← All guidesArthea Affiliates | Guide

Tracking Affiliate Program: A Lean Attribution Stack for DTC Brands

10 min read | Updated October 2, 2026

Affiliate programs leak revenue when tracking is broken. You pay commissions for sales you cannot verify, lose affiliates who never get credit, and spend hours untangling attribution disputes. The fix is not another SaaS dashboard. It is a tracking system you actually understand, built on first principles. This article gives you the exact stack we use internally at Arthea: what to track, how to track it, and where to draw the line between building and buying.

01What is affiliate program tracking, and why does it break?

Affiliate program tracking is the system that records which affiliate referred a customer and attributes a sale or action to that affiliate. It breaks when the tracking identifier is lost between click and conversion, when multiple affiliates claim the same sale, or when attribution rules are unclear.

Most DTC brands inherit a tracking model from whatever affiliate platform they signed up for. They never inspect the underlying mechanism. Then they wonder why a top affiliate reports 50 clicks but the dashboard shows 3 conversions. The common failure points are:

  • Cookie deletion: Browsers like Safari and Firefox block third-party cookies by default. If your tracking relies on a cookie set by an affiliate network, that cookie often disappears before the customer checks out.
  • Cross-device jumps: A customer clicks an affiliate link on mobile, then completes the purchase on desktop. A cookie-based system loses the thread.
  • Missing identifiers: UTM parameters get stripped by email clients, social apps, or manual URL copying. Without a fallback, the click never gets recorded.
  • Last-click chaos: Multiple affiliates touch the same customer. Without a clear attribution rule, you either pay twice or pay the wrong person.

The core problem is simple: you are trusting a black box to handle money. Once you know the mechanism, you can fix it.

02Which tracking method should you use: cookie, postback, or server-to-server?

For most DTC affiliate programs, start with server-to-server postback tracking because it is not blocked by browser privacy changes. Cookie tracking is easier to set up but less reliable. Use both if you can, with postback as the source of truth.

Here is the honest comparison:

  • Cookie tracking: A referral link sets a first-party cookie on the affiliate's domain or your domain. On conversion, your checkout reads the cookie. Easy to implement, but first-party cookies can still be blocked by ad blockers or privacy settings, and they fail cross-device. Works as a fallback, never as the only method.
  • Postback URL: When a conversion happens, your system calls a URL on the affiliate's server or your tracking endpoint with the transaction details. The affiliate's server logs the event. This is server-to-server, so no browser involvement. Accurate and privacy-resilient, but requires you to fire the postback correctly on every conversion event.
  • Server-to-server API: The most robust option. You integrate directly with the affiliate's system or your own backend via API. You control exactly what data is sent, when, and how retries work. More setup, but zero reliance on client-side anything.

The decision framework is simple. If you are running a small program with fewer than 20 affiliates, start with a first-party cookie plus a manual spreadsheet. If you are running serious volume or paying real commissions, move to server-to-server postbacks immediately. Cookie-only tracking is how programs die.

03How do you set up affiliate tracking without a bloated SaaS stack?

You can set up affiliate tracking with a simple database, a unique referral link per affiliate, and a server endpoint that records conversions, instead of paying for a SaaS platform. The core pieces are a click tracker, a conversion event, and an attribution rule.

Here is the minimum viable system, step by step:

  • Create affiliate records. Use a Google Sheet, Airtable, or a simple SQLite database. Each affiliate gets a unique ID, a name, and a commission rate (e.g. 10% of order value).
  • Generate referral links. Every affiliate gets a link like yourdomain.com/?aff=123. Use a custom domain or URL shortener if you want clean links. The affiliate ID is the only required parameter.
  • Log clicks. When someone visits that URL, a small script or redirect logs the affiliate ID, timestamp, and a session identifier. You can do this with a lightweight serverless function, a no-code tool like Zapier or Make, or even a simple PHP script. The key is to also set a first-party cookie as a fallback.
  • Capture conversions. When an order completes, your checkout or ecommerce platform fires a webhook or callback to your tracking endpoint. Include the order value, order ID, and any available affiliate identifier (from the session cookie, URL parameter, or postback).
  • Apply attribution. Define one rule: last-click or first-click. Last-click means the most recent affiliate touch gets credit. First-click means the original referrer gets credit. Pick one and enforce it consistently.
  • Calculate payouts. Store each attributed conversion with the affiliate ID, order value, commission earned, and a unique transaction ID. Export monthly or on demand.

