A common worry when teams drop Google Analytics 4 for a cookieless tool is: "Will we lose campaign tracking?" Mostly, no. UTM parameters are part of the URL, not a cookie. When someone clicks https://example.com/pricing?utm_source=newsletter&utm_medium=email&utm_campaign=oct-launch, the campaign label arrives with the page load itself. Any analytics script that reads the landing URL can record it, with no cookie and no stored identifier.
What changes is attribution across visits. GA4 uses a long-lived cookie to remember that the person who signs up on Thursday clicked your newsletter on Monday. A cookieless tool, by design, does not. This guide covers what still works, what doesn't, and how to set up UTMs so the part you keep is clean.
Build and check your links with the free UTM builder & checker. It runs in your browser with no login.
How UTM capture works (no cookie involved)
- You add
utm_parameters to a link in an email, ad, social post or partner page. - A visitor clicks. The browser loads your landing page with the full query string.
- The analytics script sends the page URL (and the referrer) to its collector.
- The collector parses
utm_source,utm_medium,utm_campaignand friends out of that URL and stores them on the pageview.
Nothing in that path needs to read or write a cookie. In SiteLine, the tracker sends the URL, path, hostname, referrer and any UTMs present on the URL. It does not set or read an analytics cookie, and the request goes out with credentials omitted. Reports break traffic down by utm_source, utm_medium and utm_campaign, with pageviews and visitors for each value. Pipeline detail: cookieless tracking explained and SiteLine privacy docs.
What GA4's cookie adds
Google documents the _ga cookie as "used to distinguish users", with a 2-year default expiry (Google Analytics cookie usage). That persistent ID is what lets GA4:
- attribute a conversion to a campaign the same browser clicked days or weeks earlier,
- report first-user source and medium separately from the current session's source,
- count returning users across a 30-day range.
Campaign values themselves still come from the URL. Google's own help page describes them as parameters sent to Analytics when a user clicks a link, and shows them as session source, medium and campaign in the Traffic acquisition report (URL builders help). The cookie is the memory, not the source.
There's also a catch on the GA4 side. If the cookie or the whole tag only loads after consent, visitors who decline or ignore the banner never send their UTMs at all. You lose the campaign and the visit. Size that gap with the cookie banner traffic loss calculator and the cookie banner guide.
GA4 vs cookieless: campaign tracking side by side
| Question | GA4 (cookies, consent-gated in many regions) | Cookieless (e.g. SiteLine) |
|---|---|---|
| Records UTMs on the landing hit? | Yes, if the tag runs | Yes |
| Needs consent before recording? | Often, in the EU/UK, for the cookie | Not for this tracking model alone (other pixels are separate) |
| Visitors who decline the banner | Not measured | Measured |
| Same person across days | Yes, via _ga cookie |
No. SiteLine's visitor hash resets every UTC day |
| Credits a later conversion to an earlier click | Yes, within GA4's attribution settings | No cross-day stitching |
Ad click IDs (gclid etc.) |
Read by Google's tags | Only what the tool parses. Add manual UTMs if you need source/medium |
| Data-driven / multi-touch models | Available | Not applicable |
The honest summary: cookieless analytics gives you complete, visit-level campaign counts (how many visitors and pageviews each campaign brought). GA4 gives you partial, user-level journeys, made patchier by consent decline and blockers. Pick the trade-off you can defend. Background: cookieless analytics vs GA4 and unique visitors without cookies.
Getting conversion attribution back without an analytics cookie
If you need "which campaign produced this signup", record it where the conversion happens rather than in a tracking cookie:
- Hidden form fields. On the landing page, copy
utm_source,utm_mediumandutm_campaignfrom the URL into hidden fields on the signup or lead form. They land in your CRM with the record the user chose to create. - Carry parameters forward. If the CTA links from the landing page to
/register, append the same UTM values to that link so the signup page sees them too. - Short vs long funnels. Campaign visit counts tell you a lot for one-visit funnels. Long B2B cycles need the CRM method above.
