Website Visitor Identification: Traffic Into Named Accounts
Most B2B site visitors never fill in a form. Company-level and person-level identification recover some as named accounts, with very different legal exposure.

Visitor identification recovers some anonymous B2B traffic as named accounts or named people. Company-level works globally through reverse IP lookup and is defensible in the EU. Person-level uses an identity graph, is effectively US-only, and carries real litigation exposure. Both are worthless without a filtered routing rule and a same-week response.
Key takeaways
- Company-level and person-level are two different products under one category name, with different mechanisms, coverage and legal footing.
- Person-level coverage depends on the visitor having touched the data co-op before, which is why it resolves US traffic and largely fails elsewhere.
- Vendor match rates are measured across their whole customer base rather than on your traffic, so plan on the number your own trial produces.
- The failure mode is organisational: an identification channel with no pre-agreed routing rule becomes noise within a fortnight.
Reviewed and updated September 5, 2026
Website Visitor Identification: Turning Anonymous Traffic Into Named Accounts
Somewhere between 95 and 98 percent of B2B website visitors never fill in a form. Visitor identification software exists to recover some of that traffic as named companies or named people. It works, partially, and the partial is the whole story: match rates, jurisdiction, and what you do in the next 24 hours determine whether this is a pipeline source or an expensive Slack channel nobody reads.
The vendors selling it describe this as deanonymizing your website traffic, and the phrase is worth reading literally. What gets undone is anonymity, and the two levels below undo different amounts of it: company-level deanonymization returns an account, person-level returns a named individual, and the legal footing for the two is not the same. So the question is never whether to deanonymize the traffic but which level you can defend.
Company-level versus person-level
Which tool is best for website visitor tracking is therefore the wrong first question, because the resolution level and the legal basis rule most of the shortlist in or out before any feature comparison starts.
These are two different products sold under one category name, and the gap between them is legal as much as technical.
| Company-level | Person-level | |
|---|---|---|
| Output | Account name, domain, firmographics | Named individual, LinkedIn profile, sometimes business email |
| Mechanism | Reverse IP lookup against an IP-to-company graph | Identity graph matching against a data co-op |
| Geographic coverage | Global | Effectively US-only in practice |
| Typical match rate | 20 to 50 percent of B2B traffic | 15 to 45 percent of US traffic |
| Regulatory exposure | Lower, still not zero | High outside the US |
| Typical monthly cost | Free tier to a few hundred dollars | $79 to several hundred dollars |
Company-level identification tells you Acme Corp visited your pricing page. Person-level tells you a named director at Acme did. The second is dramatically more actionable and dramatically more regulated.
- Returns an account and its firmographics
- Works globally
- Degrades on remote work, mobile and VPN traffic
- Commonly run under legitimate interest in the EU and UK
- Free tiers exist
- Returns a named individual
- Effectively US-only in practice
- Coverage depends on the visitor touching the co-op before
- Very hard to justify without consent in the EU and UK
- Paid from the first tier
How it actually works
Company-level resolves the visitor's IP address against a commercial IP-to-organisation database. It works because corporate networks announce ranges that map to registered organisations. It degrades badly with remote work, mobile traffic, consumer ISPs, and VPNs, which is why match rates on a consumer-heavy or heavily remote audience can sit far below the vendor's headline number.
Person-level relies on an identity graph. A network of participating sites captures a hashed identifier when a user is logged in or submits a form, and that hash is associated with a device or browser signature inside a co-op. When that same signature appears on your site, the provider resolves it back to a person. Coverage is a direct function of how much of the co-op your visitor has previously touched, which is why US B2B traffic resolves and traffic from most other markets does not.
Two consequences worth internalising. A vendor's advertised match rate is measured on their whole customer base, not your traffic mix, so treat 15 to 20 percent on your own site as the realistic planning number until a trial proves otherwise. And person-level identification is probabilistic: a shared device or a stale graph entry produces a confident, wrong name.
Legality: US versus EU

Nothing here is legal advice, and this is an area where you should involve counsel before deploying anything person-level.
In the EU and UK, an IP address is personal data under GDPR, and the ePrivacy Directive governs access to information stored on a device. Company-level identification is commonly run under legitimate interest with a documented balancing test, and several vendors are built specifically for that posture. Person-level de-anonymisation without prior consent is a different matter entirely: you are identifying a natural person who took no action to identify themselves, which is very difficult to justify under legitimate interest and which most person-level vendors do not attempt to support in Europe. That is why the person-level tools are US-first by design rather than by accident.
