How referrals are tracked
Sprout Affiliate credits an order to an affiliate using two kinds of evidence: the affiliate's link (captured in the shopper's browser when they land on your store) and the affiliate's discount code (read off the order itself). This page explains how each one works, which wins when they disagree, and where tracking genuinely does not reach.
The Web Pixel and the theme app embed
The Web Pixel. A Web Pixel is a small script Shopify runs on your storefront and on checkout, walled off from your theme so it can read the page address and the purchase event but cannot change the page. Sprout Affiliate installs one automatically every time the app loads.
It watches for a ?ref= value on any page a shopper lands on, stores it along with the time of the click in the shopper's browser storage for your store, the same place the theme app embed keeps its copy, and when checkout completes it reports the referral and the order to Sprout Affiliate. If the pixel is missing, the app Home page shows a red "Referral tracking is off" banner with a "Turn it on" button that installs it. If you see that banner, clicks on affiliate links are not being credited, so fix it before anything else.
The theme app embed. In your theme editor, under App embeds, there is a block called "Sprout Affiliate tracking". It does two things the pixel cannot.
It writes the referral onto the cart as an order attribute named Sprout Ref, so the referral lands on the order in your Shopify admin and stays there as evidence. And it reports the pages the referred visitor viewed, which is what powers Tracked clicks and the "Pages the visitor viewed" list on a referral.
It also renders the optional storefront widgets (the message bar, popup, and floating pill). Discount code attribution works whether or not this embed is on. Sprout Affiliate prompts you to turn the embed on only once a program has one of the storefront widgets switched on. If you want the embed for the cart attribute and page journeys alone, nothing prompts you, so check it yourself in the theme editor.
What is recorded on a click
A "click" is not a row in a click counter. It is an identity: the affiliate's link name plus the timestamp of the click, stored in the shopper's browser. The page rows, the Sprout Ref value written on the cart, and the check for whether a visit became an order are all keyed by that same pair.
The theme embed then reports one row per page the visitor sees, holding the path, the page title, and the external site they came from when there is one (internal navigation is never recorded as a source).
Those rows also hold the IP address the visit came from, which is used only by the self-referral check described in Fraud protection and is never shown in the app. They never contain a user agent string (the line a browser sends naming itself and the device), a cookie (a small value a site stores in the browser and reads back on later visits) or a customer id, and they are deleted 120 days after they are written. Visitors who did not arrive through an affiliate link are never recorded at all.
A single visit is capped at 200 recorded pages, and the same page is not recorded twice for the same visit, so refreshes and pagination do not inflate anything. Tracked clicks and page journeys are shown on the Growth plan and above. Page rows are still collected on Free, so upgrading shows you the history that is still inside the 120-day retention window rather than starting from zero.
How an order gets credited
When an order is matched, Sprout looks for evidence in this order.
| Order | Evidence | Shown as |
|---|---|---|
| 1 | A discount code on the order that belongs to an affiliate (their main code or any extra code you assigned). Matching ignores upper and lower case. | code |
| 2 | The Sprout Ref cart attribute written by the theme embed, if the click is still inside the attribution window (the number of days after a click during which a purchase still counts, set per program). | link |
| 3 | The Web Pixel's report for that order id, used when there is no cart attribute, when the attribute names nobody active, or when the attribute's click has expired. | pixel |
The discount code wins if both exist, unless you turn on anti-leak discount protection, described further down this page. The affiliate must be active when the order is matched, and every attributed order still passes through your auto-approval settings (which you can set for the whole shop, one program or one affiliate) before it is approved and paid.
Attribution is recalculated from the last 59 days of your orders each time the app reads them, so assigning an extra code to an affiliate can credit unpaid orders placed before you assigned it. An order that has already earned a commission stays in your lists until it is paid or rejected, even after it ages out of that window. Orders already paid are never re-attributed.
The attribution window
Each program has a Cookie duration setting on the program page, in days (1 to 365) or in hours (1 to 8,760). Choose Hours beside the field for a window shorter than a day, such as 12 hours. A program that does not set its own uses the store's, under Settings, Links, in the Affiliate links card (30 days unless you change it). Ticking Infinite cookie duration stores it as zero, which means the click never expires. The program's signup page states the window the way you set it, for example "Cookie days: 12 hours".
