How attribution works

The three ways Yonto ties a sale to a creator — tracked link, discount code, and Shopify webhook — and what each one catches.

When you pay a creator, you want one answer: did they actually drive sales? Yonto answers that by watching for the same sale through three independent paths. If any one of them fires, the sale is credited to that creator — and you see the revenue, the cost per customer, and the real return.

The three paths#

Every campaign gives one creator a unique tracked link and a unique discount code. From there, a sale can be attributed three ways:

When a shopper taps the creator's link, Yonto records the click and sets a first-party cookie in their browser that lasts 30 days. If they buy any time in that window — even without using the code — the sale is tied back to the creator. This is what catches people who click, browse, and come back later to check out.

2. The discount code#

Each creator gets a code (like MAYA10). When a shopper enters it at checkout, that's an unmistakable signal of who sent them — no cookie required. It also rewards the shopper, which lifts conversions.

Warning.the discount code must match exactly — it's case-sensitive. MAYA10 and maya10 are treated as different codes, so hand the creator the code exactly as Yonto generated it.

3. The Shopify webhook#

If you connect Shopify, Yonto receives each order server-sidethe moment it's placed and matches it to a creator by the tracked-link cookie or the discount code. This is the most reliable path: it doesn't depend on any code on your storefront, and it can't be blocked by an ad blocker.

What each path catches#

ParameterTypeDescription
Tracked linkclick cookieAny purchase within 30 days of the click, code or not.
Discount codeexact matchAny order that used the creator's code at checkout.
Shopify webhookserver-sideEvery order, matched by cookie or code — no storefront code needed.

The limits — why the number is a floor#

Attribution is never perfect, and we'd rather be honest about that than sell you a flattering number. Some real sales simply can't be proven:

  • Cross-device journeys — someone sees the link on their phone but buys on a laptop.
  • Cleared cookies or private browsing — the 30-day cookie never persists.
  • Cookie-consent rejection — if a shopper declines tracking cookies, the click can't be linked to their later purchase.
  • Dark social — the post gets screenshotted and shared in a group chat, and the buyer searches for you directly.

So treat your Yonto numbers as a confident floor — the sales we can prove, not the ceiling of everything the creator influenced.

Note.two signals are not affected by cookie banners at all: click counts (recorded at the redirect, before any storefront cookie) and discount-code sales (matched at checkout). Cookie consent only affects the link-cookie path.

When a shopper declines cookies#

If a shopper rejects tracking cookies on your store, Shopify honours that and withholds the tracking details from the order — the referrer and the tracked-link marker never reach us. We don't try to work around that.Re-identifying someone who opted out would break the consent they were given, and it's the opposite of honest measurement. So a link-only visit from someone who declined simply isn't attributable — and that's by design.

Here's what still works when consent is declined, and what doesn't:

ParameterTypeDescription
Discount codealways worksThe code is part of the order, not a tracking cookie, so a sale using it is attributed either way.
Click countalways worksRecorded at the redirect, before your store sets any cookie.
Tracked link (cookie)needs consentOnly attributes when the shopper accepts cookies, so Shopify keeps the link marker on the order.
Tip.this is why the discount code is your most reliable signal — and why it's worth having the creator lead with it. It converts better, and it attributes no matter what the shopper decides about cookies.

Putting it together#

In practice the three paths overlap and reinforce each other: the webhook catches the order, the cookie explains where it came from, and the code confirms it. You get a single, de-duplicated count per creator — and when a campaign loses money, it shows in red, plainly.