Klickbee Tracking Help

Privacy & consent

What Klickbee Tracking collects and stores, how visitors are identified without cookies, how long data is kept, and how to wait for consent.

Klickbee Tracking doesn't set any cookie on your visitors' browsers and never stores a visitor's raw IP address. This page explains exactly what is collected, what is stored, what the tracker does and doesn't do about consent, and what that means for your own site.

Your obligations stay yours

Whether you need your visitors' consent depends on your site, your country and what you configure. As the site owner, you are responsible for obtaining any consent the law requires. This page describes how the product behaves so you can make that call. It is not legal advice.

Cookies and visitor identifiers

The tracker sets no cookies. It uses the browser's own storage for three values:

WhereNameWhat it holds
Local storagekb_anon_idA random identifier for the visitor. It stays until the visitor clears their browser data, or until you call reset().
Session storagekb_session_idA random identifier for one browser tab. A new tab starts a new session.
Local storagekb_consentgranted or denied. Only used when you turn on consent mode (see below).

If storage isn't available (private browsing, blocked storage), the tracker falls back to identifiers kept in memory only, so nothing is written to the device.

Keep in mind that third-party pixels you add (Meta, Google Ads, LinkedIn or custom code) may set their own cookies. That is outside Klickbee's own tracker. See "Ad pixels and consent" below.

The dashboard itself uses cookies only for you, the signed-in user: to keep you signed in, and to remember which site you were looking at.

What is collected

For each batch of events, the tracker sends:

  • The page URL and path, the referrer and the page title.
  • The browser's user-agent, language, and screen width and height.
  • The anonymous visitor id and the session id.
  • The tracker version.
  • The visitor's first-touch acquisition data: utm_source, utm_medium, utm_campaign, utm_term, utm_content, the landing path and the referrer. Ad click ids (gclid, gbraid, wbraid, fbclid, msclkid) are used to classify the visit as paid traffic, and the Google click id (gclid, gbraid or wbraid) is also stored, to match Google Ads conversions.

Depending on what you turn on:

  • Click autocapture: for each click, the element's CSS selector, tag, visible text (up to 255 characters), aria-label, role, test id and link target, plus the click position and the page and window size.
  • Scroll depth and attention time: always collected while tracking is on. One scroll summary is sent each time a visitor leaves a page.
  • Session replay: a recording of the page as the visitor sees it. See the masking section below.
  • JavaScript errors: error messages, shortened to 255 characters.
  • Your own events and identify calls (see the sections below).

On the server, Klickbee adds the visitor's country, region, city, latitude and longitude, derived from the request's IP address and stored on the session.

IP addresses

The raw IP address is never stored. Before the location lookup, the host part of the address is zeroed (the last number of an IPv4 address; everything past the network prefix of an IPv6 address). The lookup then runs against a MaxMind database bundled with the product, and only the coarse location is kept. A consequence is that the city is approximate.

There are three ways to control what happens before a visitor agrees.

Set requireConsent: true in the npm package. Until you call grantConsent(), the tracker does nothing: no capture, no replay, no autocapture, no timers, no network request. The visitor's choice is stored in kb_consent and picked up automatically on their next page load. revokeConsent() stops tracking and replay at once and empties anything still waiting to be sent.

<TrackingProvider
  pathname={pathname}
  config={{
    projectKey: "pk_xxx",
    apiHost: "https://tracking.klickbee.com",
    requireConsent: true,
  }}
>
  {children}
</TrackingProvider>

Then, from your consent banner, using the client from useTracking():

const tracking = useTracking();

<button onClick={() => tracking.grantConsent()}>Accept</button>
<button onClick={() => tracking.revokeConsent()}>Decline</button>

The script tag cannot gate on consent

The script tag has no consent setting. window.klickbee.grantConsent() and revokeConsent() exist, but they have nothing to gate: the script starts tracking as soon as it loads. If you use the script tag and need consent, add the script to your page only after the visitor has agreed, or use the npm package with requireConsent: true.