The window is enforced in three places against the same stored click time: in the browser (the theme embed drops the stored referral once it is older than your window), on the server when the pixel reports a completed checkout, and again when Sprout matches orders to affiliates, comparing the click time against the order's own creation time. A window in hours is enforced the same way in all three, and first click uses it too.
Changing the window changes how not-yet-paid orders inside that 59-day recalculation range are judged the next time they are matched. Lengthening it credits clicks that had just aged out; shortening it takes credit away from orders whose click now falls outside. What it cannot do is bring back evidence that is already gone: a referral the browser has dropped is gone, and a pixel report refused as expired is never retried.
Clicking the same link again does not restart the cart attribute's clock, so one visitor's journey stays as one visit. What clicking a different affiliate's link does depends on the setting in the next section.
Stop tracking after a purchase
By default a click keeps crediting the affiliate for the whole window: a customer who clicks a link and buys three times in a month earns the affiliate commission on all three orders. A program can change that with Stop tracking after a purchase on the program page. It is off unless you turn it on.
With it on, the first order credited through a click on the affiliate's link uses that click up. The customer's next order earns commission only after a new click on the affiliate's link, which starts a new window. Two things clear the used click: the Web Pixel removes it from the browser when the checkout completes, and the theme embed removes it on the next page view if the store's records show it was already used. The server checks too: an order that still carries a used click (an older theme embed, or a browser that kept it) is not credited through that click by the payout engine, the order email, or the pixel's report.
An order paid through the affiliate's own discount code, on a cart that carries their click, uses that click up too, so the order after it needs a new click on the link like any other. A code that belongs to a different affiliate leaves the click alone.
Shopify records the page a visit landed on with every order placed in that visit, which is how an express checkout (Shop Pay, Apple Pay, or Google Pay straight from a product page, which skips the cart) is still credited to the link. A second order in the same visit is not credited through a click the first one already used. The click is matched by the page it landed on and the shopper's address, which needs the theme app embed; on a store with only the Web Pixel, a second order placed in the same visit can still be credited through the landing page.
The setting decides only the link. A discount code on the order still pays its affiliate. A customer connected to an affiliate through lifetime commission stays connected, and later orders still pay through that connection. With anti-leak discount protection on, a code needs a live click, so an order that carries only a used click and a code pays nobody, as anti-leak does for any order without a click.
Turning the setting on never takes an order away: orders Sprout Affiliate had already credited keep their commission, and the rule applies to orders that come in after that. On an order the rule refused, the order page says "the link click already earned on an earlier order".
When a customer clicks two different affiliates' links
You choose, under Settings, Links, in the Affiliate links card: Who gets the sale when a customer clicks more than one affiliate's link. It is on every plan. One affiliate is paid, unless their program splits the commission between every affiliate the customer clicked (Professional, Split commission by clicks).
- Last click (the default). The newest affiliate link replaces whatever was stored, with a new click time that starts a fresh window, and the cart attribute is rewritten to match on that same page load.
- First click. The first affiliate whose link the customer clicked keeps the sale for as long as that click is inside its attribution window. A later click on another affiliate's link does not take it over and is not remembered. Once the first click's window has run out, the next click the customer makes holds the sale the same way.
An example with a 30-day window: a customer clicks Ana's link on the 1st and Ben's link on the 10th, then buys on the 15th. Under last click Ben is paid; under first click Ana is. If the customer instead clicked Ana's link on the 1st, Ben's on the 10th, and Cai's on the 2nd of the next month, under first click Cai is paid: Ana's window ran out on the 31st, Ben's click came while Ana's still held the sale, and Cai's was the next click after it ran out. A link that names nobody you can pay (a mistyped name, or an affiliate you paused) never holds the sale.
