8 ms·
Show HN: Cookieless Conversion Attribution with Pathview
Morning HN.
I worked on a cloud CMS and then pivoted an analytics feature to a standalone SaaS. Pathview focuses on the conversion path rather than general analytics. I want to help users optimize conversions.
It doesn’t use cookies, contains 160-characters of JavaScript, and leverages HTTP Messaging for a modern take on an old-school analytics approach.
I’m close to launching a public beta test and could use a sanity check. Any advice, feedback, or questions for this first-time developer?
-sb
- mtmail 4y agoThe Javascript inserts an image 'https://pathview-analytics.com/response.gif?url='+e(d.location.href)+'&ref='+e(d.referrer) https://pathview-analytics.com/response.gif?url='+e(d.locati...; I'd add a timestamp to the URL to avoid browser caching. And use a separate domain or subdomain because with any success adblockers will add the URL to their block lists an that could block the whole domain. Some ad trackers use CNAME DNS entries, e.g. mytracker.mydomain.com points to tracker.pathview-analytics.com but adblockers also do the DNS resolution now, an arms race. (https://www.theregister.com/2021/02/24/dns_cname_tracking/ https://www.theregister.com/2021/02/24/dns_cname_tracking/)
- shanebellone 4y agoThe timestamp is an awesome idea. Thank you! Why would an adblocker target an analytics app? Misidentification?
- tuvan 4y agoAdblockers usually have privacy filters as well. Thats why some analytics apps recommend proxying over website servers instead of directly sending requests to analytics apps endpoints from the client.
- shanebellone 4y agoThank you for the clarification. That gives me something to think about.
- korlja 4y agoAnalytics is generally (in detail this might or might not apply for this project) seen as an invasion of privacy, wasting bandwidth, increasing load time and lowering performance. There is a population of users who would gladly accept advertisements without analytics, because they see the invasion into their privacy as the predominant evil. This is why most adblockers nowadays either block analytics by default, or at least provide a configuration to also block analytics.
- shanebellone 4y agoI agree with your statement. I did originally build this for myself, with privacy in mind. I don't like being tracked either. Pathview doesn't rely on personal data but the general perception remains true. Any thoughts on navigating through that stigma? It's worth mentioning that the first hit generally loads in ~200ms and subsequent hits in ~120ms. The difference between first and subsequent is SSL. Speed and footprint represent two of my main design considerations.
- korlja 4y agoI guess the stigma is too established to get rid of. Maybe you can sway some users by transparency, i.e. a very thorough but user-friendly explanation about what your software is doing and how it cannot possibly be used to invade their privacy. But unfortunately, as far as my opinion goes, any kind of analytics and tracking just results in an instant "yuck" reaction, like a spider landing on my lap. I don't bother with analyzing it, I'll just try to get rid of it as quickly as possible. The notion of privacy-friendly analytics has also been thoroughly burned by sleazy marketing departments outright lying. Or technical solutions that claimed to be privacy-friendly, but actually didn't really because of technical reasons. Or technical solutions being so complicated and obscure that it might as well be a privacy-protecting voodoo ritual for all a user knows.
- shanebellone 4y agoThis is tough. I dislike tracking but approve of analytics. Without data, websites cannot improve. Without improvements we'd only have Craigslists. In your opinion, is there a way to balance the need for feedback with respect for the user? What might that solution look like? Do you have any absolute demands?
- mtmail 4y agoSome users want to block only ads (visible content), some block everything including analytics, support widgets, mouse-over widgets, social media links, "back to top" links on pages. Some lists even block everything by file name, e.g. /tracker.php regardless of domain.
- shanebellone 4y agoThat's wild. I like the luxuries. Thanks for the perspective.
- Semaphor 4y agoJust to add, some of us even block all third-party domains by default. I had to specifically allow "pathview-analytics.com" to see what your script does ;)
- shanebellone 4y agoDo you have a reason that extends beyond preference? Is the result worth the price?
- Semaphor 4y agoThe vast majority of sites work with some defaults (mainly CDNs), and it stops almost all 3rd party tracking. The minor inconvenience of sometimes having to whitelist some stuff is acceptable to me.
- michaelt 4y agoIt tends to be good for security. For example, it blocks a great many XSS attacks, as if every website had a strict content-security-policy header. Or if some joker on a website adds <img src="http://192.168.0.1/reboot-router.php http://192.168.0.1/reboot-router.php"> or suchlike you're protected. Websites that want to host sketchy untrusted content use iframes to external domains, so the sketchy content can't grab the user's cookies. If the website didn't trust the third party, why should you? It can also block a variety of "features" that are actually annoyances - like third-party live chat popups, third-party cookie consent nag screens etc. In terms of the price, how troublesome it is will depend on your web browsing needs. If you're a professional buyer visiting dozens of different companies' websites every day, you might find it inconvenient. But if most of your time is divided between your 10 favourite websites? Once you've got the whitelist right you'll barely notice it.