To add the script after consent, create it from your consent banner's code:

function loadKlickbee() {
  const s = document.createElement("script");
  s.src = "https://tracking.klickbee.com/t.js";
  s.dataset.key = "pk_xxx";
  s.defer = true;
  document.head.appendChild(s);
}
// call loadKlickbee() once the visitor accepts

Do Not Track

By default the tracker respects the browser's Do Not Track signal: when it is on, the tracker does nothing at all, with the script tag and with the npm package alike. The npm package lets you override this with respectDoNotTrack: false; the script tag doesn't.

Ad pixels do not wait for consent

Meta, Google Ads, LinkedIn and custom pixels you configure on the Pixels page load as soon as the tracker starts. They are not held back by requireConsent, and they are not stopped by Do Not Track. Consent mode only gates Klickbee's own events, replay and browser-side conversion calls.

What follows from that, in practice:

  • If you don't use ad pixels, you can ignore this: the tracker alone sets no cookie.
  • If you use ad pixels and need consent for them, don't let the tracker start before consent. With the script tag, insert it after the visitor agrees (as above). With the npm package, only mount the provider after consent, or leave the pixel off in the dashboard until you're ready. You can switch a pixel on or off from the Enabled checkbox on the Pixels page without redeploying.
  • Your own consent banner remains the right place to decide. Klickbee gives you the building blocks, not a consent banner.

Session replay and masking

Replay records what the visitor sees so you can watch the session later. Its defaults protect typed data:

  • All typed input values are masked. Password, email and phone fields are always masked.
  • Ordinary page text is not masked. If a page shows personal data (an account page, an order summary), mark it yourself.
  • Images, fonts and canvas content aren't captured; at playback they load from your live site.

Add one of these attributes (or the matching class) to any element:

AttributeClassEffect
data-kb-blockkb-blockThe element is replaced by a placeholder.
data-kb-maskkb-maskThe element's text is masked.
data-kb-ignorekb-ignoreChanges inside the element aren't recorded.
<div data-kb-block>Everything in here is hidden from recordings.</div>

Recording pauses after 5 minutes without activity, and a single session records at most 30 minutes. To turn replay off entirely, use data-replay="false" on the script tag, or replay: false in the npm package.

Identifying visitors

By default visitors are anonymous. If you call identify, you link a visitor to an identifier of your own, for example your user id:

window.klickbee.identify("user_1234", { plan: "pro" });

The identifier (255 characters at most) is attached to every following batch of that visitor and appears in the dashboard next to the visitor id on the session page and in the live feed. Call reset() when the user logs out: it forgets the identifier and gives the browser a new anonymous id.

Traits are stored exactly as you send them

The identifier and the traits you pass are stored as given, in the visitor record and in the identify event. They are not hashed or masked. Prefer an internal id over an email address, and don't pass anything sensitive as a trait.

One exception exists on purpose: when a goal sends a conversion to Meta or Google Ads from Klickbee's servers, an email found in the traits (or used as the identifier) is trimmed, lower-cased and sent to the ad platform only as a SHA-256 hash, never in clear text. See Conversions.

How long data is kept

A daily clean-up removes old data. These are the periods the clean-up uses:

DataFreePro
Events180 days180 days
Session replays7 days60 days

When you delete a site, everything tracked for it is deleted with it. Data is also kept when a site goes over its quota or is suspended: it is only removed by the normal clean-up. See Billing.

AI features

If you use the Pro AI features, the content needed to produce the result is sent to Anthropic's Claude to generate it:

  • AI summary of a session: the session's journey (pages and time spent), event names and types, the browser, and the city and country.
  • Suggested goals: a brief of your site: top pages and events, channel mix, most-clicked labels, and text visible on a recent recording of your top page.
  • Suggest variations (Experiments, Page A/B): a brief of one page: its top clicks, how far visitors scroll and where they spend time, a sample of its visible text, and engagement figures.

These run only when you click the button, and only on Pro sites.

On this page