This is not a toy system. It is the same logic every affiliate SaaS runs under the hood. The difference is you see every moving part.

04What data should you track in an affiliate program?

Track at minimum the affiliate ID, click timestamp, conversion timestamp, order value, and a unique transaction ID. Also track the attribution method used, the referral URL, and the commission rate applied. This prevents disputes and lets you audit payouts.

Most disputes come from missing data. An affiliate asks, "Where is my commission for order #1234?" If you cannot show the click, the conversion, and the rule that assigned it, you pay to keep peace. The fields that matter:

  • Affiliate ID: Who gets credit.
  • Click timestamp: When the referral happened.
  • Conversion timestamp: When the purchase happened. The gap between click and conversion tells you if your attribution window is too short or too long.
  • Order value: The basis for commission. Track gross or net, but be consistent.
  • Unique transaction ID: The order ID from your store. This prevents double payouts if a webhook fires twice.
  • Referral URL: The exact link that was clicked. Useful for debugging and fraud checks.
  • Attribution method: Cookie or postback. If you change methods, you need to know which source each conversion came from.
  • Commission rate applied: If you have tiered affiliates, record the rate at time of conversion, not at time of payout.

If you track these eight fields, you can reconstruct any conversion and settle any dispute in under five minutes. If you only track affiliate ID and order value, you will lose hours and trust.

05Worked example: A lean affiliate tracking stack for a DTC brand

For a Shopify store, you can run affiliate tracking with a simple Google Sheet, a custom referral link structure, and a webhook from Shopify to a no-code tool like Make. Here is the exact runbook.

Assume you sell a $50 product and pay affiliates 10% per sale.

  • Step 1: Create the affiliate sheet. Columns: Affiliate ID, Name, Commission Rate, Email. Add affiliate 101 with rate 10%.
  • Step 2: Build referral links. Use your store domain with a query parameter: yourstore.com/discount/CODE?aff=101. The discount code can double as the affiliate identifier, but keep the aff parameter explicit.
  • Step 3: Log clicks. Create a simple Make scenario that watches for visits to URLs containing aff=. When triggered, write a row to a "Clicks" sheet: affiliate ID, timestamp, and a generated session ID. Also set a first-party cookie via a small JavaScript snippet on your storefront.
  • Step 4: Capture orders. In Shopify, create a webhook for order creation that sends order data to Make. The webhook includes order ID, total price, and any URL parameters captured in the checkout session if you pass them through.
  • Step 5: Attribute the sale. In Make, when an order webhook arrives, check for an affiliate identifier. If found (from the URL parameter or the cookie you set), look up the affiliate in your sheet. Write to a "Conversions" sheet: affiliate ID, order ID, order value, timestamp, commission earned (order value * rate).
  • Step 6: Audit and pay. At month end, sort the Conversions sheet by affiliate ID, sum commission earned, and send each affiliate a simple payout report. No SaaS fee, no mystery.

This runbook is illustrative. If affiliate 101 refers 100 clicks and 5 of those convert into $50 orders, the commission is 5 * $50 * 10% = $25. The math is the same whether you use a spreadsheet or a $500 per month platform. The spreadsheet just lets you see the math.

06Honest trade-offs: building vs. buying affiliate tracking

Building your own tracking gives you full control and no monthly SaaS fee, but you own the maintenance, edge cases, and fraud detection. Buying a tool like Refersion or Impact saves time but adds cost and locks you into their attribution model.