Every way a link reaches an order follows the setting: the Sprout Ref cart attribute, the Web Pixel's report at checkout, and the landing page Shopify records for an express checkout (Shop Pay, Apple Pay, and Google Pay buttons that skip the cart). For an express checkout under first click, the theme embed records when a link lost the sale to an earlier click, and the order is credited to the earlier click; when nothing recorded that (no theme embed, or no address to match the visit by), the landing page's link is credited.
The theme embed learns the setting from Sprout Affiliate on each page view of a referred visit and keeps it, so a change applies to the next click after the shopper's next page view. Until the embed has heard "first click", it keeps last click, so a storefront that cannot reach Sprout Affiliate behaves the way it always did. A click on another affiliate's link that lost under first click still shows in that affiliate's Tracked clicks, as a one-page visit.
A program set to Split between every affiliate the customer clicked pays the first click, the last click, and everyone clicked in between their shares of the commission instead. The order still counts for the affiliate this setting credits, and the clicks it splits by are the ones the Web Pixel reports at checkout, inside the program's window. How the split works.
Discount codes are unchanged by the setting. A code on the order still wins over any link, unless anti-leak discount protection is on, in which case the link that holds the sale under your setting is the one paid. Lifetime commission and subscription renewals are unchanged too: a customer connected to an affiliate stays connected, and a renewal is credited to whoever referred the subscription.
Two safeguards apply after that. If the pixel reports one affiliate at checkout while the order already carries a Sprout Ref naming a different one, the report is refused and the cart evidence stands. And once a referral has been recorded for one affiliate, a later report naming somebody else is ignored, so an order cannot be quietly moved from one affiliate to another after the fact.
Tracking on your other websites
Affiliates sometimes send visitors to a page you run outside Shopify first, such as a WordPress blog post or a ClickFunnels landing page, and the visitor reaches the store from there. Shopify's own tracking does not run on those pages, so Sprout Affiliate gives you a tag to paste into them. It is under Settings, Links, at the bottom of the Affiliate links card, under Other websites:
<script src="https://app.sproutaffiliate.com/track.js?shop=your-store.myshopify.com" async></script>
Copy it with the Copy button and paste it into the page's HTML, before </body> or in the site's footer or header code setting. In WordPress, that is a theme's footer code box or a plugin for header and footer code. In ClickFunnels, it is the page's tracking code setting.
Then list the site under Websites that can use this tag (one box per site, for example blog.yourstore.com) and click Save. Visits are recorded only from the websites you list, so a copy of the tag on somebody else's site records nothing. A listed address also covers the same address with www. in front; a different subdomain needs its own box. A website named in other letters, like bücher.de or пример.рф, can be typed as it is spelled or in its xn-- form; it is shown as it is spelled either way. Until a website is listed, the tag records nothing at all.
What the tag does on a page opened through an affiliate link (?ref=, with the optional ?ref_source= channel tag):
- It keeps the click in that website's own browser storage, for the affiliate's window. It sets no cookie and loads nothing from anyone else.
- It adds the click to every link on the page that goes to your store, so the theme embed and the Web Pixel pick it up when the visitor arrives. A link that already names an affiliate is left as it is.
- It records the visit, so the page shows in the affiliate's Tracked clicks as the first page of the visit, with its full address. The store pages that follow join the same visit, so one visitor is one click, and a pay-per-click program pays for it once.
An order is then credited at the store the same way as any other link click, with the same window, first or last click setting, and stop tracking after a purchase. The tag does not credit orders itself.
Extensions for affiliates
Three extras in Settings > Integrations > Extensions for affiliates. Each is off until you turn it on.
- Postback URL. Each affiliate can add a web address in their portal. When one of the affiliate's links turns into an order, Sprout Affiliate tells that address about the order, with the click it came from, so the affiliate's own ad tracker sees which ads sell. It never sends what the affiliate earns.
- Meta pixel. Each affiliate can add their own Meta pixel ID in their portal. When a shopper arrives through that affiliate's link, the affiliate's pixel runs on your store and reports the visit, so their Facebook and Instagram ads can count the visits they bring. Turning it off stops every affiliate's pixel on the next page view.
