How referrals are tracked
Sprout Affiliate credits an order to an affiliate using two kinds of evidence: the affiliate's link (captured in the shopper's browser when they land on your store) and the affiliate's discount code (read off the order itself). This page explains how each one works, which wins when they disagree, and where tracking genuinely does not reach.
The Web Pixel and the theme app embed
The Web Pixel. A Web Pixel is a small script Shopify runs on your storefront and on checkout, walled off from your theme so it can read the page address and the purchase event but cannot change the page. Sprout Affiliate installs one automatically every time the app loads.
It watches for a ?ref= value on any page a shopper lands on, stores it along with the time of the click in the shopper's browser storage for your store, the same place the theme app embed keeps its copy, and when checkout completes it reports the referral and the order to Sprout Affiliate. If the pixel is missing, the app Home page shows a red "Referral tracking is off" banner with a "Turn it on" button that installs it. If you see that banner, clicks on affiliate links are not being credited, so fix it before anything else.
The theme app embed. In your theme editor, under App embeds, there is a block called "Sprout referral tracking". It does two things the pixel cannot.
It writes the referral onto the cart as an order attribute named Sprout Ref, so the referral lands on the order in your Shopify admin and stays there as evidence. And it reports the pages the referred visitor viewed, which is what powers Tracked clicks and the "Pages they visited" list on a referral.
It also renders the optional storefront widgets (the message bar, popup, and floating pill). Discount code attribution works whether or not this embed is on. Sprout Affiliate prompts you to turn the embed on only once a program has one of the storefront widgets switched on. If you want the embed for the cart attribute and page journeys alone, nothing prompts you, so check it yourself in the theme editor.
What is recorded on a click
A "click" is not a row in a click counter. It is an identity: the affiliate's link name plus the timestamp of the click, stored in the shopper's browser. The page rows, the Sprout Ref value written on the cart, and the check for whether a visit became an order are all keyed by that same pair.
The theme embed then reports one row per page the visitor sees, holding the path, the page title, and the external site they came from when there is one (internal navigation is never recorded as a source).
Those rows never contain an IP address, a user agent string (the line a browser sends naming itself and the device), a cookie (a small value a site stores in the browser and reads back on later visits) or a customer id, and they are deleted 120 days after they are written. Visitors who did not arrive through an affiliate link are never recorded at all.
A single visit is capped at 200 recorded pages, and the same page is not recorded twice for the same visit, so refreshes and pagination do not inflate anything. Tracked clicks and page journeys are shown on the Growth plan and above. Page rows are still collected on Free, so upgrading shows you the history that is still inside the 120-day retention window rather than starting from zero.
How an order gets credited
When an order is matched, Sprout looks for evidence in this order.
| Order | Evidence | Shown as |
|---|---|---|
| 1 | A discount code on the order that belongs to an affiliate (their main code or any extra code you assigned). Matching ignores upper and lower case. | code |
| 2 | The Sprout Ref cart attribute written by the theme embed, if the click is still inside the attribution window (the number of days after a click during which a purchase still counts, set per program). | link |
| 3 | The Web Pixel's report for that order id, used when there is no cart attribute, when the attribute names nobody active, or when the attribute's click has expired. | pixel |
The discount code wins if both exist, unless you turn on anti-leak discount protection, described further down this page. The affiliate must be active when the order is matched, and every attributed order still passes through your auto-approval settings (which you can set for the whole shop, one program or one affiliate) before it is approved and paid.
Attribution is recalculated from the last 59 days of your orders each time the app reads them, so assigning an extra code to an affiliate can credit unpaid orders placed before you assigned it. An order that has already earned a commission stays in your lists until it is paid or rejected, even after it ages out of that window. Orders already paid are never re-attributed.
The attribution window
Each program has a Cookie duration (days) setting on the program page, accepting 1 to 365 days, with a store-wide fallback of 30 days used when a program does not set its own. There is no store-level control for this in the app, so set it per program. Ticking Infinite cookie duration stores it as zero, which means the click never expires.
The window is enforced in three places against the same stored click time: in the browser (the theme embed drops the stored referral once it is older than your window), on the server when the pixel reports a completed checkout, and again when Sprout matches orders to affiliates, comparing the click time against the order's own creation time.
Changing the window changes how not-yet-paid orders inside that 59-day recalculation range are judged the next time they are matched. Lengthening it credits clicks that had just aged out; shortening it takes credit away from orders whose click now falls outside. What it cannot do is bring back evidence that is already gone: a referral the browser has dropped is gone, and a pixel report refused as expired is never retried.
