Tracking Technologies

What is Cross-Site Tracking?

Cross-site tracking is the practice of following the same user across multiple unrelated websites — using third-party cookies, pixels, fingerprinting, or shared identifiers — to build a behavioral profile for advertising and analytics.

No single website knows much about an anonymous visitor. But a tracker embedded across thousands of sites sees the same browser everywhere: the news articles read, products browsed, prices compared, videos watched. Linked by a common identifier, those observations become a longitudinal behavioral profile — the raw material of programmatic advertising, audience segments, and data-broker files.

The classic mechanism was the third-party cookie, but the technique long ago diversified: tracking pixels that report page context to a central server, browser fingerprinting that derives a stable identifier from device characteristics, link decoration that passes IDs through URLs, and identity graphs that join activity through hashed email addresses collected at login or checkout.

Privacy law treats cross-site tracking as a distinct harm. The CPRA created a named category for it — 'cross-context behavioral advertising' — and gives Californians the right to opt out of having their data 'shared' for that purpose, a right also delivered through the Global Privacy Control browser signal. EU rules require opt-in consent before the underlying trackers run. Browser vendors, meanwhile, treat it as an adversary: Safari and Firefox block third-party cookies and fight fingerprinting by design.

For businesses, the operative question is not whether you think of yourself as a tracker but whether data about your visitors flows to parties who can combine it with data from other sites. If it does, opt-out rights, consent requirements, and disclosure obligations all attach.

Why it matters for eCommerce

Every ad platform integration on your store — Meta, Google, TikTok — is a cross-site tracking relationship: you contribute your shoppers' behavior to a profile assembled across the web, and you draw on that profile for targeting. That is 'sharing' under the CPRA even when no money changes hands, which is why your site needs a functioning Do Not Sell or Share opt-out and GPC support.

Frequently asked questions

Is cross-site tracking illegal?
Not inherently, but it is heavily regulated. The EU requires prior opt-in consent for the trackers involved. California and most other US state privacy laws grant an opt-out from sharing data for cross-context behavioral advertising, and consent requirements apply to sensitive categories.
How does cross-site tracking work without third-party cookies?
Through fingerprinting, URL-based ID passing (link decoration), server-side event forwarding, and identity graphs keyed on hashed emails. The identifier changes; the profile-building — and the legal obligations — remain.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free scan

← Back to all glossary terms