Deanonymizing website traffic.
How B2B website traffic deanonymization works, how much of it actually resolves, what GDPR and CCPA require in 2026, and where the honest limits are.
Deanonymizing website traffic means attaching an identity — a company, or a named individual — to a session that arrived without one. In B2B it is done by reverse IP lookup, by identity-graph matching through a pixel, or by recognising someone already in your database. None names everybody, and honest coverage figures sit well below headline ones.
Last verified: 2026-07-29. Every price, coverage figure and legal citation below was checked against a live vendor page or a regulator's own publication on that date, with the URL inline.
One clarification before anything else, because this word carries two unrelated meanings. If you arrived looking for re-identification of individuals inside a published anonymised dataset — the privacy-research sense, the one that appears in academic papers about supposedly anonymous medical or mobility data — this is not that page. This page is about the B2B marketing practice: putting a company or a person's name on your own website traffic. Same word, different field.
I'm Dag, co-founder of ContactLevel. We sell in this category and we deliberately do not sell anonymous visitor deanonymization, so read this knowing I'll be pointing you at other vendors for the part we don't do.
What "deanonymize website traffic" actually means.
An anonymous session is one where your systems have a device and some behaviour but no identity. Someone read three pages including pricing, spent four minutes, left. You have a row in analytics and nothing to act on.
Deanonymization closes that gap by resolving the session to one of two entities:
→ An account. "Someone at Acme Corp read your pricing page." Useful for account-based programmes, useless for knowing who to call.
→ A person. "Sarah Chen, VP Engineering at Acme, read your pricing page." Actionable, harder, more legally constrained, and available in far fewer places than the marketing suggests.
The same practice trades under several names — website visitor identification, visitor deanonymization, reverse IP lookup, anonymous visitor tracking. They are not perfect synonyms (reverse IP is one mechanism, not the whole category) but in vendor copy they are used interchangeably. When you compare tools, ignore the label and ask what entity comes out the other end.
How does website traffic deanonymization work?
Three mechanisms. Most products combine at least two and describe the combination as one number.
1. Reverse IP lookup — company-level, global.
The visitor's browser sends an IP address. The tool matches it against a registry of IP ranges assigned to organisations and returns the company.
It works everywhere and it is cheap. It also fails in a specific, predictable way, and HubSpot documents the failure better than most vendors document their successes: "Smaller companies and individuals may not have their own IP addresses. In those cases, the prospect will appear as the internet service provider (e.g., Comcast, Cox, Verizon)" (HubSpot Knowledge Base).
So reverse IP resolves your enterprise traffic and loses your mid-market traffic, and it loses anyone working from home regardless of how big their employer is. IP targeting for B2B goes through why remote work broke this mechanic more than any privacy regulation did.
Reverse IP is also the mechanism sitting inside most of the platforms a B2B team already pays for, which is why "can our existing stack do this?" almost always resolves to the company rather than the person. The per-vendor verdicts, quoting each vendor's own documentation, are on can 6sense identify anonymous website visitors?, can Demandbase identify anonymous website visitors?, can Marketo identify anonymous website visitors? and can ZoomInfo identify anonymous website visitors?.
2. Identity-graph matching — person-level, effectively US-only.
A script on your site collects browser, device and cookie signals and sends them to a provider that holds a large graph of known profiles. When the signals match a profile with enough confidence, the provider returns a name, and often a business email and LinkedIn URL.
This is the mechanism behind every "see who visits your site without a form fill" product. It is also the mechanism that runs straight into EU law, which is why it is sold as a US product almost everywhere.
3. Matching against people you already hold — first-party, no cold resolution.
The quietest of the three. If a visitor is already in your CRM or in one of your ad audiences, recognising them on a return visit is a first-party operation: the graph is used to tie a device back to a person you already hold, not to buy a name for a stranger who has never been in one of your lists. No cold resolution, and nothing to resolve if the person was never yours to begin with.
This is what ContactLevel does, and it is a narrower claim than the other two. It is also why we cannot sell you the anonymous half — a stranger who has never been in one of your audiences stays a stranger to us.
