Meritt Get started

The attribution window, the cookie, and what actually lasts a year

Sixty days, ninety days: that setting is a commercial decision. What really decides the fate of a recurring commission is somewhere else.

What an attribution window really is

The attribution window is how long a click can still explain a sale. Sixty days by default here: somebody clicks on 1 March, buys on 15 April, the sale is attributed. On 5 May, it is not.

That is a commercial setting, not a technical one. It answers a question with no universal right answer: how long after seeing somebody's recommendation do you still consider them the reason for the purchase? A week for an impulse buy. Ninety days for business software that gets evaluated by a committee.

Hence the window being set per program, and sometimes per affiliate: an affiliate writing comparison articles read for two years is not in the same position as one posting a promo code on a sale day.

The click sets a cookie on your domain holding the click id. At checkout your server reads it and knows who to credit.

That mechanism has three limits, and none is fixed by a setting.

  • It does not survive a change of device. You click on your phone on the train, you buy that evening on your laptop. Two browsers, two stores: the first one's cookie does not exist in the second.
  • It does not survive a clear-out. Private browsing, clearing site data, a reinstall.
  • It does not survive browser policy. Safari caps at seven days the cookies set by a script on a delegated domain — whatever window you configured. A sixty-day window then does not have the reach its number suggests.

For a commission on the first sale, that is fine: most purchases follow the click by a few days. For a recurring commission, it is the whole problem.

The real subject: the renewal in month eleven

You promise 20% for life on a monthly subscription. The initial sale is easy to attribute. The renewal in month twelve arrives eleven months later, triggered by your billing system, with no browser, no page, no cookie. No attribution window can help: there is nothing to attach.

What decides is whether you ever wrote down, somewhere, that this customer belongs to this affiliate.

Binding the identity

There is exactly one moment when your server knows both things at once: checkout. At that point it has the click cookie in the request, and the id it has just given that customer — cus_42, user_1183, an email address, it does not matter, as long as it is always the same for the same person.

One call is enough to say so:

POST /v1/identify
{
  "clickId": "…",              // the _mrt cookie, read server-side
  "externalUserId": "cus_42"   // your id, in your system
}

Once that link exists, it no longer depends on any browser. Next year's renewal arrives with cus_42, and the commission lands in the right place.

The attribution window protects the first sale. The identity binding protects every one after it.

Three levels, weakest to strongest

LevelWhat carries itWhat it survives
The click A first-party cookie The same device, for the length of the window
The identity Your customer id A change of device, a year, a cleared cookie
The payment The reference at your provider A refund, which has to claw the commission back

Each level is optional, and each one makes attribution sturdier than the one before. A program that only sets the first works — until the first disputed recurring commission.

The case with no link at all

An affiliate speaking on a podcast, on camera or on stage has no link to click. Their listener remembers a word and types it at checkout. That is what the discount code is for: your payment system tells you which code was used, and the code belongs to a person.

One rule, non-negotiable: one code per affiliate. Two codes for the same person, or one code shared by two affiliates, and the same sale arrives twice under two names. That is not a mistake you clean up neatly afterwards.

When two affiliates claim the same sale

It happens, and it has to be decided before it happens. The usual rules:

  • Last click wins — the most widespread convention, and it rewards whoever triggered the purchase.
  • An identity binding beats a cookie, because it is more precise: it names a person, not a browser.
  • A discount code beats a click, because it was typed deliberately at checkout.
  • Self-referral does not count. An affiliate buying through their own link brought nobody, and that has to be refused at attribution — not at payout, later, when the commission is already sitting in their balance.

What has to be counted honestly

Two details completely change the figures you show an affiliate.

Visitors, not page loads. An affiliate refreshing their own page ten times has not made ten clicks. If earnings per click are computed on the number of requests, the figure is divided by ten, and the affiliate concludes your program is worthless.

Bots are not visitors. Link previews from Slack, WhatsApp or a feed reader open the URL. They have to be redirected — otherwise the preview is broken — but not counted.

Being able to prove it a year later

The last point is not attribution, it is retention. An affiliate writing to you in March about a commission from last summer deserves a precise answer: which click, which day, which customer, which sale, which rate, which payout.

That assumes nothing was overwritten along the way. A commission is an entry; a correction is one more entry. A refund, a refusal, a returned payout then read in the order they happened, and "why this amount" has an answer.

Meritt does what this article describes.

Tracking on your own domain, attribution by click and by identity, payouts from your own PayPal and Wise accounts, invoices and credit notes written for you. $0, $49 or $99 a month, never a percentage.

Read next