Investors, growth coaches, and ad platform reps speak as if every website shares one global identity graph: the same person on phone, laptop, and work desktop, stitched across Facebook, Google, and your checkout. Cookieless first-party analytics does not live in that world. Neither does most indie EU SaaS, and pretending otherwise creates bad roadmaps and embarrassing security reviews.
A deeper look at cookieless analytics guides guides. Read analytics without a cookie banner for EU SaaS for strategy and sessionStorage visitor counting tradeoffs for how sessions behave. Here: what breaks without cross-site identifiers, and better questions that still move revenue.
What we mean by “cross-site IDs”
Cross-site identity requires a stable identifier that survives:
- Multiple pages and multiple domains in an ad network’s ecosystem, or
- Long time gaps with storage that outlives a tab (cookies, device IDs, logged-in ad profiles).
Examples: _fbp, _ga, UID2, many CDP anonymous_id cookies, mobile ad IDs.
KiboData’s default tracker deliberately avoids that class: sessionStorage `session_id`, first-party ingest, no cookie jar for analytics. You measure your origin for this session well. You do not join that session to a stranger’s blog or to Meta’s view of the customer.
Cannot #1: Census-accurate “unique visitors” over months
Without persistent first-party storage (or logins), you cannot count how many distinct humans touched your site in Q3 with census accuracy.
Sessions split on new tabs; shared computers merge unlike humans; bots inflate counts. Cookie-based analytics also lie, just differently (ITP, multi-device).
Do instead:
- Report sessions and pageviews with a footnote definition.
- Use signup and paid accounts for human-grounded growth metrics.
- Compare week-over-week session trends for campaigns, not absolute uniques vs a vendor benchmark.
Cannot #2: True multi-touch attribution across channels
Multi-touch attribution (MTA) assigns fractional credit across touchpoints: ad click, podcast, newsletter, demo call, pricing page. MTA at scale needs identity resolution across sessions and often third-party data.
SessionStorage on your marketing domain sees:
- UTMs on entry URLs in this tab.
- Paths on your host before checkout redirect.
It does not see:
- Brand search two days later without UTMs (looks “direct”).
- Podcast influence with no tagged link.
- Sales call closed in Zoom.
Do instead:
- First-touch UTM in session for self-serve funnel (honest label: first touch in this session).
- Last non-direct touch heuristics only with documented rules, still session-bound.
- Post-purchase surveys (“How did you hear about us?”) for qualitative mix, underrated for indie SaaS.
- Stripe metadata populated from sessionStorage before Checkout when redirects cooperate, see Stripe checkout tied to traffic.
Cannot #3: Cross-domain journeys you do not control
If marketing lives on getproduct.com and the app on app.product.com, sessionStorage does not cross registrable domains. If a partner blog links without UTMs, you see referrer maybe, not a unified funnel across sites.
Do instead:
- Consolidate marketing on one canonical domain when possible.
- Use consistent UTMs on every external placement you control.
- Put signup and paid events on the app origin with the same analytics project if the script can run there, now identity is account-based post-login, which is what you wanted anyway.
Cannot #4: Cross-device “same user” before login
User researches on phone, buys on desktop. SessionStorage cannot link those without:
- User logging in on both (server-side user id), or
- A persistent cookie/login provider you chose to add, or
- Probabilistic fingerprinting (do not do this for indie B2B; legal and brand risk).
Do instead:
- Optimize mobile landing and desktop checkout separately via session segments, not fictional unified users.
- Email magic links that carry campaign context in query params on second device, new session, but UTMs can be present if you design links that way.
Cannot #5: Remarketing audience sizes
Remarketing needs ad network cookies and consent frameworks. Cookieless analytics is not a replacement for Meta Custom Audiences. If your growth plan says “retarget blog readers,” you need ad pixels and budget, outside this stack’s default tools.
Do instead:
- Newsletter capture on high-intent pages, you own the list without remarketing pools.
- Content that earns return direct traffic, measurable as direct/referrer spikes, not as individual stalking.
Cannot #6: View-through display attribution
View-through claims an ad impression caused a conversion without a click. That is ad-network machinery. Your first-party session tracker will not validate TV-style attribution fantasies.
Do instead:
- Measure clicked campaigns with UTMs.
- Run geo or time-boxed experiments (turn spend on/off) and read session + revenue lifts, noisy but honest at small scale.
