Developer

Install the tracking script

First-party capture is a no-code setup: paste one script tag, then add one DNS record so it loads from your own domain. For what first-party capture is and why it matters, see the product page.

Step 1: Add the script to your head

Paste this one line inside the <head> of every page. Replace YOUR_COP_KEY with your public key from Settings, then API Keys. This is the script that captures the visit.

HTML
<script id="datacops_script"
  src="https://cdn.joindatacops.com/script?cop_key=YOUR_COP_KEY" async></script>

On its own, this already works: the script loads and captures. But it is loading from the shared DataCops domain, which is the easiest thing for a blocker to catch. Steps 2 and 3 make it first-party.

Step 2: Point a subdomain with one DNS record

In your domain's DNS settings, add this record. It points a subdomain of your own site at DataCops.

TypeHostValue
CNAMEdatacopscdn.joindatacops.com

That gives you datacops.yourstore.com. On Cloudflare, set the record to DNS only (grey cloud), not proxied. DataCops checks the record, then issues a real, valid certificate for that exact subdomain. From the browser's point of view, a request to your own subdomain is a first-party request, not a third-party one. The full walkthrough, with provider tips and fixes, is in First-party setup.

Step 3: Load the script from your domain

When the subdomain shows a valid padlock, change the script's host to your own subdomain. The cop_key stays the same.

HTML
<script id="datacops_script"
  src="https://datacops.yourstore.com/script?cop_key=YOUR_COP_KEY" async></script>

Keep the id="datacops_script". The script reads its own tag to find out which host it was loaded from and which cop_key it carries, then sends every request back to that same host. So once the tag points at your subdomain, all capture traffic is first-party too, with no other change.

What the script sends

Why this matters: ad blockers and browser privacy rules mostly act on known third-party tracker hosts. A request to datacops.yourstore.com is a request to your own site, so far more real visits reach DataCops, and more real conversions reach your ad platforms.

Everything goes to the host in the script tag, with your cop_key in the query string.

RequestWhen
POST /collectPage views, events and bot signals from the browser.
POST /identifyWhen window.dcutils.identifyUser(email) runs, or a form you mapped in the picker is submitted. See the SignupCops SDK.
POST /collect/workerOnly from the optional server-side capture worker, not the browser.

Form fields are only read after the visitor has given consent. In Europe the built-in consent banner asks first, and Google Consent Mode v2 is on by default.

Verify

Check both the subdomain and the data, in this order:

  1. Open https://datacops.yourstore.com in a browser. A valid padlock means the certificate is live.
  2. Load any page of your site with the browser's network tab open. Requests to /collect should go to your subdomain, not to cdn.joindatacops.com.
  3. Check your DataCops dashboard. The visit appears within seconds.

Good to know

  • Shopify stores can use the DataCops Shopify app instead of pasting the tag. See Shopify.
  • Add the tag once, in the shared head of your site, so it runs on every page.
  • The cop_key is public and safe in page source. Your private key never goes in the browser. See Authentication.
  • On the first-party subdomain DataCops can also set a long-lived server cookie. See server-side cookies.
  • A Cloudflare Worker that forwards server-side hits must post to cdn.joindatacops.com, not to your datacops subdomain. See Cloudflare Worker.
Was this page helpful?