
Tax and accounting
54% better lead quality after using LeadJourney for marketing
Karsten Guhr
Managing Director
Read the storyFirst-party tracking
Your own server sets a first-party identifier on a subdomain you own, so the journey holds all the way to the lead.
Rated by teams that stopped depending on the cookie
First-party tracking at
Same site, same month, five ways to lose a cookie
The pixel's 268 all sit in the first row. Every row below it needed a cookie that was not there.
The definition
In short
First-party tracking records visits and conversions without third-party cookies. A pseudonymous identifier is set by your own domain and server, joined to a person only when they fill in a form or call, and hashed before anything reaches an ad platform. It is consent-aware, not consent-free: what you may collect stays the same, how reliably you collect it changes.
The identifier comes from your own domain, such as track.yourdomain.com, not from a tracking domain the browser and the blocklists treat as a third party. That is what first-party means here.
The event is recorded on your server and the identifier lives there, so a seven-day cookie cap or a cleared browser does not reset it. How it is captured and forwarded is server-side tracking.
Before consent the event carries no personal data. After it, the full record. First-party tracking that ignores the banner is not first-party tracking, it is a workaround with a new name.
The visits stay pseudonymous until the visitor identifies themselves. At that moment the sessions are stitched to the lead, and what goes to the ad platforms goes hashed.
Why the cookie stopped working
A conversion pixel remembers a visitor with a third-party cookie, and every major browser now limits or blocks that cookie. The pixel does not report what it forgot.
The pixel is not failing at random. It is failing exactly where the browsers and the regulators told it to. Tracking that depends on a cookie inherits every one of those limits.
Watch it
What is left of your conversion data once consent, iOS and the ad blockers are done with it, and how the gap gets closed.
Case studies
One measured result per customer, with the person, the role and the company behind it.

Tax and accounting
54% better lead quality after using LeadJourney for marketing
Karsten Guhr
Managing Director
Read the story
SEO agency
95% clarity about marketing KPIs and a foundation to scale
Nikita Yatsun
Managing Director
Read the story
Klickkraft GmbH
Business coaching
€10-20k in monthly Meta spend, tied to qualified leads and revenue per ad
Florian Buck
Managing Director
Read the story
LinkedIn growth agency
2x customer retention, once every LinkedIn touchpoint was tracked to revenue
Marc Richard
CEO
Read the story
![]()
Digital publishing
Which article produced the lead and the revenue, across AI and organic search
Andreas Malkow
CEO & Head of PR
Read the story
SEO and GEO agency
Proven ROI on every retainer, from organic and AI search leads through to revenue
Philipp Nessmann
Managing Director
Read the storyGetreach
Backlinks marketplace (SaaS)
Every source, every CRM
The channels a first-party click can come from, and the CRMs the identity is read back from once the person is known.
Spend, campaign structure and click IDs come in. Closed deals go back out as offline conversions.
The traffic your analytics still files under direct. No setup, the tracking script separates it.
Lead stage and deal value flow in. Every campaign sees the revenue it actually produced.
What first-party tracking does
Tracking runs on track.yourdomain.com, a domain you own. To Safari, Firefox and the blocklists it is your site talking to itself, so nothing in the setup is a third-party cookie or a third-party request.
The visitor is recognised by a pseudonymous first-party identifier the server issues and keeps, together with the click ID from the first visit, so the seven-day cap and a cleared browser do not reset the journey.
The consent state travels with every event. Before consent, the event is recorded without personal data; after it, the full record. A declined banner stays declined, and the conversion is still counted.
The visits stay anonymous until the person fills in a form, books or calls. At that moment the touchpoints, across sessions and devices, are stitched to the lead. See cross-device journeys.
Email, phone and the click ID go to Meta, Google, LinkedIn and Microsoft hashed, with an event ID for deduplication, so match quality rises without a personal field ever leaving in the clear.
Data is processed and stored in Frankfurt, encrypted at rest, an Art. 28 data processing agreement is signed and the sub-processor list is public, so the vendor review has a named control for every row.
What first-party tracking does not do
Removing the third-party cookie removes a dependency, not an obligation. Consent still governs personal data, and a tool that quietly rebuilds the cookie with a fingerprint has only moved the problem to legal. LeadJourney reads the consent state and records the conversion either way, without the person.
Inside the layer
Three sessions, two devices, and nothing stored in the browser between them.
One journey
Open the lead and read the path no cookie could have held: the Meta click on an iPhone, the return after the seven-day cap, the form at a desk, the deal in the CRM.
The declined row is still a conversion. It just is not a person.
Consent in the log
The log shows what was recorded for each visitor and under which consent: the full event where the banner was accepted, an anonymous one where it was declined. See GDPR compliant tracking.
Meta scores the event on what arrives. Every field here arrived hashed, and only because the visitor accepted.
What leaves your domain
Open a consented event and see what reached the platform: the email and phone hashed on your server, the click ID, the IP and user agent, and the shared event ID. No raw personal field on the list.
Live in 21 minutes
No fingerprinting library, no container to host, no engineering ticket.
Point track.yourdomain.com at LeadJourney and paste one script into your site header. From the first visit the identifier is first-party and set on the server, and no third-party cookie is written.
The consent state comes from the banner you already run. Connect Meta, Google, LinkedIn and Microsoft Ads by OAuth for the conversion APIs, and your CRM for the outcomes: native for HubSpot, Pipedrive, Close and Attio, a webhook for Salesforce and the rest.
Decide what each event becomes: the consented lead to Meta with hashed fields, the declined one as an anonymous count, the closed deal back to Google with its value. The pixel can stay and is deduplicated from the first hour.
