Trace
Getting started

Install the tracking script

Add Trace's lightweight script to your site, check that it works, and start collecting data.

Trace collects data with a single script tag. Once it's on your pages, pageviews, sessions, outbound links, file downloads and form submissions are recorded with no further code.

1. Add your site

Sign up at https://data.whos1.bid/signup, then add a website from the dashboard with its Domain (for example example.com), a Name and a Timezone. Adding sites is available to workspace owners and admins.

2. Paste the snippet into the head of every page

Copy your site's snippet from Settings → General. It looks like this:

<script
  defer
  data-website-id="YOUR_WEBSITE_ID"
  data-domain="example.com"
  src="https://data.whos1.bid/script.js"
></script>

Put it inside the <head> of every page. In a framework, add it once to the root layout — for example Next.js app/layout.tsx or the index.html of a Vite or React app.

PlatformWhere to paste it
Plain HTML or any frameworkBefore </head> on every page, or once in the root layout.
ShopifyOnline Store → Themes → Edit code, open theme.liquid, and paste before </head>.
WordPressUse a plugin such as "Insert Headers and Footers", or your theme's custom-code field, and paste it into the head.

Both data-website-id and data-domain are required. The script sends nothing if either is missing. Events are only accepted from your site's domain (and its subdomains) and any additional domains you allow in Settings → General.

Single-page apps work out of the box

Route changes made with the History API (pushState and the back/forward buttons) are tracked as pageviews automatically. For older routers that only change the #/hash, add data-hash-based-routing="true".

3. Check it's working

  • Open your site in another tab. The green online counter in the dashboard header should go up within a few seconds.
  • Use Verify installation in Settings → General (a banner offering the same check also appears on the dashboard while the site has no visitors). Trace loads your live site at https://example.com (then https://www.example.com), checks that the script is on the page and running, and sends a test event. The test isn't counted as a visitor.
  • Add data-debug="true" to the script tag to have the script log what it does (and why an event was rejected) in the browser console.

If verification fails, the banner tells you why and offers Check again and Try another URL:

ProblemWhat to do
We couldn't detect the tracking script on your siteMake sure the snippet is in the <head> of the page that was checked, and that the change is deployed.
Your snippet is configured for a different siteCopy the snippet again from Settings → General — the website ID doesn't match.
Your site's Content Security Policy (CSP) is blocking the trackerAdd https://data.whos1.bid to your CSP's script-src and connect-src.
We detected an issue with your site's cacheClear your site's or CDN's cache so the updated HTML is served.
We couldn't reach the URLCheck that the URL is correct and publicly accessible, and that no firewall, login or CDN rule blocks it. Use Try another URL for a different page.
We couldn't verify your proxied installationIf you serve the script through your own domain, check that your proxy forwards /api/collect.

Local development is ignored

Tracking is off on localhost, 127.0.0.1, *.local and *.localhost hostnames, and on pages opened from file://, so your own testing never pollutes real data. To test the install locally, add:

<script
  defer
  data-website-id="YOUR_WEBSITE_ID"
  data-domain="example.com"
  data-allow-localhost="true"
  src="https://data.whos1.bid/script.js"
></script>

Use data-allow-file-protocol="true" for pages opened from file://.

Calling Trace before the script loads

The script is loaded with defer, so code that runs earlier can't call it yet. Add this stub before your own code and any calls are queued, then sent once the script is ready:

<script>
  window.datafast = window.datafast || function () {
    (window.datafast.q = window.datafast.q || []).push(arguments);
  };
</script>

Excluding your own visits

To stop recording visits from your own browser, open the browser console on your site and run:

localStorage.setItem("df_ignore", "true");

Events from that browser are then ignored on that site. Remove the item to be tracked again. To exclude whole IP addresses or countries for everyone, use Settings → Exclusions.

Good to know

  • The script does nothing inside an iframe, so a page embedded in another page doesn't double-count.
  • The same URL viewed again within one minute in the same tab isn't counted as a second pageview.
  • Headless and automated browsers (WebDriver, Puppeteer, Playwright and similar) are ignored by the script before anything is sent.

Next steps

On this page