For developers
Tracking script options
Every option on the script tag: no-code events, first-party proxying, privacy signals, manual page views and domain limits.
What options does the tracking script have?
Everything is an attribute on the script tag, and everything is off unless you turn it on, so an existing install behaves exactly as it did.
data-api sends events to an address of your own. data-do-not-track="true" honours Do Not Track and Global Privacy Control. data-before-send names a function that can edit or drop anything before it is sent. data-auto-pageview="false" turns off automatic page views. data-downloads="true" records clicks on links to files. data-forms="true" records form submissions. data-outbound="off" turns off outbound-link events, which are on by default.
How do I track a click without writing JavaScript?
Put data-asuito-event on any element and a click on it, or on anything inside it, records that event. Every attribute that starts with data-asuito-event- becomes a property, with dashes turned into underscores: data-asuito-event-seat-count="5" sends seat_count.
The click is never delayed or cancelled. The event is sent with a beacon that outlives the page, so a link that navigates away still records.
data-downloads records a click on a link to a document, archive, installer or media file, sending only the file name and type, never the address or its query string. data-forms records which form was submitted by its id, name or the path it posts to. The values typed into the form are never read.
How do I stop ad blockers from blocking the script?
Ad blockers match on the address a script reports to. Point data-api at a path on your own domain and forward that path to https://asuito.com/api/px, and to a blocker the traffic is indistinguishable from your own site.
The proxy has to forward the visitor’s address in X-Forwarded-For. If it does not, every visitor appears to come from your proxy, and your visitor counts and locations collapse into one. In nginx that is proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for, alongside proxy_pass to the collector. Forward the User-Agent, Accept-Language and Sec-Fetch-Mode headers too: the collector uses them to tell people from automated traffic.
You can also host px.js yourself. Its reporting address normally comes from where it was loaded, so when you serve it from your own domain set data-api as well.
Can the script respect Do Not Track?
With data-do-not-track set to true the script does nothing at all for a visitor whose browser sends Do Not Track or Global Privacy Control. It is off by default, because by default nothing here identifies anyone, and a blanket default would quietly drop a large share of your visitors.
Anyone can opt a device out for good by setting localStorage asuito.disabled to 1 in their browser. The script only reads that flag, never writes it, and it works on every site that uses the script, which makes it the way to exclude yourself when your address changes every day.
data-before-send names a global function called with the kind of message (event, outbound, leave or vitals) and a readable copy of it. Return null to drop the message, or return the edited copy. If your function throws, the message is dropped, because a function written to remove something must not fail by sending it.
How do I count a page that is not a URL?
Set data-auto-pageview to false and no page views are sent on their own. Call spx.pageview() when a page view really happens, or spx.pageview('/checkout/step-2') to record a virtual path for a screen that has no address of its own. A page view you send by hand is never deduplicated.
How do I stop other sites using my tracking token?
Your tracking token sits in your page source, so anyone can copy it to another site. Under Settings → Data you can list the domains it may report from, and everything else is ignored. A bare domain covers it and its www; *.example.com covers every subdomain. Changes apply within half a minute.
Can I exclude a whole office network?
Exclusion rules now cover an address range such as 203.0.113.0/24 for an office or a VPN, as well as a single address or a country. A rule applies to page views, events, page speed and time on page alike. Ranges wider than /8 (IPv4) or /32 (IPv6) are refused, so a typo cannot exclude a large part of the internet.
How is paid traffic without UTM tags counted?
Google Ads and Microsoft Ads add a click id to every ad click, and many accounts never add UTM tags on top. When a visit arrives with a click id and no UTM tags of its own, it is recorded as paid traffic from that platform (google / cpc, bing / cpc, and the same for TikTok, LinkedIn and X). Your own UTM tags always win.
Only the presence of the click id is used. The id itself identifies one click of one person to the ad platform, so it is read and thrown away, never stored. Facebook’s fbclid is deliberately not used: it is added to every link that leaves Facebook, organic posts included.