Person-level vs company-level: which one are you actually buying?
| Company-level | Person-level | |
|---|---|---|
| Output | Organisation name and firmographics | Name, title, often business email and LinkedIn URL |
| Mechanism | Reverse IP lookup | Identity-graph match via a site script |
| Sold in | Globally | Effectively US-only from the major vendors |
| Coverage published | Rarely published as a percentage | RB2B: 15-20% (Starter/Pro), 35-45% (Pro+) |
| Fails on | Remote workers, VPNs, leased ISP ranges, small firms | Anyone not in the graph; all non-US traffic |
| Sales use | Account alerts, target-list prioritisation | Named follow-up, buying-group mapping |
| Ads use | Account-based targeting, still needs contacts to run person-level ads | Direct — but only after enrichment maps work identity to ad identifiers |
| EU exposure | Lower, but the script still engages ePrivacy Art. 5(3) | Higher — you are identifying an individual |
| Price floor (Jul 2026) | €0-79/month (Leadfeeder) | $79-999/month (RB2B, Vector) |
The distinction that matters commercially: company-level tells you an account is in market, person-level tells you which human to talk to. If your motion is a five-person buying committee at a named account, company-level gets you halfway and stops.
How much traffic can you actually deanonymize?
This is where the category's credibility problem lives, and the cleanest way to show it is with one vendor's own two pages.
RB2B's homepage says: "Identify 70-80% of your web traffic - both people and companies!"
RB2B's pricing page, on the same day, sells contact-level site ID (US only) from the $79 Starter tier at 15-20% coverage, holding at 15-20% on Pro and rising to 35-45% on Pro+. The Free tier carries no contact-level line at all; the 15-20% printed against it is the company-level figure (rb2b.com/pricing, checked 2026-07-29).
Neither figure is dishonest. They count different things. The 70-80% includes sessions where only the company resolved. The 15-45% is the share where a person was named. If your reason for buying is names, the second number is the one that determines whether the product works for you. RB2B is not alone in this, and the match-rate arithmetic reconciles the headline-versus-footnote gap for four vendors using nothing but their own published pages.
Here is what the market publishes, as of 2026-07-29, with nothing filled in where a vendor stays silent:
| Vendor | Entity resolved | Coverage the vendor publishes | Geography stated | Published price |
|---|---|---|---|---|
| RB2B | People + companies | Contact-level 15-20% (Starter/Pro), 35-45% (Pro+); company-level 15-20% (Free/Starter/Pro), 35-45% (Pro+) | Person-level US only, and not on the Free tier | $0 / $79 / from $149 / from $199 per month |
| Datamoon | People | "Up to 70%" | "We only identify visitors in the US" | Not published |
| Vector | People | Not published | Not stated | Reveal $399-999/mo; Target $3,000-4,000/mo |
| Warmly | People + companies | Not published | Not stated | From $10,000/yr or $4,875/quarter |
| Leadfeeder / Dealfront | Companies | Not published | Global, strongest in Europe | €0 / €79 / €369 / €599 per month, billed annually |
| 6sense | Companies — "even if the individual visitors remain anonymous" | Not published | Global | Not published |
| HubSpot prospects | Companies via IP | Not published | Global | Bundled with HubSpot |
Two things that table does not show and that you should factor in anyway:
- Your traffic mix drives the result more than the vendor does. A US-heavy B2B site on corporate networks resolves far better than an international or consumer-mixed one. The vendor's benchmark is not your benchmark.
- Coverage is per session. A 20% session rate still names a meaningful share of your repeat visitors over a quarter, because serious buyers come back. Evaluate after 90 days, not after a fortnight.
And a note on Dealfront: its pricing URL now 301-redirects to Leadfeeder's, so treat them as one product line rather than two independent options on your shortlist. The direction of that rename is the opposite of what most comparison content says, and both Leadfeeder alternatives and Dealfront alternatives walk through what it means for an existing contract.
