Tracking modes
Each site has its own tracking mode, chosen in its Settings. An instance manages as many sites as you like, each in its own mode. The mode is never written in the tag: it comes from the server with the response to the first page view, and a change takes effect on the next page, without touching the site’s pages.
| Mode | The visitor | What is measured in addition | With regard to the CNIL |
|---|---|---|---|
| Cookieless (default) | a daily hash | — | within the exemption |
| Measurement cookie | a random identifier, in a first-party cookie | new and returning visitors, frequency, time to conversion, multi-visit attribution | within the exemption, under conditions |
| With consent | cookieless until consent, then a cookie | the same, for visitors who have consented | consent required, collected by the site’s platform |
See the CNIL (the French data protection authority) for the conditions of the exemption.
Cookieless
Section titled “Cookieless”The visitor is a daily hash:
visitor = SHA-256(daily salt ‖ site ‖ IP address ‖ user agent), truncated to 128 bits- The salt is drawn at random every day (UTC) and kept in the database, so that all API replicas compute the same hash. The next day, the worker destroys it: no one can recompute a hash any more, or link two days together.
- The site is part of the hash: the same browser on two sites has two identifiers. No tracking from one site to another.
- The IP address is used for the computation, then forgotten: it never leaves the memory of the request.
The consequence is deliberate: a unique visitor is counted per day. Returning visitors, visit frequency and attribution beyond a single day are not measured — except for signed-in visitors.
Measurement cookie
Section titled “Measurement cookie”The _eoa cookie carries a random 128-bit identifier and its creation date:
3f9c…e1a2.20261004.
- The server draws the identifier. On the first page view without a cookie,
/collectcreates one, uses it for that page view and returns it; the script sets it. No page view is counted twice. - The expiry is set at creation (13 months at most, adjustable from 1 to 13) and is never extended by a visit.
- It is a first-party cookie, set by the script on the page’s domain (
SameSite=Lax,Secureover HTTPS). It contains nothing but the identifier and its date, with no link to the IP address or to the visitor’s identity. optOut()deletes it. If the site switches back to cookieless, the next response asks the script to delete it.
Sharing the visitor across subdomains
Section titled “Sharing the visitor across subdomains”The cookie domain (optional, in Settings) sets the cookie on a parent domain,
.maison-arvor.fr: the same visitor is then recognized on maison-arvor.fr and
blog.maison-arvor.fr, if both sites share this setting. This is the only way to follow a
visitor from one site to another: there is no linking across different domains.
Safari
Section titled “Safari”Safari (ITP) caps the lifetime of cookies set by a script at 7 days. Returning visitors are therefore undercounted there beyond one week. This is a browser limitation, not a setting.
With consent
Section titled “With consent”For sites that already collect consent and want to tie measurement to it:
- as long as the consent management platform has said nothing, the script measures cookieless;
- when the visitor accepts, it calls
EodiaAnalytics.consent(true): the script switches to the measurement cookie on the next page; - if they withdraw their consent,
EodiaAnalytics.consent(false)deletes the cookie and returns to the daily hash.
// Example: hook this up to your consent management platform's event.window.addEventListener('consent-updated', (e) => { EodiaAnalytics.consent(e.detail.audienceMeasurement === true)})The call can be made before the script loads, thanks to the call queue.
Two kinds of visitor
Section titled “Two kinds of visitor”The same site can see both kinds of visitor: a visitor who refuses, a mode changed along the
way, a consent withdrawn. The visitor_kind column of the views tells them apart: daily
(daily hash), cookie (measurement cookie), none (a
server-side send without a visitor). The
new_visitor column is only meaningful for cookie.
What does not change from one mode to another
Section titled “What does not change from one mode to another”- the IP address is never recorded, and only the country is inferred from it;
optOut()and the Global Privacy Control signal count as a refusal in every mode;- the data retention period is capped at 25 months (adjustable per site);
- the data is read only by you, in your own eodia insights instance.
eodia analytics is free software by Eodia.