In the US, there is no federal equivalent, but the risk has shifted from privacy regulators to plaintiffs' lawyers. The active exposure in 2026 is state wiretapping and session-tracking litigation, most prominently claims brought under the California Invasion of Privacy Act, alongside state comprehensive privacy laws and the Washington My Health My Data Act for anything health-adjacent. Practical mitigations that vendors and counsel commonly recommend: a clear and current privacy policy disclosure, a consent banner configured for your jurisdictions, honouring global privacy control signals, and geographic gating so the person-level pixel does not fire for EU and UK visitors at all.
The 2026 tool landscape
Pricing verified against vendor pages and current buyer guides in mid-2026. This category reprices frequently.
| Tool | Resolution | Priced from | Notes |
|---|---|---|---|
| RB2B | Person-level, US traffic | Free tier, paid from $79 per month | Slack and Teams push, credit-based, US-only person-level |
| Vector | Person-level plus ad audience activation | Around $399 per month, scaling to $999 | Strongest when identified contacts feed paid retargeting |
| Warmly | Company and person-level with orchestration | From $10,000 per year as published on its pricing page in mid-2026, with a 10,000-credit floor on every tier | Bundles alerts, chat, and sequencing on top of identification |
| Leadfeeder (Dealfront) | Company-level | Genuine free tier, paid from around $99 per month | The most defensible option for EU and UK traffic |
| Clearbit Reveal | Company-level | Retired as a standalone product | Folded into HubSpot Breeze Intelligence; requires a paid HubSpot subscription, and non-HubSpot teams cannot buy the successor |
The Clearbit entry deserves emphasis because it still appears on comparison lists as a live option. HubSpot acquired Clearbit and rebranded the enrichment as Breeze Intelligence; the standalone Reveal product and free tools were sunset, and buying it now means buying HubSpot. If you were evaluating it, the practical replacements are in best Clearbit alternatives. For a detailed look at the person-level leader, see our RB2B review and alternatives.
Running a trial that tells you something
Every vendor in this category publishes a match rate measured across its whole customer base, and your traffic is not that base. The only number worth planning on is the one your own site produces, and a two-week trial answers it if you decide in advance what you are measuring.
Measure matched-and-in-ICP, not matched. A match rate counts resolutions. What you are buying is qualified resolutions, and the gap between the two is decided by your traffic mix rather than by the vendor. A site with heavy consumer or job-seeker traffic can post a healthy headline match rate and produce very few accounts anyone would work.
Compare against what you already know. Run the trial alongside your existing form fills and CRM for the same fortnight. Identified accounts that were already in an open opportunity are not new signal, and on most sites they are a meaningful share of the matches. Subtract them before you calculate a cost per usable account.
Spot-check the person-level names by hand. Person-level identification is probabilistic, and a shared device or a stale graph entry produces a confident wrong name. Take twenty resolutions, check each against LinkedIn and the company site, and count how many you would be comfortable emailing. That number is the one to budget against.
Decide the routing rule before the data arrives. A trial that ends with a Slack channel full of company names and no agreed action is a trial that proves nothing, because the failure it demonstrates is organisational rather than technical.
Turning identification into pipeline
The failure mode is universal and it is not the software. A Slack channel fills with company names, everyone admires it for two weeks, and then it becomes noise. Three things prevent that.
- Yes: Filter before you route
- Yes: Weight by page, not by visit
- Yes: Never mention the surveillance
Filter before you route. Score every identified visitor against ICP fit before it reaches a human. An identified visitor who is not in your ICP is not a lead, and letting those into the channel is what trains people to ignore it.
Weight by page, not by visit. A pricing page view, a docs page view, and a careers page view are three different events. Route on the first two and suppress the third.
| Signal | Action | Response window |
|---|---|---|
| ICP-fit person views pricing | Direct outreach on the underlying problem | 24 hours |
| Multiple people from one ICP account in a week | Multithread the account across email and LinkedIn | 48 hours |
| Company-level ICP match, no person resolved | Add the account to a targeted sequence, source contacts separately | 5 days |
| Repeat visitor already in an open opportunity | Alert the owning rep, do not sequence | Same day |
| Non-ICP visit | Suppress entirely | None |
Never mention the surveillance. "I saw you visited our pricing page" is the single fastest way to lose the account. Reference the problem the page addresses. The whole point of the signal is timing, not a conversation starter.
