Start free trial Log in

UTM tracking without cookies: how campaign attribution still works

See your data

A common worry when teams drop Google Analytics 4 for a cookieless tool is: "Will we lose campaign tracking?" Mostly, no. UTM parameters are part of the URL, not a cookie. When someone clicks https://example.com/pricing?utm_source=newsletter&utm_medium=email&utm_campaign=oct-launch, the campaign label arrives with the page load itself. Any analytics script that reads the landing URL can record it, with no cookie and no stored identifier.

What changes is attribution across visits. GA4 uses a long-lived cookie to remember that the person who signs up on Thursday clicked your newsletter on Monday. A cookieless tool, by design, does not. This guide covers what still works, what doesn't, and how to set up UTMs so the part you keep is clean.

Build and check your links with the free UTM builder & checker. It runs in your browser with no login.

  1. You add utm_ parameters to a link in an email, ad, social post or partner page.
  2. A visitor clicks. The browser loads your landing page with the full query string.
  3. The analytics script sends the page URL (and the referrer) to its collector.
  4. The collector parses utm_source, utm_medium, utm_campaign and friends out of that URL and stores them on the pageview.

Nothing in that path needs to read or write a cookie. In SiteLine, the tracker sends the URL, path, hostname, referrer and any UTMs present on the URL. It does not set or read an analytics cookie, and the request goes out with credentials omitted. Reports break traffic down by utm_source, utm_medium and utm_campaign, with pageviews and visitors for each value. Pipeline detail: cookieless tracking explained and SiteLine privacy docs.

Google documents the _ga cookie as "used to distinguish users", with a 2-year default expiry (Google Analytics cookie usage). That persistent ID is what lets GA4:

Campaign values themselves still come from the URL. Google's own help page describes them as parameters sent to Analytics when a user clicks a link, and shows them as session source, medium and campaign in the Traffic acquisition report (URL builders help). The cookie is the memory, not the source.

There's also a catch on the GA4 side. If the cookie or the whole tag only loads after consent, visitors who decline or ignore the banner never send their UTMs at all. You lose the campaign and the visit. Size that gap with the cookie banner traffic loss calculator and the cookie banner guide.

GA4 vs cookieless: campaign tracking side by side

Question GA4 (cookies, consent-gated in many regions) Cookieless (e.g. SiteLine)
Records UTMs on the landing hit? Yes, if the tag runs Yes
Needs consent before recording? Often, in the EU/UK, for the cookie Not for this tracking model alone (other pixels are separate)
Visitors who decline the banner Not measured Measured
Same person across days Yes, via _ga cookie No. SiteLine's visitor hash resets every UTC day
Credits a later conversion to an earlier click Yes, within GA4's attribution settings No cross-day stitching
Ad click IDs (gclid etc.) Read by Google's tags Only what the tool parses. Add manual UTMs if you need source/medium
Data-driven / multi-touch models Available Not applicable

The honest summary: cookieless analytics gives you complete, visit-level campaign counts (how many visitors and pageviews each campaign brought). GA4 gives you partial, user-level journeys, made patchier by consent decline and blockers. Pick the trade-off you can defend. Background: cookieless analytics vs GA4 and unique visitors without cookies.

If you need "which campaign produced this signup", record it where the conversion happens rather than in a tracking cookie:

Storing UTMs in localStorage or a first-party cookie of your own to "remember" them is a storage decision with its own consent questions in some jurisdictions. That's not legal advice: check your rules before you rebuild the cookie you just removed.

Naming conventions that keep reports clean

Google's help page notes that UTM values are case-sensitive: utm_source=google and utm_source=Google are different values. Google recommends always setting source, medium and campaign. Every analytics tool fragments on inconsistent strings, cookieless or not.

Parameter Use for Good Avoid
utm_source Who sent the visit newsletter, linkedin, partner-acme LinkedIn one week, linkedin.com the next
utm_medium Channel type email, cpc, social, referral A new medium per campaign
utm_campaign The named push oct-launch, q4-webinar Spaces, dates in three formats
utm_content Creative or link variant hero-cta, footer-link Leaving A/B variants unlabelled
utm_term Paid keyword gsc archive Using it for non-paid noise

Rules that save the most cleanup:

  1. Lowercase, hyphens, no spaces. Decide once and write it down.
  2. Fixed vocabularies for source and medium. Save them as presets in the UTM builder so freelancers and ESP templates reuse them.
  3. Never tag internal links. A UTM on your own nav or banner relabels a visit that already had a real source.
  4. No personal data in UTMs. No emails, names or user IDs. URLs end up in logs, referrers and analytics.
  5. Check the final URL after wrappers. ESP click-tracking, link shorteners and redirects can drop the query string. Paste the live link into the checker and click it in a private window.

Things that break UTMs (in any tool)

Organic search doesn't use UTMs

Google organic clicks arrive without UTMs. In analytics they show up by referrer, and the query detail lives in Google Search Console, which never reads your tags. To see campaigns and organic search side by side, put cookieless analytics next to a Search Console archive: combine GSC with cookieless analytics. Numbers won't match exactly, and the why analytics numbers don't match guide explains why.

Track campaigns in SiteLine

SiteLine records UTMs on every pageview without an analytics cookie. It reports by source, medium and campaign, and stores your Search Console history beside it, with read-only MCP if you want an agent to answer "which campaign drove last week's traffic?". Start the 7-day trial with no card, or see pricing from $4.99/month. Comparing options first? GA4 alternatives and consent-free analytics.

FAQ

Do UTM parameters need cookies to work?

No. UTMs are query parameters on the landing URL. A cookieless tracker reads them from the page URL when the visit happens. Cookies only matter if you want to remember the campaign across later visits.

Will cookieless analytics show which campaign led to a signup?

It shows how many visitors each campaign brought, but it won't stitch a signup days later back to an earlier campaign click. Capture UTMs into hidden form fields so your CRM stores the campaign with the signup.

UTM values in a URL are not a cookie. A cookieless tracker that reads them sets nothing on the device. Other tags on the page (ads pixels, chat widgets) have their own rules. This is not legal advice.

Why do my UTM campaigns show as several rows?

Inconsistent spelling or casing. Email, email and e-mail are three different values. Standardise with presets in the UTM builder.

Should I add UTMs to Google Ads if auto-tagging is on?

If your analytics tool doesn't read Google's click ID, yes. Manual UTMs give a cookieless tool the source, medium and campaign it can parse.