When a website operator installs Attruly, the following is recorded about each visit. The operator chooses what else to send through custom events and traits.
Data recorded by the Attruly tracking snippet| Data | Purpose |
|---|
| A randomly generated visitor id | To recognise a returning browser. Stored first-party. Not derived from any device characteristic and not usable across sites |
| Page URL, path and title | To report which pages are visited and which page a visit started on |
| Referrer | To identify where the visit came from |
| UTM parameters and ad click ids | To attribute the visit to a campaign |
| User agent, parsed to device, OS and browser | To report the device mix and to identify automated traffic |
| IP address | Used to resolve an approximate country and to apply the operator’s exclusion list. Not stored against the visit |
| Timestamps | To order the touch path and bucket reports by day |
| Custom events and traits | Whatever the operator chooses to send. Entirely under their control |
What is never recorded: no cross-site tracking, no device fingerprinting, no advertising identifiers, no third-party cookies, and no data sharing between the projects of different customers. A visitor id from one Attruly customer's site is meaningless on another's.