The Basics: What Gets Collected the Moment You Land on a Page

Before you click anything or type a single character, a website has already gathered several data points about you. Your IP address — a number assigned to your internet connection — is visible to every site you visit. From it, sites can infer your general geographic location, typically down to the city level. Your browser type and version, operating system, screen resolution, and device type are also transmitted automatically as part of standard web requests.

This technical layer of data, often called passive data, requires no interaction from you. It's part of how the internet works. But it still feeds into detailed profiles. For a broader look at how your online behavior shapes your digital footprint, see our overview of digital habits.

79%

Americans concerned about data collection

According to Pew Research Center, roughly 79% of US adults say they are concerned about how companies use the data collected about them.

~300

Average third-party trackers per site visit

Research by privacy analytics firms has found that browsing a typical set of popular websites can expose a user to hundreds of third-party tracking requests in a single session.

83%

Browsers with unique fingerprints

Electronic Frontier Foundation research on browser fingerprinting found the majority of tested browsers produced fingerprints distinct enough to identify individual users.

Cookies, Trackers, and the Third-Party Network

Cookies are small text files a website stores in your browser to remember your session — things like login state or shopping cart contents. These first-party cookies are generally necessary for basic site functionality. The more privacy-significant category is third-party cookies, set not by the site you're visiting but by external advertising and analytics networks whose code is embedded in the page.

A single news article, for example, may load tracking scripts from a dozen different ad-tech companies simultaneously. Each one can record that you visited that page and combine it with data from other sites in their network. Over time, this builds a cross-site behavioral profile — what topics you read about, how long you spent, and what you clicked. This tracking persists across websites you've never directly interacted with.

Many readers are surprised to learn that common misconceptions about privacy tools don't hold up. Our article on private browsing myths covers what actually stops tracking — and what doesn't.

“The web was not designed with privacy as a foundational property. Every layer of tracking we see today has been built on top of an architecture that was never intended to protect user anonymity.”

— Bruce Schneier, Security technologist and author on privacy and cryptography

Browser Fingerprinting: The Cookieless Tracker

As more browsers restrict or block third-party cookies, some trackers have shifted to browser fingerprinting — a method that assembles a unique identifier from characteristics of your browser environment. These include your installed fonts, graphics rendering behavior, time zone, language settings, and hardware specs. Individually, none of these are unique. Combined, they often are.

Unlike cookies, fingerprints can't be deleted because they aren't stored on your device — they're reconstructed each time you visit. Research by the Electronic Frontier Foundation has demonstrated that a large majority of browsers produce fingerprints unique enough to track individuals reliably. This makes it one of the harder tracking methods for everyday users to counter.

Data You Actively Provide — and Where It Goes

Beyond passive collection, websites gather data you provide directly: names, email addresses, phone numbers, payment details, and form responses. Even partial form entries — data you type but don't submit — can sometimes be captured by certain analytics scripts, depending on how a site is built.

Once collected, this data rarely stays in one place. It may be shared with marketing partners, analytics providers, or sold to data brokers who compile and resell detailed consumer profiles. If you're joining a new platform, reviewing its data practices beforehand is worthwhile — see our guide on protecting your privacy on new platforms.

US privacy law provides limited federal protection for most users. The CCPA gives California residents specific rights — including the right to opt out of data sales — while other states have begun passing similar legislation. A comprehensive look at your legal options appears in our Digital Privacy A to Z guide.

Review a Site's Privacy Policy Before Sharing Data

Privacy policies are legally required disclosures of how a site collects, uses, and shares your data. While they can be long, the sections on 'data sharing' and 'third parties' are the most revealing. Many sites also offer opt-out controls buried in account settings or cookie preference menus — it's worth looking.