Storing UTMs in localStorage or a first-party cookie of your own to "remember" them is a storage decision with its own consent questions in some jurisdictions. That's not legal advice: check your rules before you rebuild the cookie you just removed.
Naming conventions that keep reports clean
Google's help page notes that UTM values are case-sensitive: utm_source=google and utm_source=Google are different values. Google recommends always setting source, medium and campaign. Every analytics tool fragments on inconsistent strings, cookieless or not.
| Parameter | Use for | Good | Avoid |
|---|---|---|---|
utm_source |
Who sent the visit | newsletter, linkedin, partner-acme |
LinkedIn one week, linkedin.com the next |
utm_medium |
Channel type | email, cpc, social, referral |
A new medium per campaign |
utm_campaign |
The named push | oct-launch, q4-webinar |
Spaces, dates in three formats |
utm_content |
Creative or link variant | hero-cta, footer-link |
Leaving A/B variants unlabelled |
utm_term |
Paid keyword | gsc archive |
Using it for non-paid noise |
Rules that save the most cleanup:
- Lowercase, hyphens, no spaces. Decide once and write it down.
- Fixed vocabularies for source and medium. Save them as presets in the UTM builder so freelancers and ESP templates reuse them.
- Never tag internal links. A UTM on your own nav or banner relabels a visit that already had a real source.
- No personal data in UTMs. No emails, names or user IDs. URLs end up in logs, referrers and analytics.
- Check the final URL after wrappers. ESP click-tracking, link shorteners and redirects can drop the query string. Paste the live link into the checker and click it in a private window.
Things that break UTMs (in any tool)
- Redirects that drop the query string, such as
http→httpsor trailing-slash rules on some servers and CDNs. Test the exact link you publish. - UTMs after a
#fragment. Fragments are not sent to the server, and many trackers read only the query string. Put?utm_…before any#. - Ad blockers blocking the analytics script entirely. That's a delivery problem, not a cookie one. A first-party proxy helps.
- In-app browsers and apps that strip parameters. Rare, but worth a test on your main social channel.
Organic search doesn't use UTMs
Google organic clicks arrive without UTMs. In analytics they show up by referrer, and the query detail lives in Google Search Console, which never reads your tags. To see campaigns and organic search side by side, put cookieless analytics next to a Search Console archive: combine GSC with cookieless analytics. Numbers won't match exactly, and the why analytics numbers don't match guide explains why.
Track campaigns in SiteLine
SiteLine records UTMs on every pageview without an analytics cookie. It reports by source, medium and campaign, and stores your Search Console history beside it, with read-only MCP if you want an agent to answer "which campaign drove last week's traffic?". Start the 7-day trial with no card, or see pricing from $4.99/month. Comparing options first? GA4 alternatives and consent-free analytics.
FAQ
Do UTM parameters need cookies to work?
No. UTMs are query parameters on the landing URL. A cookieless tracker reads them from the page URL when the visit happens. Cookies only matter if you want to remember the campaign across later visits.
Will cookieless analytics show which campaign led to a signup?
It shows how many visitors each campaign brought, but it won't stitch a signup days later back to an earlier campaign click. Capture UTMs into hidden form fields so your CRM stores the campaign with the signup.
Do I need a cookie banner for UTM tracking?
UTM values in a URL are not a cookie. A cookieless tracker that reads them sets nothing on the device. Other tags on the page (ads pixels, chat widgets) have their own rules. This is not legal advice.
Why do my UTM campaigns show as several rows?
Inconsistent spelling or casing. Email, email and e-mail are three different values. Standardise with presets in the UTM builder.
Should I add UTMs to Google Ads if auto-tagging is on?
If your analytics tool doesn't read Google's click ID, yes. Manual UTMs give a cookieless tool the source, medium and campaign it can parse.