Platform
First-party tracking
The base layer of DataCops. One script, loaded from your own domain through a single DNS record, captures visits and conversions as first-party, so browsers treat it as part of your site and you see the traffic other tools lose.
What it is
First-party capture means the DataCops script is served from a subdomain of your own domain, like datacops.yourstore.com, over its own valid certificate, and sends its data back to the same subdomain. To the browser it is part of your own site, not a third-party tracker. This is the foundation every other part of DataCops sits on: the cleaner the capture, the more real people everything downstream can count.Why third-party capture loses data
A normal pixel loads from someone else's domain, one shared across thousands of sites. Browsers treat that as an outsider. Ad blockers match it against lists of known tracker domains and remove it. Safari and Brave limit what it can store. And the request names it uses, words like track, pixel or analytics, are exactly what filter lists look for. So a share of your real traffic is never captured at all, and nothing tells you how big that share is.
How it works
- Your subdomain points at DataCops. One CNAME record, datacops to cdn.joindatacops.com.
- DataCops issues a certificate for that exact subdomain, so it serves over HTTPS like the rest of your site.
- The script loads from your domain and posts each visit and event back to it.
- Request names stay off block lists. Every DataCops route is checked against real ad-block filter lists before it ships, and words like track, pixel and analytics are not allowed in route names.
- Each visit gets a verdict. Bot checks and IP intelligence run on the session, so what you count is a real person, not just a hit.
No setup removes every possible block. A visitor with a strict custom rule or a DNS-level blocker can still stop the script. First-party capture moves you from the easiest thing to block to one of the hardest.
Set it up
First-party capture is a no-code setup in two steps: paste one script tag in your <head>, then add one DNS record so the script loads from your own domain.
| Step | What you do | Guide |
|---|---|---|
| 1. Script | Paste the script tag with your public cop key into your site's head. | Install the tracking script |
| 2. DNS | Add CNAME datacops pointing to cdn.joindatacops.com, or use the one-click button. | First-party domain setup |
DataCops checks the record every 30 seconds for up to 48 hours, issues the certificate, and emails you once your site is set up. It works on every plan.
What it captures
Out of the box, with no tagging, the script records:
| What | How |
|---|---|
| Visits and page views | Every page load becomes part of a session, with device, browser, country and referrer. |
| Ad click IDs | fbclid, gclid, wbraid, gbraid, ttclid, li_fat_id, msclkid and twclid are kept with the visitor, plus Meta's fbc and fbp. |
| Campaign tags | utm_source, utm_medium and utm_campaign from the landing URL. |
| Purchases | Thank-you and order-confirmed pages, including single-page apps, with value and currency when the page shows them. |
| Sign-ups and forms | Registration forms, OAuth sign-ups and form submits. An email in the form links the visitor to a person. |
| Calls and messages | Clicks on phone, email and WhatsApp links. |
Auto-captured events are recorded straight away, but nothing is sent to an ad platform until you map it, for example auto purchase to Purchase. For buttons the auto capture does not know about, the point-and-click picker lets you click the element on your own site. See PixelCops and Event Manager.
Remembering returning visitors
Safari clears storage written by scripts after seven days, so a buyer who comes back on day ten looks like a stranger. Because DataCops runs on your own subdomain, it can set a signed first-party cookie from the server instead, kept for up to 400 days and refreshed on each visit. It is only set for clean, consented sessions, it is switched on per site, and it only works on your own subdomain, not the shared host.
When a visitor shares an email, at sign-up, login or in a form, DataCops links it to their ad click. If they come back later on a new device and use the same email, the earlier click can still be credited. And when visitors move from yoursite.com to app.yoursite.com by clicking a link, a short signed link parameter carries their ID across. See 400-day durable identity.
First-party vs server-side capture
DataCops captures in two layers. They work together and are not either-or.
- First-party capture is the base. The script on your own domain captures the visit from inside the page. It is the one thing every site turns on.
- Server-side capture is the optional extra. A Cloudflare Worker reads the ad click from the link the moment the request arrives, before any script runs. DataCops joins it to the page visit and only fills click IDs the script missed.
Shopify stores
Shopify storefront pages get first-party capture the same way. Once your own domain, not the free myshopify.com address, has its datacops record live, the theme embed loads the script from your subdomain on its own. No extra step inside Shopify.
Checkout runs in Shopify's sandbox, where the DataCops Web Pixel follows the funnel from add to cart to checkout completed. Once your subdomain is live, the pixel sends to it too, within about 15 minutes and without any change on your side. The paid order itself also arrives server-side from Shopify, and the order ID makes sure the pixel copy and the server copy count as one sale. See Shopify.
Where the data goes next
Captured visits feed your dashboard, where the user count is real people only. Mapped conversions pass the consent check, the duplicate check and, if you turn it on, Real people only, and then go server-side to the ad platforms you connect: Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X.