The trade-offs are concrete:

  • Cost: Building costs your time to set up and maintain, maybe $0 in software if you use free tiers. Buying costs $50 to $500+ per month, plus a percentage of affiliate payouts on some platforms. For a small program, buying is often more expensive than the commissions themselves.
  • Control: When you build, you can change attribution rules, add fraud filters, or export raw data whenever you want. When you buy, you work within the tool's UI and API limits. If the tool's reporting breaks, you wait for support.
  • Maintenance: Your own system breaks on your schedule: a webhook fails, a sheet hits row limits, a cookie setting changes. You fix it. A SaaS tool handles most of that, but you still monitor integrations.
  • Fraud detection: SaaS platforms bundle fraud detection features like click IP tracking, duplicate order flagging, and self-referral blocking. Building your own means you implement these one by one. For small programs, manual review is enough. For large programs, the time cost grows fast.
  • Integrations: Buying a tool gets you pre-built integrations with Shopify, WooCommerce, and major affiliate networks. Building your own means you wire webhooks and APIs yourself. That is a one-time effort, but it is real.

At Arthea, we build our own tracking for internal products because we want to tune attribution exactly to our revenue model and avoid paying a percentage of every affiliate sale. But we are not dogmatic. If you have a high-volume program with dozens of affiliates and no engineering time, a tool like Refersion or Impact is a rational choice. The mistake is choosing a tool without understanding what it does under the hood. Once you know the mechanism, you can decide.

07FAQ

How long should an affiliate cookie last?

Thirty days is a common default for DTC products with short consideration cycles. If your average time from first click to purchase is over two weeks, set the cookie or attribution window to 60 or 90 days. Match the window to your sales cycle, not to what the SaaS tool defaults to.

How do I prevent affiliate fraud?

Track IP addresses, flag suspicious click-to-conversion ratios, require unique transaction IDs, and never pay on self-referrals. Block known VPN or datacenter IPs if fraud becomes a pattern. For small programs, a monthly manual review of the conversions sheet catches 90% of abuse.

Can I track affiliates without cookies?

Yes. Use server-to-server postbacks or append the affiliate ID to the checkout URL and capture it in your order system. If your ecommerce platform lets you pass a custom field through checkout, you can attribute without any browser-based tracking.

What is the difference between first-click and last-click attribution?

First-click gives credit to the affiliate who introduced the customer. Last-click gives credit to the most recent affiliate touch before conversion. Last-click is simpler and common, but it incentivizes bottom-of-funnel spam. First-click rewards content affiliates who do the heavy lifting. Pick one and enforce it consistently across your whole program.

Affiliate tracking does not have to be a mystery or a monthly tax. Start with a spreadsheet, a referral parameter, and a webhook. Move to server-side postbacks when volume demands. Audit the data yourself before you trust any dashboard. The system is the product, not the platform. For the full system breakdown, see our affiliate tracking hub.

Frequently asked questions

What is affiliate program tracking, and why does it break?
Affiliate program tracking is the system that records which affiliate referred a customer and attributes a sale or action to that affiliate. It breaks when the tracking identifier is lost between click and conversion, when multiple affiliates claim the same sale, or when attribution rules are unclear.
Which tracking method should you use: cookie, postback, or server-to-server?
For most DTC affiliate programs, start with server-to-server postback tracking because it is not blocked by browser privacy changes. Cookie tracking is easier to set up but less reliable. Use both if you can, with postback as the source of truth.
How do you set up affiliate tracking without a bloated SaaS stack?
You can set up affiliate tracking with a simple database, a unique referral link per affiliate, and a server endpoint that records conversions, instead of paying for a SaaS platform. The core pieces are a click tracker, a conversion event, and an attribution rule.
What data should you track in an affiliate program?
Track at minimum the affiliate ID, click timestamp, conversion timestamp, order value, and a unique transaction ID. Also track the attribution method used, the referral URL, and the commission rate applied. This prevents disputes and lets you audit payouts.
The Arthea ecosystem

Arthea Affiliates pays a recurring commission for promoting either product — same attribution, same payout, one account.