How Websites Track You

Every time you visit a website, a behind-the-scenes exchange of information begins. Understanding how tracking works is the first step toward controlling it — and it's less complicated than it sounds.

Cookies are small text files a website saves to your browser. Some are useful: they remember your login or shopping cart. Others — called third-party cookies — follow you across multiple sites to build a profile of your interests, helping advertisers serve targeted ads. This is why you might see an ad for running shoes on a news site shortly after browsing an athletic retailer.

Tracking pixels are tiny, invisible images embedded in web pages and emails. When they load, they signal back to the sender — confirming you opened an email or visited a page.

Device fingerprinting is a more advanced technique. It collects details about your device — screen size, installed fonts, browser version — and assembles them into a unique identifier, even if you've cleared your cookies.

Private Browsing Has Limits

Incognito or private mode stops your device from saving your browsing history locally. It does not make you anonymous online — your internet service provider, employer network, and the websites you visit can still observe your activity. Use it for session privacy on a shared device, not for full anonymity.

If you're completely new to how the internet works, our beginner's guide to getting online covers the foundational concepts that will make this guide easier to follow.

What Data Is Actually Being Collected

Data collection falls into a few broad categories. Knowing what's being gathered helps you decide which areas matter most to you.

  • Browsing history: which pages you visit and how long you stay.
  • Search queries: the terms you type into search engines.
  • Location data: your approximate geographic location, often inferred from your IP address or GPS if you've granted permission to an app.
  • Device and account data: the type of device you use, your operating system, and details tied to any account you're signed into.
  • Behavioral data: what you click on, how you scroll, and what you purchase.

79%

Americans concerned about data use by companies

According to Pew Research Center survey data, a large majority of Americans say they are concerned about how companies collect and use their personal data.

81%

Users who feel little control over collected data

Pew Research Center has reported that roughly eight in ten U.S. adults say they have very little or no control over the data that companies collect about them.

This data is used primarily by advertisers, but it can also be shared with data brokers — companies that compile and sell consumer profiles — or exposed in a data breach. Understanding that your data has real-world value is a useful motivator for taking privacy seriously.

Your Browser: The First Line of Defense

Your web browser handles nearly every online interaction, making its settings the most impactful place to start.

Practical browser steps

  1. Enable tracker blocking. Most modern browsers include a built-in setting to block third-party trackers. Look in your browser's Privacy or Security settings.
  2. Clear cookies regularly. You can set your browser to clear cookies when it closes, or clear them manually every few weeks.
  3. Use a private or incognito window for sensitive searches. Note: this prevents your device from saving history, but it does not hide your activity from your internet provider or the sites you visit.
  4. Consider a privacy-focused search engine. Some search engines are designed to not store your queries or build a profile around your searches.

Check your browser's built-in privacy report — most modern browsers show exactly how many trackers they've blocked on any given page. It's a fast way to see which sites are heaviest on tracking.

Seeing tracker counts in real time helps users develop an intuition for which categories of sites (news, retail, social) collect the most data, making privacy decisions more informed.

Set a monthly 'privacy check-in' reminder to review app permissions on your phone. Apps can update their permission requests after installation, and quarterly reviews are often too infrequent to catch changes.

App permission creep is a documented issue — apps that initially requested minimal access sometimes expand their requests through updates without drawing much attention.

Extensions — small add-ons for your browser — can add extra protection. Ad blockers and script blockers reduce the number of trackers that can load. However, be selective: only install extensions from well-known sources, as malicious extensions exist. See our link-safety checklist for related guidance.

Passwords, Accounts, and Two-Factor Authentication

A weak or reused password is one of the most common ways accounts get compromised. The good news is that this risk is highly manageable.

Password basics

  • Use a unique password for every account. If one service is breached and you've reused that password elsewhere, attackers can access your other accounts automatically — a technique called credential stuffing.
  • Make passwords long and unpredictable. A random phrase of four or more unrelated words is both strong and memorable.
  • Use a password manager — a secure app that stores all your passwords so you only need to remember one master password.

Two-factor authentication (2FA)

Two-factor authentication adds a second verification step — such as a code sent to your phone — when you log in. Even if someone obtains your password, they can't access your account without that second factor. Enable 2FA on email, banking, and social media accounts as a priority.

Never Share a Verification Code

If you receive an unexpected 2FA code that you didn't request, do not share it with anyone — including someone claiming to be from a company's support team. This is a common social engineering tactic used to steal accounts. Treat any unsolicited request for your verification code as a red flag and report it to the relevant platform.

If you receive an unexpected 2FA code that you didn't request, do not share it with anyone — including someone claiming to be from a company's support team. This is a common social engineering tactic used to steal accounts.

Treat any unsolicited request for your verification code as a red flag and report it to the relevant platform.

]

Protecting Yourself on the Go

Mobile devices and public networks introduce privacy considerations beyond the home setup.

App permissions: Apps on your phone frequently request access to your location, contacts, microphone, and camera. Review these regularly in your phone's Settings. Grant only what an app genuinely needs to function — a flashlight app, for example, has no legitimate reason to access your contacts.

Public Wi-Fi caution: Free networks at coffee shops, airports, and hotels are convenient but are more easily monitored than your home network. Avoid logging into banking or sensitive accounts on public Wi-Fi. Our guide on using public Wi-Fi safely goes into more detail on what's low-risk versus what to avoid.

Shared or borrowed devices: If you use a library computer or a friend's phone, always sign out of every account before you leave. For more habits in these situations, see our guide on staying safe on shared devices.

Watch Out for 'Free' Apps and Services

When an app or service costs nothing, the business model often involves collecting and monetizing user data. This isn't inherently illegal, but it's worth reading the privacy policy — or at minimum, being selective about what information you provide during sign-up. Using a secondary email address for non-essential accounts can limit the personal data you expose.

Building a Privacy-First Mindset

Online privacy isn't a single action — it's an ongoing practice. Think of it like locking your front door: you don't do it once and forget about it.

Habits that compound over time

  • Read privacy prompts. When a website asks to use your location or send notifications, pause and ask whether it needs that permission. Declining most of these requests costs nothing.
  • Check account activity. Most services let you see which devices are logged into your account. Review this occasionally and remove anything unfamiliar.
  • Reduce your data footprint. Delete accounts you no longer use. Old, dormant accounts can be breached just like active ones.
  • Stay skeptical. If an offer seems too good to be true, or if a message creates unusual urgency, slow down. Phishing and scams rely on rushed decisions.

“Privacy is not about having something to hide. It's about having the power to choose what you share and with whom.”

— Ann Cavoukian, Former Information and Privacy Commissioner of Ontario, creator of Privacy by Design framework

For deeper reading and tools, explore the resources below, or visit our Everyday Tech guides for more practical advice on getting the most out of your digital life.

guide

Electronic Frontier Foundation (EFF) – Surveillance Self-Defense

A free, plain-language guide from a leading digital rights nonprofit covering practical tools and habits to protect your privacy online, organized by threat level.

tool

Have I Been Pwned

A free tool that lets you check whether your email address has appeared in any known data breaches, helping you identify which accounts may need a password change.

guide

FTC Consumer Information – Privacy & Identity

The Federal Trade Commission's official consumer resource hub on data privacy, identity theft, and online scams — reliable, government-sourced guidance for U.S. residents.

Share

Internet & Mobile Editorial Team · Contributor

Internet & Mobile Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.