URLTracker — Track, analyze, grow

URLTracker documentation

Conversion postbacks

Record qualified server-side outcomes against tracked links using an authorized postback workflow. This guide explains the complete workflow, what the reporting means, and what to verify before using it in a live campaign.

No credit card. No tracking code required.

01

Set up deliberately

Name the work clearly, validate the destination, and decide which result should count before publishing.

02

Test the real path

Use the final link or QR code on representative devices and inspect the complete redirect journey.

03

Read context together

Evaluate clicks, unique estimates, automation, devices, locations, referrers, and outcomes as related evidence.

04

Respect the boundary

Collect only necessary campaign data, disclose measurement, and never treat an IP address as a verified person.

SECTION 01

What conversion postbacks covers

A conversion turns a redirect request into business context by recording a later qualified action, such as an approved registration, booking, order, or subscription. URLTracker’s current workflow accepts an authorized postback rather than trusting an unauthenticated browser event as proof of value.

URLTracker is a redirect-measurement service. A visitor requests a short HTTPS route, the service records permitted technical and campaign context, and the browser is sent to the destination configured by the link owner. The dashboard turns those requests into practical views, including time, eligible and estimated unique activity, recognized automation, available referrers, UTM labels, device and browser patterns, approximate network-derived geography, QR assets, pixels, and supported conversion postbacks.

Those views describe requests and configured business events; they do not reveal a person’s private identity. Network addresses may be shared, translated, rotated, or routed through proxies. Referrer headers can be missing. Device and geography fields are inferred from technical signals and can be wrong. Treat the report as campaign evidence, not as a directory of named visitors.

SECTION 02

Prepare the campaign and measurement plan

Define the event name, when it should fire, which internal record is authoritative, whether revenue is gross or net, the currency convention, and how duplicate submissions will be prevented. Never send full payment details, passwords, health data, or unnecessary customer fields in a conversion request.

Write down the final destination, campaign owner, publishing channel, launch date, expected audience, and the action that represents success. Decide whether one route is enough or whether placements need separate links. Separate only the choices you intend to compare: for example, a profile link and a video description, or the primary and secondary calls to action in an email.

Use stable lowercase UTM values and a shared naming sheet. A useful pattern is the publishing platform in utm_source, the channel category in utm_medium, the initiative in utm_campaign, and the creative or placement in utm_content. Never place email addresses, customer names, order details, medical information, or confidential internal fields in a public URL.

  • Confirm that the destination is legitimate, mobile-ready, and available over HTTPS
  • Define a qualified outcome before reviewing click totals
  • Create separate routes only for decisions that matter
  • Keep personal and sensitive information out of slugs and UTM values

SECTION 03

How the feature behaves in URLTracker

The worker provides a conversion postback route protected by the configured postback token. A server you control should send the supported link reference and approved outcome fields only after the authoritative event occurs. Store the token as a secret, never in frontend code, a public repository, a URL, or a screenshot.

Use the dashboard controls to copy the published route, open its detail view, edit the short code where supported, and enable or disable forwarding. Disabling a route is an operational control; it should not replace destination maintenance, campaign archiving, or incident procedures. If a route appears in printed material or old content, document the dependency before changing it.

A successful request is only the beginning of the journey. Email-security scanners, social preview crawlers, uptime systems, corporate gateways, and browser privacy tools may request a link automatically. URLTracker identifies known automation where possible, but classifications are probabilistic. Test using the same channel and device pattern as the audience instead of relying only on a dashboard preview.

SECTION 04

Interpret reporting and validate outcomes

Validate with a non-production or clearly labelled test event, then confirm that the correct link report shows the expected conversion and value once. Monitor failed requests and duplicates at the sending system. A redirect click and a postback may occur at different times, and late conversions should be analyzed with a documented attribution window.

Begin with a consistent date range, then compare total requests with eligible clicks, unique estimates, bot classifications, time patterns, country and device distributions, referrers, and campaign labels. A sudden burst from one network or repeated software signature may have a different meaning from steady activity followed by registrations or purchases. Use the destination’s authoritative system to confirm important business outcomes.

Differences between URLTracker, an advertising platform, an email sender, and a web-analytics product are normal. Each system observes a different point in the path and may use different bot rules, identities, consent states, attribution windows, time zones, and deduplication. Reconcile definitions before reconciling numbers, and record the definition used in recurring reports.

SECTION 05

Privacy, security, and current limits

The current postback is a focused server-to-server feature, not a promise of a general public analytics API or a complete multi-touch attribution platform. Authentication and deduplication are shared operational responsibilities. Reconcile financial reporting with the payment or order system, not the link dashboard alone.

Provide an accurate privacy notice, obtain consent where law or platform rules require it, limit access to analytics, establish a retention period, and protect exports. Do not use a short route to conceal a harmful destination, impersonate another organization, evade moderation, or surprise an audience. Link text and surrounding content should explain what a visitor is opening.

URLTracker is currently free during launch, but free availability is not a promise of permanent unlimited capacity. The service does not guarantee rankings, delivery, attribution perfection, or identification of individuals. Features evolve; verify critical workflows with a controlled test before a high-volume campaign and preserve an independent record of destinations and campaign names.

Step by step

Start measuring in minutes.

  1. 1

    Define the event contract

    Choose the authoritative trigger, event name, value convention, currency, and deduplication key.

  2. 2

    Protect the token

    Store the postback credential only in the secret manager of the server sending the outcome.

  3. 3

    Send a controlled event

    Use a test link and non-sensitive payload, then verify status, logging, attribution, and duplicate behavior.

  4. 4

    Reconcile outcomes

    Compare dashboard attribution with the authoritative CRM, booking, subscription, or order record.

Frequently asked questions

Questions about urltracker documentation.

Should the postback token be used in browser JavaScript?

No. It is a secret for an authorized server-to-server request and must not be exposed to a visitor.

Is URLTracker the financial system of record?

No. Use your payment, order, or accounting system as the authority and treat URLTracker as campaign-attribution context.

Does URLTracker identify exactly who clicked?

No. It reports request and campaign context. IP addresses, devices, and approximate locations are not reliable proof of a person’s identity.

Why do two analytics products show different totals?

They observe different stages and may apply different identities, bot filters, attribution windows, consent rules, time zones, and deduplication.

Can I use sensitive data in a link name or UTM value?

No. URLs are commonly logged and shared. Keep personal, confidential, and sensitive information out of public routes and parameters.

Create your first tracked link free.

Use the complete URLTracker analytics workspace during launch. No credit card is required.

Start tracking links