Sealmetrics is a consentless analytics platform built on the aggregate, cookie-free tracking mechanics described below. It records events without a persistent visitor identifier and without writing anything to the visitor's device, which is why, on our self-assessment, measurement can run without a consent banner (in Germany an open question — see Germany).
How Consentless Tracking Works
Consentless tracking measures events in aggregate instead of following people. The tracker records a small set of non-identifying fields per hit — timestamp, user agent, current URL, referral URL, browser timezone and a session identifier (see What We Track) — sends them to EU infrastructure, and never writes anything to the visitor's device. Nothing stored can identify a person or link a device across days.
The mechanics, in four steps
- Event detection. A JavaScript tracker (about 1.1 KB gzipped) fires on page load and on events you instrument. It sets no cookies and uses no localStorage or sessionStorage. It reads standard browser properties to compute the session identifier described below; that hash is never written to the device and never stored as sent.
- Transmission. The hit is sent as a lightweight beacon request. The visitor's IP appears at the network layer, as it does for any HTTP request, but is never persisted in the analytics database — it is used in memory only for anti-abuse checks and site-configured exclusions.
- Isolated processing. Each hit is processed on its own. Hits from the same person are never joined across sessions, so no journey or profile can be reconstructed.
- Aggregation. Reports are built from aggregate counts. Event-level rows are purged after 1 day, and the raw user agent string is never stored — only the browser, OS and device categories derived from it; hourly aggregates are kept 90 days; daily aggregates and conversions 24 months. Retention is fixed for every plan and enforced by database TTLs.
All customer analytics data is stored and processed in Dublin, Ireland (EU).
Two measurement modes
Isolated hits — a page view that arrives without a session identifier is counted as an independent event, with no link to any other event: pure aggregate counting.
Session-marked hits — a session identifier groups the hits of one visit (a two-hour inactivity window). The tracker computes it in the browser as a hash of standard device characteristics (a device fingerprint) combined with the publisher's account ID; it is never written to the device. On the server it is re-keyed with a daily salt that is destroyed on rotation, so the stored identifier changes every day, the raw hash is never stored, and a returning visitor cannot be recognised on another day. Because the account ID is part of the hash, the same browser produces different identifiers on different sites and no cross-site correlation is possible. This is what makes within-session metrics such as bounce rate and pages per session possible without a persistent identifier.
Why this needs no consent
Nothing is stored on the visitor's terminal equipment, and no data that identifies anyone is kept: during the day the session identifier is pseudonymised data processed under legitimate interest (GDPR Art. 6(1)(f)), and once the salt rotates it cannot be reconstructed, not even by Sealmetrics. Reports are always aggregated. The tracker does read standard browser properties to compute the session identifier, which engages the ePrivacy Directive's Article 5(3); see Analytics Cookies: Consent Exemption Requirements for how the audience-measurement exemption criteria apply. Cookie-based tools face the opposite situation, which is why they typically lose a significant share of visitor data in EU markets when visitors decline, depending on sector, brand strength and traffic mix.
Sealmetrics holds no third-party security certification, and no supervisory authority certifies analytics tools — the compliance pages are self-assessments against published criteria.
Where to read the detail
- What is Consentless Analytics? — the full concept, the GDPR and ePrivacy reasoning, the comparison with cookie-based tools, and what the model can and cannot measure
- What We Track vs What We Don't — every field recorded, with its retention
- Data Location & Retention — EU hosting, complete retention schedule, encryption
- How Attribution Works Without a User-ID — last-click attribution mechanics
- Installation — adding the script tag and instrumenting conversions
- Cookieless Tracking: Technical Deep Dive — extended analysis of the architecture