a banner because a competitor has one.

Is sessionStorage “strictly necessary”? It is not authentication. Do not claim it is strictly necessary for the site to function unless your counsel agrees. The honest pitch is proportionate measurement for site improvement and marketing ROI, with minimal identifiers and no cross-site tracking.

What about CNIL, ICO, and “analytics cookies” guidance? Regulators distinguish exempt analytics (often tightly defined) from broader tracking. Cookieless first-party measurement may fit a different box than Google Analytics with _ga. Read current guidance for your country, the France indie notes guide summarizes practical patterns French founders use without pretending to be a law firm.

Do I need a DPA with KiboData? If you use a hosted analytics vendor, check their DPA, subprocessors, and EU hosting story. If you self-host ingest on your domain, your responsibilities shift. Either way, data minimization beats checkbox compliance.

What you can measure well without cookies

On a single domain with webhook revenue, cookieless analytics is often good enough for:

  • Daily and weekly traffic trends (pageviews and sessions).
  • UTM source/medium/campaign performance when links are tagged consistently.
  • Landing path breakdowns (/, /pricing, blog posts).
  • Campaign spikes when a newsletter or launch sends a visible hump.
  • Revenue per visitor over a window when checkout events hit the same project.
  • Bot and crawler visibility if your stack classifies user agents (useful when AI crawlers hit docs).

These metrics drive real decisions: pause a channel that sends junk traffic, fix a landing page that converts, pin a date range around a price change. They do not require knowing that the same human opened your site on phone and laptop as one “user.”

What you should not pretend to measure

Without persistent cross-device IDs (and often without logins on marketing pages), you cannot honestly claim:

  • True unique visitors across months with census accuracy.
  • Multi-touch attribution across seven ad networks and three subdomains.
  • Return visitor rates that match ad platforms’ dashboards.
  • Cross-site journeys (your marketing site → partner blog → back) unless you control identity on both sides.

Pretending otherwise erodes trust with technical buyers, exactly the audience EU B2B SaaS courts. See also what you cannot measure without cross-site IDs lists failure modes and better-framed alternatives.

Composing a sane stack for EU indie SaaS

A pattern we see work:

  1. One first-party analytics script (cookieless session model) on marketing + docs that matter for conversion narrative.
  2. No third-party marketing pixels until you have spend that justifies consent UX and legal review.
  3. Stripe (or similar) webhooks for revenue truth, never trust pageview-only “purchases.”
  4. UTM discipline documented in Notion, see the UTM attribution guides if tagging is chaotic.
  5. Privacy policy that names the analytics host, data fields, retention, and contact, updated when you add tools.

Optional: server-side access logs for security, separate from product analytics. Do not double-count them as “visitors” in your head.

Cookie banners when you still need one

You might still deploy a banner because:

  • You run ads (Meta, LinkedIn) with pixels.
  • You embed YouTube, Intercom, or other third parties that set cookies.
  • Your legal counsel wants explicit opt-in for any non-essential analytics.

Cookieless first-party measurement can shrink the banner’s scope: fewer vendors, clearer “reject” path, less all-or-nothing fatigue. If the only tracker is your own subdomain with sessionStorage, some teams move analytics under “legitimate interest” with an easy opt-out link, again, counsel decides.

Implementing without overselling to users

Marketing copy should match mechanics:

  • Say “session-based counting” rather than “100% private” or “zero tracking.”
  • Say “no cookies for analytics” rather than “GDPR compliant out of the box.”
  • Show what fields leave the browser (path, referrer, session id, UTMs).
  • Offer contact for deletion requests if you store events with identifiers.

KiboData’s tracker stays small, defaults to batched ingest, and avoids cookies by design. It will not replace a compliance program. It will stop you from installing a heavyweight suite just to answer “did Product Hunt week beat baseline?”

Migration path from Google Analytics

Teams often migrate in stages:

  1. Run parallel for two weeks if GA is already consented, compare trends, not absolute numbers.
  2. Remove GA from production once UTMs and webhooks flow to the new tool.
  3. Update privacy policy and remove obsolete cookie declarations.
  4. Retrain yourself to think in sessions and pinned weeks, not GA’s “users” metric.

Expect session counts to differ from GA’s cookie-based “users.” That is not a bug if you document the definition.

Weekly ritual: proportionate analytics

Spend fifteen minutes:

  1. Open a 28-day traffic view.
  2. Check one UTM dimension and one landing path.
  3. Compare revenue in the same window (webhook-sourced).
  4. Write one sentence in your changelog: what you learned, what you will not overfit on small samples.

If the numbers are flat, you saved a day of dashboard tinkering. If something moved, you have a hypothesis, validate with another week, not another tracker.

How these guides fit together

What to do tomorrow

  1. Inventory scripts on your marketing site, list every domain that sets cookies.
  2. Decide your visitor unit (sessions) and stick to it in meetings.
  3. Wire one test checkout to your analytics project so revenue and traffic share dates.
  4. Update your privacy page with plain language about session-based analytics.

Cookieless analytics for EU SaaS is not a magic exemption from privacy law. It is a proportionate way to steer a small product without turning your landing page into a consent wall for ad-tech you do not use. Measure what you can defend, say what you cannot, and ship the next improvement with eyes open.

More on this topic