Two vendors sit just outside that table and get asked about often enough to name. Factors.ai resolves accounts globally and contacts in the US through an RB2B integration, but its centre of gravity is attribution rather than identification. AudienceLab is a US consumer identity graph sold to advertisers — broad, US-only, and a different instrument from anything else on this page, which is worth knowing before you compare its coverage figure to a B2B tool's.
Is deanonymizing website traffic legal under GDPR?
Regulated, not banned — and the important structural point is that two separate rules apply, in sequence. Most vendor FAQs collapse them into one and answer the easier one.
Rule one: the script. Before anyone asks whether naming the visitor is lawful, there is the question of putting code on their device. The EDPB adopted the final version of Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive in October 2024, and the guidance explicitly extends beyond cookies to pixel tracking, URL tracking, IP-based tracking and unique identifiers. If a technique stores information on, or gains access to information stored in, a visitor's terminal equipment, Article 5(3) is engaged — which in practice means consent, obtained before the script fires.
Rule two: the identity. Then GDPR applies to what you do with the result. Recital 30 of the GDPR is direct about the raw material here: online identifiers including internet protocol addresses and cookie identifiers "may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them" (EUR-Lex, Regulation 2016/679). Article 4(1) defines personal data as any information relating to an identified or identifiable natural person. So an IP address plus behaviour plus a graph lookup is squarely inside scope, and you need a lawful basis, a transparency notice, and an answer on retention.
What the market did about it. The clearest evidence of how hard rule one bites is that the vendors themselves ring-fence. RB2B states its person-level identity is "a US-only technology with a US-only database." Datamoon states "We only identify visitors in the US." Neither is being cautious for sport — that is the commercial shape the rules produce. In Europe the sellable product is company-level identification, which is why Leadfeeder and Dealfront are the names you hear there.
Practical position, not legal advice. If you run EU traffic and want any form of visitor identification, the questions your counsel will ask are: does the script fire before consent, what is your lawful basis for the identification itself, can you produce a consent record with a timestamp and a capture location, how long do you retain the resolved identity, and what happens on an erasure request. Have answers before you install anything. I'm a marketer, not a lawyer, and this page is not a substitute for one.
What changed in California for 2026?
Three things worth knowing if any of your traffic is Californian.
Amended CCPA regulations took effect 2026-01-01. The CPPA Board adopted them on 2025-07-24 and the Office of Administrative Law approved and filed them on 2025-09-22, covering risk assessments, cybersecurity audits and automated decisionmaking technology on a phased compliance timeline (CPPA).
The Global Privacy Control is not optional. The California Attorney General states that GPC "must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information" (oag.ca.gov). If your identification vendor ignores browser opt-out signals, that is your exposure, not theirs.
Enforcement is live and it reaches this exact category. In September 2025 the CPPA ordered Tractor Supply to pay $1,350,000, with the findings including failing to provide consumers an effective mechanism to opt out of the selling and sharing of personal information (CPPA, 2025-09-30). In December 2025 it fined ROR Partners $56,600 for selling custom audience lists without registering as a data broker, with the agency stating: "A sale is a sale. A business cannot bypass the CCPA's and the Delete Act's requirements by selling personal information as part of a larger suite of products and services it offers" (CPPA, 2025-12-03).
That second one is the relevant precedent for anyone buying in this space. Building audiences out of resolved identities is not a side feature that escapes the rules because it sits inside a bigger platform.
What ContactLevel does and does not deanonymize.
Stated plainly, because the alternative is a disappointed customer in month two:
We do not deanonymize cold, anonymous, net-new website traffic. There is no ContactLevel pixel that puts a name on a stranger. If someone who has never been in one of your audiences lands on your site, we do not identify them and we will not pretend otherwise on a call.
What we do identify is the person who is already in one of your ContactLevel audiences — synced from your CRM, uploaded, or built in-platform. When that person clicks an ad or returns to your site, we attribute the click and the visit to them by name. That is a first-party operation on people you already have a relationship with, and it is a narrower claim than the identity-graph vendors make.
What we don't report is per-person ad impressions. Person-level impression tracking is on the roadmap; it is not in the product today, and we are not publishing a date for it. What we track today is the dated statement of record, and it wins any disagreement with a marketing page.