- Chat widget. Paste the script your chat provider gives you, such as Tidio, Crisp or Intercom, and press Save. The chat then appears in your affiliates' portal, so affiliates can message you from there.
Code tracking compared with link tracking
Code tracking needs nothing in the browser. The code is on the order, so it works across devices, in private windows, past any window length, and even if the shopper never touched the affiliate's link. Its weakness is that codes leak: they get posted to coupon sites and used by people the affiliate never sent.
Link tracking is the opposite. It proves the visitor actually arrived through that affiliate, but it lives in the storage of the one browser that clicked, so a move to another device, a private window, a content blocker or a cleared browser store all lose it. "What is not tracked" below lists each case. A program that offers a discount can combine the two: set "How customers get the discount" to "Auto-applied by the affiliate's link", and the shared URL runs through Shopify's /discount/CODE route and redirects to the store with ?ref= attached, so one link applies the code and leaves link evidence.
Anti-leak discount protection
Anti-leak is on every plan, Free included, and off by default. It is under Settings, Fraud detection, labelled "Anti-leak discount protection". With it on, a discount code alone does not earn commission. The buyer has to have arrived through the affiliate's link. If the click evidence names a different affiliate from the code, the click is trusted and that affiliate is paid. If there is no click evidence at all, the order pays nobody.
Two consequences follow. The rule keeps applying until you switch it off, whatever plan you are on. And because anti-leak can leave real orders uncredited, expect a drop in attributed orders on the day you turn it on. That drop is the feature working.
What lands on the order itself
When an order comes in attributed, Sprout Affiliate tags it in Shopify. The default tag is Sprout_order, plus the affiliate's name as a second tag. Both are under Settings, Links, in the Order tags card: "Tag on every referred order" is a text field you can rename or leave blank for no tag, and "Also tag with the affiliate's name" is a checkbox you can turn off. An order that is only attributed later, through the pixel's report, may not carry the tag, because tagging happens when the order arrives. An order that matches one of the self-referral rules also gets Sprout_possible_self_referral, so you can review it before you ship. See The warning tag in Shopify.
Test orders are attributed like any other order, which is how you check tracking before you go live, but they are held with the reason "Test order" instead of being approved automatically, and they never accrue the transaction fee your plan charges on referral sales (2% on Growth, 1.5% on Professional, 1% on Enterprise; Free has none).
Plan limits that affect tracking
On Free, the first 200 referral orders in a calendar month are attributed. Anything above that earns no commission and is not paid. The Payouts page shows a warning banner counting how many referrals went over the limit. Every paid tier is uncapped. Tracked clicks, time on store, and click-to-order conversion require the Growth plan or above.
What is not tracked
- Cross-device and cross-browser journeys. The referral is stored in the browser that clicked. Click on a phone and buy on a laptop, and there is no link evidence. Only a discount code survives that jump.
- A referrer the sending site strips. The "came from" source is read from the referrer, the address of the page the visitor was on when they clicked, which their browser passes to your store. Plenty of apps and sites send nothing, so the visit shows as direct. A missing referrer affects reporting only, never who gets paid.
- Anything a blocker or cleared storage removes. Content blockers, private windows and storage clearing all lose the stored referral. Nothing on our side can recover it.
- Page journeys without the theme embed. If the app embed is off, attribution still works through the pixel and through codes, but Tracked clicks and page journeys stay empty.
- Visits for a paused affiliate. Page views are only recorded for an active affiliate. Pause someone and their visits stop being recorded, though a referral for them can still be recorded as evidence.
- Conversions on the Tracked clicks page without a cart attribute. A visit is only marked as turning into an order when the order carries the matching
Sprout Refvalue. An order credited through the pixel alone still pays the affiliate, but the visit shows as "No order" in click analytics.
Checking that it works
Place a test order through an affiliate link, then open that order in Sprout. The header reads "Referred by" the affiliate, followed by "via code", "via link", or "via pixel", so you can see which evidence was used. The order in your Shopify admin should carry the Sprout Ref attribute if the theme embed is on. If nothing appears, check the tracking banner on Home first, then the app embed in your theme editor, then whether the click is older than your program's cookie duration.