Profile merging across devices: how identity resolution actually works
The same person browsing on a phone and buying on a laptop is two records until something connects them. What the connection is, what happens at the moment of the merge, and the rule that stops it going wrong.
A person finds you on a phone during a commute, looks again on a work laptop at lunch, and buys on a tablet that evening. That is one customer and three trails, and whether your marketing treats them as one determines whether any of your behavioural targeting is real.
The mechanism is unglamorous and it matters more than any segmentation rule you will write on top of it.
Create the profile on the first page view
The instinct is to create a customer record when somebody buys or subscribes. That is too late, because everything that led to the purchase happened before it and is thrown away.
- A profile appears on the first page view, keyed to a first-party cookie, with nothing on it but that identifier.
- Events attach to it from that moment — pages seen, products viewed, cart activity.
- It gains a name and an email later, when they order or subscribe.
That ordering is the whole point. A profile created early has a history at the moment it identifies; one created at checkout is born with none, and no amount of later cleverness recovers it.
The identifiers that connect trails
- The first-party browser identifier. Strong within one browser, useless across devices, and it disappears when cookies are cleared.
- A hashed email address. The strongest cross-device signal, available the moment somebody identifies anywhere.
- The shop's own customer id, for anybody with an account. Authoritative when present.
- A cart token, which links an abandoned cart to the order it eventually became.
Match on the strong ones and treat the weak ones as supporting evidence. Never merge on a name, and never on an IP address — a household or an office shares both.
What has to happen at the moment of a merge
When two profiles turn out to be one person, the merge has to be complete or it creates a worse mess than it solved.
- Oldest profile wins as the surviving record, so the earliest history is preserved.
- Identities move across — every cookie id, every email hash, every customer id now points at the survivor.
- Events move, keeping their original timestamps rather than the merge time.
- Counts recompute rather than add naively, so an order counted on both sides does not become two.
- Consent is unioned carefully. If one record consented and the other did not, take the most recent explicit decision, not the most permissive one.
Identity must not come from a context with no shopper in it
This is the trap that silently ruins the whole model. An order created in wp-admin by a staff member, or by WP-CLI during an import, runs in a request with the staff member's browser cookie attached.
If that cookie is treated as the shopper's identity, every order typed in by the same person collapses into one profile. A shop discovers this when one customer appears to have four hundred orders.
- Return no browser identifier outside a real shopper request. Admin context, CLI context and REST calls all qualify.
- Fall back to the email hash when there is no browser trail, which is the correct identity for an order typed in by hand.
- Pin it with a test, because it is invisible until it is very visible.
What to expect from the numbers
Merging changes counts, and it is worth knowing which way before somebody asks.
- Your visitor count falls as trails combine. This is correction, not loss.
- Repeat purchase rate rises, because orders previously split across two records now sit on one.
- The merge rate itself is a useful metric. A sudden change means something upstream altered how identity is collected — a checkout change, a consent banner change, a plugin update.
Sources and further reading (3)
- EDPB — Guidelines 2/2023 on Art. 5(3) ePrivacy
- EDPB — Guidelines 05/2020 on consent
- GDPR Article 4 — Definitions (personal data, pseudonymisation)
Checked on 23 September 2026. Provider prices, mailbox rules and legal guidance change — verify anything you plan to act on.
Profiles that start before the purchase
Auralata creates a profile on the first page view and merges trails when they turn out to be the same person — oldest record wins, events keep their real timestamps, and identity is never taken from a request with no shopper in it.