The number we do publish is a match rate of 70-99% — and it measures something completely different from the coverage figures in the table above. It is the share of a contact list that successfully matches to real accounts when you sync it to LinkedIn, Meta, Google, Reddit or X. Setting it next to RB2B's 15-45% would be comparing two unrelated things, which is exactly the trick B2B match rates exists to disarm.
How do you pair deanonymization with activation?
Here is the part that gets skipped, and it is the reason this page exists rather than a page trying to sell you visitor ID.
Deanonymization ends with a name in Slack. Then what?
Sales follows up on the best ones. That workflow is real and it works — until volume exceeds capacity. If your site names 400 people a month and your team can chase 40, the remaining 360 are a report, not a pipeline.
The other 360 are an advertising audience. They have already shown intent on your site. Keeping them warm with ads across LinkedIn, Meta, Google, Reddit and X costs a fraction of a rep's attention and does not decay when someone goes on holiday.
The obstacle is identifiers. The email a deanonymization tool hands you is a work email. Nobody signs up to Meta with their work email, and few sign up to Google or Reddit with one either. Upload that list raw and most of it will not match. This is the single most repeated explanation I give on sales calls, and it is the whole mechanic behind contact-level data enrichment: map the business identity to the personal identifiers ad platforms actually match on, which is how a list moves into the 70-99% range instead of the 20-50% a raw CSV upload returns.
So the stack that works looks like this:
- Identify. RB2B, Dealfront or Datamoon resolves the anonymous session. Company-level in Europe, person-level in the US.
- Route the top slice. High-intent, target account, named person → sales, same day.
- Enrich everyone. Push the identified contacts into a ContactLevel audience so each business identity gains the personal identifiers ad platforms need.
- Activate. Sync the audience to LinkedIn, Meta, Google, Reddit and X and keep reaching those people while the account matures.
- Measure the click. Person-level click and site-visit attribution comes back. Per-person impressions do not — see above.
At least one ContactLevel customer runs precisely this, with the RB2B pixel as the upstream feed. It is a pattern we recommend, not a compromise we tolerate. RB2B alternatives walks through the mechanics of moving RB2B's output into ad audiences, and is mostly a page about pairing rather than replacement.
What to ask a vendor before you buy.
Six questions. The good ones answer all six by pointing at their own published pages.
- "Is your coverage figure people or companies, and where does it say so on your site?" If the answer is a number without an entity, it is a marketing number.
- "What is the coverage on the tier I'd actually buy — and is the feature even on that tier?" Both vary by plan. RB2B publishes 15-20% company-level coverage on its bottom three tiers and 35-45% on the top one, and it does not sell contact-level ID on the Free plan at all.
- "Which countries do you resolve people in?" Expect "the US". Anything broader deserves a follow-up about lawful basis.
- "Does your script fire before consent in the EU?" Article 5(3) attaches to the script, not to the outcome.
- "Can you produce a consent record with a timestamp and capture location?" This is the question a vendor security review will ask you, so ask it upstream first.
- "What can I do with the output besides read it?" If the answer is "Slack, CRM and CSV", you have bought identification and you still need activation.
Run the same six at us. Our answers: we resolve people already in your audiences rather than anonymous traffic; coverage is not the right metric for what we do and 70-99% is a list-to-platform match rate; identification is strongest in the US; we can produce consent records with timestamp and capture location; and activation is the entire product.
Where to go next.
→ Who is visiting my website? — the shorter, plainer answer, including what Google Analytics and HubSpot can and cannot tell you.
→ RB2B alternatives — RB2B's own published numbers, the genuine replacements, and how to activate its output instead of replacing it.
→ B2B match rates — the three different things called "match rate", and why comparing them across vendors is the most common mistake in this category.
→ What we track today — the dated, versioned statement of what ContactLevel measures in production, including what it does not.
→ Contact-level website visitor identification — what our narrower version of visitor identification is, and who it is not for.
→ IP targeting for B2B — why reverse-IP resolution degrades, and what remote work did to it.
→ Pricing — published plans and what each includes.