- freemint 4y agoWhat would i need to add to the my websites privacy policy? What would i need to do to be GDPR and CCPA compliant? Those questions go completely unanswered and should be part of https://pathview.io/get-started https://pathview.io/get-started . If those questions are not unanswered or addressed, the service is a liability. Answering those questions also gives a lot of transperancy to your customer what you are and are not doing. There should be an automatism and promise to inform people that an update to the privacy policy is required.
- shanebellone 4y agoYou don't need a cookie banner or special privacy policy. It doesn't track personal data. You're absolutely right though, the website should mention those things. I'm hesitant to make claims about GDPR and CCPA. Those claims come with questions about the underlying mechanism which is only covered by a provisional patent. I really need a lawyer to move forward on those fronts. Pathview is about two months old, and the website is less than a week. Clarifications will be required, and decisions will be made. Thank you for the extra motivation.
- littlestymaar 4y agoIf you're tracking users, no matter if it's done via cookies or something else, then if falls under GDPR and you at least have something to do about it. GDPR's definition of personal data is much broader than one may expect, you should definitely ask a lawyer on this subject to be sure you're compliant.
- shanebellone 4y agoOnly if you use personal data as defined by GDPR which includes the transmission, processing, and storing of IP addresses or their hashed equivalents. A salted hash cannot be attributed to an individual user. The EU position regards the IPV6 range as sufficiently small to attribute a hash back to an IP with enough motivation and resources. Pathview strictly uses the salted hash to count unique visits. It's as minimally invasive as possible.
- rgavuliak 4y agoWhat does this have to do with attribution? Attribution is generally concerned with attributing revenue to marketing channels.
- shanebellone 4y agoI'm attributing individual conversions to conversion paths (starting with the referer). This is not a multi-channel solution. Pathview will help users optimize their websites to improve conversion rates. Does that clarify?
- njitram 4y agoWas confused about this as well; attribution is a term used by marketer for attributing revenue to channel and campaigns (cost), so you might want to make it clear that this is really about single website attribution. Is it single session attribution or can you measure if a user enter the website and convert a few days later?
- shanebellone 4y agoPoint noted. I'll be careful with my language. Thanks for reiterating. This system is focused on the source of the hit and the page views that led to the conversion. It could be used to measure organic search ROI for individual content pages. You could justify content spend based on performance data and plan future content based on past returns. I find this use case particularly interesting. It is capable of multi-session attribution. From a product perspective, the tradeoff is timeframe for efficiency. The longer the historical perspective, the more costly feature becomes. This represents a current personal debate about tradeoffs.
- njitram 4y agoYou will probably quickly run into asks from customers about 'attribution modelling' concepts and multi touch attribution, you now probably created first touch attribution?
- t0mas88 4y agoI think you should add a bit more information on how you calculate the metrics without using cookies. For example how do you count unique visitors if you don't track any user information and don't set any cookies?
- shanebellone 4y agoI'm using a salted hash to calculate unique visitors. The cleartext IP is never captured or stored and is only available because it's required to return a response. What is the right amount of information to share? Most users won't care but others will. I want to simplify rather than complicate. Finding balance is difficult.
- closewith 4y ago> I'm using a salted hash to calculate unique visitors. Where do you store the salted hash?
- shanebellone 4y agoThe salted hash is stored in a database.
- closewith 4y agoWhere is it stored on the client? Or is it a salted hash of the IP address used to connect? If so, the recent precedent from CNIL wouldn't consider that exempt from GDPR cookie banner unless obscured via a first-party proxy.
- shanebellone 4y agoIt's the salted hash of the IP used to connect. I did build my approach around the Internet's backbone to future proof. Banning my approach would fundamentally break the Internet. I've made a note and will read into the precedent. Thank you for the research topic.
- TekMol 4y agoWhat is the motivation to do the tracking without cookies?
- shanebellone 4y agoI hate cookie banners.
- madeofpalk 4y agofwiw 'cookie banners' aren't about the technology cookies, but rather about gaining consent for tracking and storing data on users. Even if you do this without cookies, if you still track users (like for attribution) for non-essential purposes, then you could still need consent from a "cookie banner". a hash of an ip address could still be 'personal data' under the eyes of gdpr.
- shanebellone 4y agoI appreciate and understand that. I responded with this point to another comment. GDPR does aggressively define what can and cannot be done. As far as I know, I'm adhering to their definitions and guidelines. I will consult with a lawyer to confirm before I make claims about GDPR or other laws. My goal is to make the best product possible given the constraints set. I believe there is middle ground between user privacy and analytics.
- korlja 4y ago> a hash of an ip address could still be 'personal data' under the eyes of gdpr. We did something similar for a project, which got approved by the relevant data protection officer: hash(IP + daily secret) as an identifier in the logs. This will be used to count unique visitors, the wraparound at 24:00:00 didn't matter to us. The daily secret is just a random number that our one (small setup) application server generates each day. It is never written out to disk or database, so an appserver restart also recreates that secret, it is strictly kept in RAM. That way, we could argue that, barring extreme measures like attaching a debugger to get the secret, we technically prevented deanonymisation. But that was just a small-scale project, has never been tested in court and the usual YMMV, IANAL, ... Edit: I think some webservers can be configured to do something similar