Revenue Attribution & Consent

Why attribution needs consent, and how to handle it

Written By David

Last updated 24 days ago

Revenue Attribution is one of Cromojo’s most powerful features: it connects a sale back to the marketing source that drove it, so you can see which channels actually make you money. But because it links payment and customer information to a visitor, it is more privacy-sensitive than basic analytics. And unlike cookieless page-view analytics, it is generally not consent-free. This article explains why, and what to do.

Not legal advice. This article gives general, plain-language guidance, not legal advice. Privacy laws vary by country and by your role. You are responsible for your own privacy policy, lawful basis, and any consent your site needs. When in doubt, consult a qualified privacy professional.

Why attribution is different from basic analytics

Basic analytics counts anonymous page views and sources. Revenue attribution goes a step further: it ties a purchase (which can include a hashed customer reference, an amount, and order IDs) to a specific visitor and their journey. The moment you connect a real purchase to a person’s browsing, you are processing personal data in a more direct way.

  • Basic analytics: aggregated, pseudonymous, often usable without consent.

  • Revenue attribution: links identifiable purchase data to a visitor, a higher privacy bar, usually requiring a lawful basis and, in many cases, consent.

Plain version: counting visitors is low-risk. Saying “this person, who paid 49 euros, came from this Instagram ad” is personal data, so treat it with more care.

What this means for you legally

Because attribution processes identifiable purchase data, you should assume you need a clear lawful basis, and in many jurisdictions explicit consent, before enabling it. In practice that means:

  • Disclose it in your privacy policy: name the data used for attribution (for example, a hashed customer reference, the purchase amount, and order IDs), the purpose (marketing measurement), and the lawful basis.

  • Get consent where required, before the data is linked, especially under GDPR/ePrivacy in the EU and UK.

  • Sign any required data processing agreement (DPA) with Cromojo, since Cromojo processes this data on your behalf.

  • Apply data subject rights (access, deletion, objection) to attribution data too.

What attribution stores: a hashed customer reference, the amount, and Stripe order identifiers (subscription, invoice, and payment IDs), linked to the same anonymous visitor ID. Unlike raw analytics events (auto-deleted after 60 days), these revenue records have no automatic expiry and are kept until deleted.

How to enable attribution responsibly

  1. Update your privacy policy first, so the disclosure is live before you turn attribution on.

  2. Put attribution behind consent if you operate in (or sell to) regions that require it. Gate it the same way you gate analytics in your consent banner.

  3. In Cromojo, go to Settings → Analytics → Conversion Metrics, set Metric source to Revenue, and connect your Revenue provider (Stripe or Shopify). Attribution turns on once a provider is connected, so do this only after the steps above are in place.

  4. Document your decision (lawful basis, consent method) so you can show it if a user or regulator asks.

If you’re not ready for consent yet

You don't have to use attribution to get value from Cromojo. Until your consent flow is ready, you can keep using cookieless basic analytics (visitors, sources, page views) and simply not turn revenue on, leave Metric source set to Goals and don't connect a revenue provider. You'll still see which channels bring traffic, just not the revenue link, and you stay on the lighter-touch privacy footing.

To switch attribution off later, go to Settings → Analytics → Conversion Metrics and set Metric source back to Goals (or disconnect your Stripe/Shopify revenue provider). New purchases will no longer be linked to visitors.

Related articles