Cross-Device Tracking
Date: 2026-08-17
Recognising that the phone browsing at lunchtime and the laptop buying at nine are the same person. Research on one device and purchase on another is one of the commonest patterns in commerce, and without a login there is now essentially no reliable way to join them — which means a known share of your attribution is simply wrong.
Cross-device tracking is attributing activity on several devices or browsers to one person, either deterministically (a shared login) or probabilistically (matching signals).
What breaks without it
REALITY WHAT YOU RECORD
Tue 12:40 phone, Instagram ad user A: paid social → 1 session,
browses 4 products no purchase, "bounced"
Wed 19:15 laptop, Google "brand" user B: organic brand → 1 session,
buys £180 purchase £180
one person, one journey, one two users, two sessions
purchase caused by the ad the ad gets no credit
brand search gets all of it
Three separate errors from one missed join: user counts inflated, the paid channel undervalued, and the customer’s real journey invisible. All three push spend towards bottom-of-funnel channels that are receiving credit for demand created elsewhere — Attribution Models, Multi-Touch Attribution.
The two methods, and the state of each
| Deterministic | Probabilistic | |
|---|---|---|
| Basis | A shared identifier the user provided — usually a login, or an email hash | Statistical inference from IP, user agent, behaviour, timing |
| Accuracy | High, where it applies | Moderate at best, unverifiable in practice |
| Coverage | Only logged-in users | Theoretically everyone |
| Regulatory position | Defensible with consent and a lawful basis | Difficult — inferring identity is profiling |
| Availability now | Yours to build | Largely gone — see below |
Probabilistic matching has been substantially degraded by IP masking, user-agent reduction and platform restrictions on fingerprinting signals. Where it still functions it’s both less accurate and harder to justify to a regulator than it was — Browser Privacy Restrictions, Fingerprinting.
So the practical answer is deterministic or nothing, and deterministic means a login.
The login problem
Cross-device measurement is downstream of an account strategy, which is a product decision rather than an analytics one.
typical UK commerce site
logged in at some point in a purchase journey ~30–50%
logged in during EARLY research much lower — often <15%
↑ and early research
is exactly the part
you're trying to join
The asymmetry is the whole difficulty. People log in to buy, not to browse — so the identified half of the journey is the half you could already attribute, and the anonymous half is the half that needed joining. Increasing login rate at the point of purchase doesn’t fix this; increasing it during research does, and that’s a much harder product problem.
Things that genuinely help: persistent login with long-lived sessions, a real reason to have an account during browsing (saved items, saved sizes, price alerts), and identifying from an email click — a link with a signed identifier does join the device to a known person, and it’s the highest-yield lever most retailers already have — Lifecycle Messaging.
Backwards stitching
When someone logs in on device B, you learn retrospectively that device A’s earlier activity was theirs — if you kept it and if you can link it.
device A (phone) anon_id a1 Tue: 4 product views
device B (laptop) anon_id b7 Wed: login as user 4821, purchase
on login: user 4821 ← b7
user 4821 ← a1 ← only if a1 was EVER linked to 4821,
e.g. they logged in on the phone once
in the past
Two consequences worth planning for. The join is only possible for devices that have been identified at least once, so a genuinely new device’s prior anonymous activity is unrecoverable. And applying the join retroactively means historical reports change — yesterday’s user count falls as identities merge, which looks like a data error unless the modelling layer handles it explicitly — Identity Stitching, Event Streams vs Aggregates.
Measuring the gap rather than closing it
Since most of it can’t be fixed, the useful move is quantifying it.
- Cross-device rate among identified users. For customers who are logged in across devices, what proportion of purchases involved more than one device? If it’s 35% of your identified base, assume something similar in the anonymous base — that’s the scale of the distortion in every attribution report
- Assisted-conversion share among identified users, versus what the same journeys would look like if you’d treated each device separately. The difference is the undercount
- Report the caveat with the number. “Paid social is credited with 8% of revenue; among identified cross-device customers it appears in 19% of purchase journeys” is a far more honest statement than either figure alone
The rigorous answer is not tracking at all. Where the question is “did this channel cause incremental revenue”, geo holdouts and marketing mix modelling answer it without needing to identify anybody — and they’re the methods that survive as tracking degrades further — Incrementality Testing, Geo Holdout Tests, Marketing Mix Modelling.
The compliance position
- Linking devices to a person is processing personal data, and needs a lawful basis and disclosure in the privacy notice — UK GDPR and PECR for Analytics, Legitimate Interest vs Consent
- Probabilistic matching is harder to justify than deterministic, since the user neither provided nor can easily correct the link
- Hashed email as a join key is still personal data. Hashing is pseudonymisation, not anonymisation — a hashed email joins to a person by design, which is the whole point of using it — Pseudonymisation and Anonymisation
- Deletion requests span every device record, which is only tractable if the identity graph is one system rather than five vendors’ internal ones
Where it interacts
- Identity Stitching — the same problem within one device; this is the harder outer case
- Anonymous and Identified Users — the two states, and why the transition between them is where the accounting gets difficult
- Attribution Windows — cross-device journeys are longer, so a short window truncates exactly the journeys this affects
- Customer Lifetime Value — an unjoined customer appears as two customers with half the value each, which distorts every cohort and LTV figure downstream