Cookies, tracking and fingerprinting
What cookies are, the kinds that matter for consent, and the other ways websites track visitors.
Consent laws are written about tracking, and cookies are the most common way to track. This page is the background for the rest of the documentation: what a cookie is, which kinds need consent, and what else counts as tracking.
What cookies are
A cookie is a small text file that a website or app places on a visitor's device. The browser sends it back with each later request to the same site, which is what lets a website recognise a returning visitor, keep them signed in, remember a setting, or build a record of their behaviour. Cookies are used for analytics, personalisation and tracking, and for things the website cannot work without.
Types of cookies
Cookies are usually sorted by what they do:
- Essential cookies are needed for a website or app to function: keeping a session, a shopping basket or a sign-in.
- Preference cookies remember a choice the visitor made, such as a language.
- Analytics cookies collect data on how visitors use a website or app.
- Marketing cookies track visitor behaviour across websites and apps for targeted advertising.
They are also sorted by who sets them. A first-party cookie belongs to the website the visitor is on; CookieHub's own consent cookie is one. A third-party cookie is set by another domain, through content embedded in the page such as an advertising tag or a video player, and is the usual means of following a visitor from site to site.
Only the essential ones can be set without consent. CookieHub groups cookies into five cookie categories that follow this division, and visitors consent per category.
Online tracking
Tracking is collecting data on a visitor's behaviour online, usually to target advertising. Cookies are one way; others are pixels (tiny images or scripts that report a page view or an event to a third party) and browser storage such as localStorage and sessionStorage, which can hold identifiers like a cookie does. CookieHub's scanner can include storage entries in its scan so they appear in the declaration; see Crawler Settings.
Fingerprinting identifies a visitor without storing anything on their device, from the combination of details the browser reveals: its version, fonts, screen size, time zone and more. Because nothing is stored, a consent dialog cannot block it by withholding a cookie; it is a matter of which scripts you allow to run. Automatic cookie blocking and Google Tag Manager triggers hold back the scripts of services until consent, whether they track with cookies or not.
Where to next
- Cookie categories: how CookieHub groups cookies for consent.
- Consent management: how consent is asked for, stored and proven.
- Automatic cookie blocking: holding scripts back until consent.