Cannot #7: Long offline sales cycles with only marketing analytics
Enterprise deals close in Slack threads and quarterly budgets. Marketing sessions in March may correlate with a wire in September. SessionStorage will not stitch that arc.
Do instead:
- CRM stage for pipeline; marketing analytics for top-of-funnel efficiency.
- Self-serve RPV for PLG motion, revenue per visitor guides, separate from sales-led ARR.
What you *can* still measure well (recap)
Staying first-party and cookieless preserves strong signals:
| Question | Feasible? |
|---|---|
| Did newsletter week beat baseline sessions? | Yes |
| Which landing path preceded checkout in same session? | Often |
| Revenue per session by UTM source? | Yes, with webhooks |
| Bot vs human crawl spikes on docs? | Yes, with UA classification |
| Exact same human across devices pre-login? | No |
How ad platforms disagree with your dashboard forever
Meta and Google report “conversions” using their IDs, modeled conversions, and different attribution windows. Your cookieless dashboard will never match Ads Manager, not because your engineer failed, but because definitions differ.
Founder rule: pick one internal source of truth for weekly decisions (usually bank + your analytics + Stripe). Use ad dashboards for relative creative tests, not reconciliation to the cent.
Legal and trust upside of admitting limits
EU B2B buyers increasingly distrust surveillance marketing. Saying “we use session-based analytics on our domain only; we do not buy brokered identity” is a feature in security reviews, especially paired with French or German privacy pages described in France indie SaaS practical analytics notes.
Overselling attribution erodes trust faster than admitting “we see sessions, not souls.”
Architecture patterns that recover *some* identity ethically
Without cross-site ad IDs, you can still sharpen signal:
- Authentication boundary: after signup, events attach to
user_idserver-side; pre-signup remains session-based. - Checkout metadata: pass
session_idor first-touch UTM into Stripe Customer metadata for support lookups (not for reselling data). - Pinned date ranges: compare launch weeks instead of chasing user-level cohorts in marketing analytics, marketing pulse guides.
- First-party subdomain:
t.yourdomain.comingest keeps cookies unnecessary while improving control.
Each pattern adds engineering; indie teams should add only what answers a question they will actually act on.
Red flags in vendor copy (including your own)
Walk away or rewrite when you see:
- “100% accurate unique visitors” without defining unit.
- “Full funnel attribution” on marketing site only.
- “GDPR compliant” as a substitute for subprocessors list.
- “Cookieless” while loading five third-party tags.
KiboData positions as: lightweight script, sessionStorage session id, webhook revenue in the same view, not a CDP.
Questions to ask before buying a heavier tool
- Will this require consent banner changes?
- Does it set third-party cookies?
- Where does EU customer browsing data live?
- Can we export/delete on request?
- What decision this week uses a metric only this tool provides?
If the answer is “nice Sankey diagram for investors,” you might be shopping theater.
Scenario: Product Hunt launch
You will see a session spike. Some buyers bookmark and return later, new session, maybe direct. Cookieless analytics understates “Product Hunt caused this revenue” for delayed conversions; it correctly screams “something happened Wednesday.”
Supplement with:
utm_source=producthunton every PH link.- Pinned range around launch day.
- Survey on thank-you page optional.
That is enough for indie scale.
Scenario: Podcast host reads your URL
Many listeners type domain directly, direct traffic rises without UTMs. You cannot attribute per listener. You can note timing if episodes ship on a schedule and direct sessions bump, weak evidence, honest label.
Scenario: Agency promises “ROAS”
ROAS needs ad spend + attributed revenue under ad network rules. Your cookieless site analytics will not compute ROAS for Meta campaigns without Meta’s pixel and their numbers. Internal RPV by UTM for paid social links you tagged is the proportionate indie version.
Closing the loop with revenue truth
Every limitation above hurts less when money is webhook-grounded. A session you undercounted still produces a checkout_completed event if the sale happened. Joining may be fuzzy; revenue existence is not.
Optimize for revenue per session trends by channel you control, not for recovering Meta’s graph.
Read next
- Main guide: analytics without a cookie banner for EU SaaS
- Mechanics: sessionStorage visitor counting tradeoffs
- France context: France indie SaaS practical analytics notes
Cookieless analytics is a scope decision: measure your house honestly, refuse cross-site identity theater, and spend the saved complexity on product and distribution you can attribute well enough to ship the next experiment.