Clicking the same link again does not restart the cart attribute's clock, so one visitor's journey stays as one visit. Clicking a different affiliate's link stores a new link name and a new click time, which starts a fresh window and a fresh visit.
When a customer clicks two different affiliates' links
Last click wins. The newest ?ref= replaces whatever was stored, in both the pixel and the theme embed, and the cart attribute is rewritten to match on that same page load. There is no first click preference and no splitting of commission.
Two safeguards apply after that. If the pixel reports one affiliate at checkout while the order already carries a Sprout Ref naming a different one, the report is refused and the cart evidence stands. And once a referral has been recorded for one affiliate, a later report naming somebody else is ignored, so an order cannot be quietly moved from one affiliate to another after the fact.
Code tracking compared with link tracking
Code tracking needs nothing in the browser. The code is on the order, so it works across devices, in private windows, past any window length, and even if the shopper never touched the affiliate's link. Its weakness is that codes leak: they get posted to coupon sites and used by people the affiliate never sent.
Link tracking is the opposite. It proves the visitor actually arrived through that affiliate, but it lives in the storage of the one browser that clicked, so a move to another device, a private window, a content blocker or a cleared browser store all lose it. "What is not tracked" below lists each case. A program that offers a discount can combine the two: set "How customers get it" to "Auto-applied by the affiliate's link", and the shared URL runs through Shopify's /discount/CODE route and redirects to the store with ?ref= attached, so one link applies the code and leaves link evidence.
Anti-leak discount protection
Anti-leak is a Professional plan setting, found under Settings, Fraud detection, labelled "Anti-leak discount protection". With it on, a discount code alone does not earn commission. The buyer has to have arrived through the affiliate's link. If the click evidence names a different affiliate from the code, the click is trusted and that affiliate is paid. If there is no click evidence at all, the order pays nobody.
Two consequences follow. Attribution reads the anti-leak switch as you saved it rather than re-checking your plan, so a plan change does not silently change how orders are judged, and the rule keeps applying until you switch it off. And because anti-leak can leave real orders uncredited, expect a drop in attributed orders on the day you turn it on. That drop is the feature working.
What lands on the order itself
When an order comes in attributed, Sprout tags it in Shopify. The default tag is Sprout_order, plus the affiliate's name as a second tag. Both are under Settings, Links & coupons, in the Order tags card: "Tag on every referred order" is a text field you can rename or leave blank for no tag, and "Also tag with the affiliate's name" is a checkbox you can turn off. An order that is only attributed later, through the pixel's report, may not carry the tag, because tagging happens when the order arrives.
Test orders are attributed like any other order, which is how you check tracking before you go live, but they are held with the reason "Test order" instead of being approved automatically, and they never accrue the transaction fee your plan charges on referral sales (2% on Growth, 1.5% on Professional, 1% on Enterprise; Free has none).
Plan limits that affect tracking
On Free, the first 200 referral orders in a calendar month are attributed. Anything above that earns no commission and is not paid. The Payouts page shows a warning banner counting how many referrals went over the limit. Every paid tier is uncapped. Tracked clicks, time on store, and click-to-order conversion require the Growth plan or above.
What is not tracked
- Cross-device and cross-browser journeys. The referral is stored in the browser that clicked. Click on a phone and buy on a laptop, and there is no link evidence. Only a discount code survives that jump.
- A referrer the sending site strips. The "came from" source is read from the referrer, the address of the page the visitor was on when they clicked, which their browser passes to your store. Plenty of apps and sites send nothing, so the visit shows as direct. A missing referrer affects reporting only, never who gets paid.
- Anything a blocker or cleared storage removes. Content blockers, private windows and storage clearing all lose the stored referral. Nothing on our side can recover it.
- Page journeys without the theme embed. If the app embed is off, attribution still works through the pixel and through codes, but Tracked clicks and page journeys stay empty.
- Visits for a paused affiliate. Page views are only recorded for an active affiliate. Pause someone and their visits stop being recorded, though a referral for them can still be recorded as evidence.
- Conversions on the Tracked clicks page without a cart attribute. A visit is only marked as turning into an order when the order carries the matching
Sprout Refvalue. An order credited through the pixel alone still pays the affiliate, but the visit shows as "No order" in click analytics.
Checking that it works
Place a test order through an affiliate link, then open that order in Sprout. The header reads "Referred by" the affiliate, followed by "via code", "via link", or "via pixel", so you can see which evidence was used. The order in your Shopify admin should carry the Sprout Ref attribute if the theme embed is on. If nothing appears, check the tracking banner on Home first, then the app embed in your theme editor, then whether the click is older than your program's cookie duration.