AddThisFeature

Attribution Capture

Remember how someone arrived so a signup can be traced back to what brought them.

moderate Growth

What it adds

Durable capture of campaign parameters and referrer at first contact, carried through the signup journey and attached to the resulting account.

What your agent is told to do

5
  1. 1

    Capture campaign parameters and the referring document on the very first request of a visit, before any redirect, consent gate, or login bounce can strip them.

  2. 2

    Store the captured values server-side against the visitor, then remove them from the URL. Do not thread the tags through every subsequent link — a campaign tag in a shared URL misattributes everyone who clicks it.

  3. 3

    Keep both first touch and last touch as separate fields, and state which one the app reports on. Do not overwrite first touch, ever.

  4. 4

    Validate against an allowlist of parameter names and cap each value's length. Anything unrecognised is discarded, not stored.

  5. 5

    Attach the stored attribution to the account at creation and to the first purchase, then leave those records immutable.

Edge cases it handles

7
  • Attribution must expire. Define a window — 30 or 90 days — after which a stale first touch stops being credited, or every customer is attributed to a campaign from a year ago.
  • Campaign parameters must never reach application logs, error reports, or analytics payloads unfiltered — they routinely carry email addresses and personal identifiers.
  • Never append captured tags to an outbound or external return URL. That leaks internal campaign structure to third parties.
  • Direct traffic with no referrer is a real category. Record it as direct rather than leaving the field null and guessing later.
  • Self-referrals from the app's own domain are not acquisition. Exclude the app's own hosts from the referrer.
  • If capture requires consent under the visitor's jurisdiction, record nothing until consent is given — an unattributed signup is better than an unlawful one.
  • Cross-device or cross-domain stitching needs an explicit consent basis and a stated identity rule. Do not silently join visitors by IP.

Definition of done

9
  • Source data is captured before any redirect or account creation can lose it.
  • First touch and last touch are stored separately and first touch is never overwritten.
  • Only allowlisted parameters within a length cap are stored; the rest are discarded.
  • Captured parameters are scrubbed from URLs, logs, and outbound links.
  • Attribution expires after a stated window rather than being credited indefinitely.
  • Direct and self-referred traffic are classified explicitly, not left null.
  • Attribution is written onto the account at signup and does not change afterwards.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.