Guide
What is visitor identification — and is it GDPR-compliant?
Visitor identification resolves some of the anonymous people browsing your store into contactable profiles, by matching signals against a third-party identity graph. It can be run in a GDPR-compliant way — but only if it's consent-first and you understand two things up front: it resolves a share of visitors (not all of them), and you remain the data controller responsible for a lawful basis. This guide is deliberately honest about both.
What it actually does
When someone visits your store without logging in or entering an email, they're anonymous to you. Visitor identification takes the signals available and matches them against a third-party identity graph — a large, maintained dataset that maps signals to contactable profiles. For the share it can match, you get a profile you can add to your marketing audiences. That's the whole mechanism: it's a lookup against an external graph, not magic and not surveillance of individuals you build yourself.
How many visitors get resolved — honestly
Not all of them. In practice, tools resolve a share of anonymous traffic, and the exact rate varies by store and audience. The identity graph is US-centric, so a store with mostly US traffic will see a higher match rate than one with mostly EU or rest-of-world traffic. Anyone promising to 'identify all your visitors' is overselling. A realistic frame is: recover some of the high-intent visitors you'd otherwise lose entirely.
Is it GDPR-compliant?
It can be — but 'the tool is compliant' is the wrong way to think about it, because you remain the data controller. Compliance depends on how it's run. Two things matter most:
- Consent and lawful basis. You are responsible for having a lawful basis to process the personal data and for honouring the consent signals your visitors give. Growth Layer is built consent-first: consent signals and Global Privacy Control (GPC) are honoured, and opt-outs are suppressed before anything syncs.
- The identity graph is US-centric. This is material to a GDPR assessment — matching involves a third-party dataset, and you should account for that in your privacy notice and processing records. We state it plainly rather than burying it.
Growth Layer runs on Sico Software's own hardware, with GDPR and data deletion built in from day one, and pools patterns, not people. But the lawful-basis decision for your store is yours to make — treat any 'fully GDPR-compliant, nothing to do' claim with suspicion.
What consent-first means in practice
Consent-first isn't a slogan; it's the order of operations. Before any matched contact is synced into Klaviyo or Meta, consent state and GPC signals are checked and opt-outs are suppressed. Suppression happens at the point of sync, not as an afterthought. The goal is that the only profiles that reach your marketing tools are ones there's a basis to reach — and that a visitor who has said no is never in the pipeline.
Frequently asked questions
Does visitor identification identify every visitor?
No. It resolves a share of anonymous visitors, and the rate varies because the identity graph is US-centric. Claims to identify all your visitors are not credible.
Is it legal in the EU/UK?
It can be run compliantly, but you remain the data controller responsible for a lawful basis. Growth Layer is consent-first (consent + GPC honoured, opt-outs suppressed) and hosts data in the EU with deletion built in, but the lawful-basis decision for your store is yours to make.
What does 'pool patterns, not people' mean?
It's the privacy posture: the product is oriented toward aggregate behaviour and honouring individual opt-outs, rather than building profiles of people who have declined to be reached.