How it compares
| What you need | LeadJourney | ||
|---|---|---|---|
| Works without third-party cookies | No: Built on them | Partly: First-party cookie, consent-gated | Yes: First-party identifier on the server |
| Survives Safari's seven-day cap | No: Cookie gone on day 8 | No: Script-set _ga cookie, same cap | Yes: Identifier kept on the server |
| Loads with an ad blocker on | No: Script on every blocklist | No: gtag.js is blocked too | Yes: First-party request to your subdomain |
| What a declined banner leaves you | No: Nothing | Partly: Cookieless pings and modelled numbers | Yes: An anonymous conversion, no personal data |
| Knows the person once they identify | Partly: Advanced matching a developer wires | Partly: A user ID you implement | Yes: Stitched on the form or the call, hashed |
| Hosting, DPA and sub-processors | No: Meta's infrastructure, Meta's terms | Partly: Google's infrastructure, Google's terms | Yes: Frankfurt, Art. 28 DPA, public list |
What changes
A lead that returns on day nine, on another device, is still the same person with the same first click, so the campaign that started it keeps its credit.
Hosting, cookies, DPA, sub-processors, DPO: the questions legal asks first each name a control. Regulated teams such as financial and legal advisors run on it.
Nothing personal is recorded before consent and nothing raw leaves, so the tracking setup stops being the thing compliance worries about.
Hashed email, phone and click ID on consented events give Meta and Google more to match on than a cookie ever carried.
The phone that saw the ad and the laptop that converted are one record once the person identifies, in the report and in the CRM.
The log that proves what was recorded and under which consent is the log marketing reads every day. No second tool, no second story.
Original reviews
4.9 out of 5 across 11 public reviews. Quoted as they were left, shortened only by dropping whole sentences.
“Before LeadJourney, we had no reliable tracking concept for our five-figure ad spend. We were manually building spreadsheet and CRM reports, inaccurate and time-consuming. Within two days, everything was set up. For the first time, I know exactly what I pay per lead and which campaigns actually bring in the best-qualified prospects.”
Florian BuckCEO, Klickkraft GmbH“With LeadJourney we are able to track all our leads and connect them with sales and attribution data to make better decisions. In the first month of using it we scaled from 0 to 100k revenue from paid ads only.”
“LeadJourney finally fixed my Marketing Analytics. It goes way beyond basic Ad Tracking Software. The Customer Journey Report saves hours of digging, and capturing everything from Offline Conversions to AI Search Tracking makes it the Best B2B Attribution Platform available.”
“Connected LeadJourney for 2 clients, setup took literally 20 minutes each. The data became more accurate, the reports actually make sense. Now clients look at the dashboard and the 'why don't the numbers match?' questions are gone.”
Alexander SamarPerformance Marketing Agency“With LeadJourney, we have finally found a tool that provides us with the data we need to scale our performance marketing campaigns. The most important KPI is no longer lead price but cost per qualified lead.”
Steffen SiesingCEO, Bilanzmanufaktur GmbH“The ability to track both online and offline conversions in one unified dashboard has given us insights we never had before. Our ROI has improved dramatically since we started integrating LeadJourney with our CRM. We're finally able to see the full customer journey, and it's been a game changer for our strategy.”
Andre WitzelFounder, Trading.de“The ability to seamlessly integrate data from multiple channels and see real-time insights has significantly improved our campaign results. We now focus on metrics that truly matter, like ROI and qualified leads.”
Nikita YatsunCEO, RLV Media GmbHRead the reviews where they were left
Common questions
What marketers and their privacy teams want to know before they take the third-party cookie out of the setup.
Server-side tracking is about where the event is recorded: on a server, on your own domain, instead of in the browser. First-party tracking is about how the visitor is identified while that happens: with an identifier set by your own domain and server instead of a third-party cookie. LeadJourney is both, which is why the two pages exist. The server-side page covers the capture and the forwarding; this one covers the identity.
No. Consent law covers personal data and anything stored on or read from the visitor's device, not the word cookie. What changes is how much still works when the banner is declined: LeadJourney records the conversion without the person, and records the person only after consent. The GDPR page lists the controls and the sub-processors.
With a pseudonymous first-party identifier set by your own subdomain and kept on the server rather than in a third-party cookie, together with the click ID recorded on the first visit. Until the visitor fills in a form, books or calls, that identifier is not a person. Once they do, the sessions are stitched to the lead.
Safari caps script-set cookies at seven days, so a pixel meets a returning lead as a stranger. LeadJourney's identifier and the click ID are on the server, so day nine is the same journey. A device switch is stitched the moment the person identifies, because the phone's sessions and the laptop's form both belong to the lead they became.
First-party is a design choice, not a certificate. Compliance comes from what is recorded and where: no personal data before consent, hashed fields to the platforms, processing and storage in Frankfurt, an Art. 28 DPA, a public sub-processor list and an appointed Data Protection Officer. The guide to GDPR compliant conversion tracking goes through the setup end to end.
Meta through the Conversions API, Google Ads through Enhanced Conversions and offline conversion import, LinkedIn through its Conversions API and Microsoft Ads through offline conversions. Every event carries an event ID, so a conversion your pixel also saw is counted once, and you can keep the pixel running as long as you like.
Yes. LeadJourney reads the consent state from the banner you already run and records accordingly: an anonymous event before consent, the full event after it. You do not replace the banner and you do not configure a second one, and the consent state is written onto every event in the log.
About 21 minutes: point a subdomain, add one script, connect the ad accounts and the CRM by OAuth, choose the event mapping. There is no fingerprinting library to add, no container to host and no engineering ticket. Onboarding is guided, on a call, if you want it.
See it on your own consent rates
Book a demo and we look at your own traffic: what the pixel sees per browser and consent state, and what a first-party layer would record.
Safari is where the seven-day cap bites. Brave is where the script never loads. Neither touched the server.