Speed is the variable that decides whether this works. Identification data ages out in days, so the play is a short, ready sequence run across both email and LinkedIn at once, not a queue for someone to work on Friday. The sequencing patterns in the outbound sales playbook apply directly.

Where it sits in the signal stack

Visitor identification is first-party intent, and it is the strongest signal most companies are not yet using: the account came to you. Third-party topic data from a co-op is a wider, weaker, and far more expensive net. Instrument your own traffic before you buy a feed, and read the B2B intent data guide for how the two layers combine. Once both are firing, the routing itself is worth automating, along the lines described in 8 GTM agent workflows.
When to skip the category entirely
Three situations where identification is the wrong purchase, and where teams buy it anyway.
Traffic is too thin to matter. The arithmetic is unforgiving: a site with 800 monthly visitors, a fifth of them in ICP, at a realistic person-level match rate, produces a handful of names a month. That is a list a human could assemble by hand, and the tool costs more than the hour.
Nobody owns the response. Identification data ages out in days, so the value is entirely in a same-week response. If the honest answer to "who works these on Tuesday" is nobody, the subscription buys a dashboard and the dashboard buys nothing.
The traffic is mostly outside the United States. Person-level coverage is a function of the co-op, and the co-op is US-heavy. A European-majority audience gets company-level identification at best, which is a genuinely useful and much cheaper product, so buy that instead of paying for a person-level tier that cannot resolve your visitors.
If none of those apply, start company-level. It is cheaper, defensible in more jurisdictions, and it proves whether anyone will act on the signal before you take on the litigation exposure that comes with naming individuals.
Bottom line
Company-level identification is cheap, global, defensible in the EU, and roughly half as useful. Person-level identification is powerful, US-practical only, and carries litigation risk that needs real legal review. Both are worthless without a filtered routing rule and a same-week response.
If you want the response motion built rather than another dashboard, get a free campaign plan and we will design the sequence that fires when a named account shows up.
Frequently asked questions.
Frequently asked questions- What is website visitor identification?
- Software that turns anonymous site traffic into named accounts or named individuals. Company-level tools resolve the visitor's IP address against a commercial IP-to-organisation database and work globally. Person-level tools match a device or browser signature against an identity co-op and return a named individual, which works mainly on United States traffic.
- Is person-level identification legal in the EU?
- It is very difficult to justify without consent, and most person-level vendors do not attempt to support it in Europe. An IP address is personal data under GDPR, and identifying a natural person who took no action to identify themselves is hard to defend under legitimate interest. Company-level identification is the commonly used posture there instead.
- What match rate should I expect?
- Lower than the vendor's headline, because that number is measured across its whole customer base rather than on your traffic mix. Plan on a modest figure until a trial on your own site proves otherwise, and measure matched-and-in-ICP rather than matched, since resolutions outside your ideal customer profile are not leads.
- How quickly do we have to act on the data?
- Within days, and ideally within 24 hours for a pricing-page visit from an in-profile person. Identification data ages out fast, so the value is entirely in a same-week response run across email and LinkedIn. Never reference the visit itself in the message; reference the problem the page addresses instead.
About the author.
Fernando Cao is CEO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Accenture Strategy. Studied at University of Bath.
Fernando Cao · CEO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
B2B Intent Data: What It Predicts, Which Providers Pay Off
Intent data predicts that an account is researching a topic more than usual. That is the whole signal. What the providers cost, and why most programs disappoint.
Old GTM vs New GTM: What Changed in the Last Two Years
Most teams still run the 2019 playbook: buy a list, load a sequencer, hire BDRs. Here is the signal-based model that replaced it, and the honest cost of switching.
What Is a GTM Engineer? The Role, the Stack, the Pay
A GTM engineer builds the systems that produce pipeline. The role, the day-to-day ownership, the stack by layer, verified salary ranges, and how to hire one.
How to Build an ICP That Changes Your Target List
Most ICPs never change the target list. Here is the count test, the five inputs, a worked TAM, SAM and SOM example with full arithmetic, and an eight-field worksheet.
Anthropic's Labour Market Report Is a Management Story
The interesting number is not what the models can do. It is the gap between that and what companies have actually built into how they operate. That gap is an org-design problem, not a talent problem.
The 7-Layer GTM AI Stack for 2026 (The Order Matters)
Your outbound will plateau this year. Not because of the tools you picked, but because of the order you stacked them in. Each layer caps every layer above it.