GTM Strategy

    Website Visitor Identification: Traffic Into Named Accounts

    Most B2B site visitors never fill in a form. Company-level and person-level identification recover some as named accounts, with very different legal exposure.

    Company-level and person-level visitor identification compared on output, mechanism, geographic coverage, match rate, regulatory exposure and cost
    July 21, 2026Updated September 5, 20269 min read
    Share:
    The short answer

    Visitor identification recovers some anonymous B2B traffic as named accounts or named people. Company-level works globally through reverse IP lookup and is defensible in the EU. Person-level uses an identity graph, is effectively US-only, and carries real litigation exposure. Both are worthless without a filtered routing rule and a same-week response.

    Key takeaways

    • Company-level and person-level are two different products under one category name, with different mechanisms, coverage and legal footing.
    • Person-level coverage depends on the visitor having touched the data co-op before, which is why it resolves US traffic and largely fails elsewhere.
    • Vendor match rates are measured across their whole customer base rather than on your traffic, so plan on the number your own trial produces.
    • The failure mode is organisational: an identification channel with no pre-agreed routing rule becomes noise within a fortnight.

    Reviewed and updated September 5, 2026

    Website Visitor Identification: Turning Anonymous Traffic Into Named Accounts

    Somewhere between 95 and 98 percent of B2B website visitors never fill in a form. Visitor identification software exists to recover some of that traffic as named companies or named people. It works, partially, and the partial is the whole story: match rates, jurisdiction, and what you do in the next 24 hours determine whether this is a pipeline source or an expensive Slack channel nobody reads.

    The vendors selling it describe this as deanonymizing your website traffic, and the phrase is worth reading literally. What gets undone is anonymity, and the two levels below undo different amounts of it: company-level deanonymization returns an account, person-level returns a named individual, and the legal footing for the two is not the same. So the question is never whether to deanonymize the traffic but which level you can defend.

    Company-level versus person-level

    Which tool is best for website visitor tracking is therefore the wrong first question, because the resolution level and the legal basis rule most of the shortlist in or out before any feature comparison starts.

    These are two different products sold under one category name, and the gap between them is legal as much as technical.

    Company-levelPerson-level
    OutputAccount name, domain, firmographicsNamed individual, LinkedIn profile, sometimes business email
    MechanismReverse IP lookup against an IP-to-company graphIdentity graph matching against a data co-op
    Geographic coverageGlobalEffectively US-only in practice
    Typical match rate20 to 50 percent of B2B traffic15 to 45 percent of US traffic
    Regulatory exposureLower, still not zeroHigh outside the US
    Typical monthly costFree tier to a few hundred dollars$79 to several hundred dollars

    Company-level identification tells you Acme Corp visited your pricing page. Person-level tells you a named director at Acme did. The second is dramatically more actionable and dramatically more regulated.

    Company-levelReverse IP lookup
    • Returns an account and its firmographics
    • Works globally
    • Degrades on remote work, mobile and VPN traffic
    • Commonly run under legitimate interest in the EU and UK
    • Free tiers exist
    Person-levelIdentity graph matching
    • Returns a named individual
    • Effectively US-only in practice
    • Coverage depends on the visitor touching the co-op before
    • Very hard to justify without consent in the EU and UK
    • Paid from the first tier
    Two products sold under one category name. The mechanism, the coverage and the legal footing all differ.

    How it actually works

    Company-level resolves the visitor's IP address against a commercial IP-to-organisation database. It works because corporate networks announce ranges that map to registered organisations. It degrades badly with remote work, mobile traffic, consumer ISPs, and VPNs, which is why match rates on a consumer-heavy or heavily remote audience can sit far below the vendor's headline number.

    Person-level relies on an identity graph. A network of participating sites captures a hashed identifier when a user is logged in or submits a form, and that hash is associated with a device or browser signature inside a co-op. When that same signature appears on your site, the provider resolves it back to a person. Coverage is a direct function of how much of the co-op your visitor has previously touched, which is why US B2B traffic resolves and traffic from most other markets does not.

    Two consequences worth internalising. A vendor's advertised match rate is measured on their whole customer base, not your traffic mix, so treat 15 to 20 percent on your own site as the realistic planning number until a trial proves otherwise. And person-level identification is probabilistic: a shared device or a stale graph entry produces a confident, wrong name.

    Legality: US versus EU

    Schematic: Legality: US versus EU (IP address privacy, Company-level balancing test, Person-level consent, US litigation)

    Nothing here is legal advice, and this is an area where you should involve counsel before deploying anything person-level.

    In the EU and UK, an IP address is personal data under GDPR, and the ePrivacy Directive governs access to information stored on a device. Company-level identification is commonly run under legitimate interest with a documented balancing test, and several vendors are built specifically for that posture. Person-level de-anonymisation without prior consent is a different matter entirely: you are identifying a natural person who took no action to identify themselves, which is very difficult to justify under legitimate interest and which most person-level vendors do not attempt to support in Europe. That is why the person-level tools are US-first by design rather than by accident.

    In the US, there is no federal equivalent, but the risk has shifted from privacy regulators to plaintiffs' lawyers. The active exposure in 2026 is state wiretapping and session-tracking litigation, most prominently claims brought under the California Invasion of Privacy Act, alongside state comprehensive privacy laws and the Washington My Health My Data Act for anything health-adjacent. Practical mitigations that vendors and counsel commonly recommend: a clear and current privacy policy disclosure, a consent banner configured for your jurisdictions, honouring global privacy control signals, and geographic gating so the person-level pixel does not fire for EU and UK visitors at all.

    The 2026 tool landscape

    Pricing verified against vendor pages and current buyer guides in mid-2026. This category reprices frequently.

    ToolResolutionPriced fromNotes
    RB2BPerson-level, US trafficFree tier, paid from $79 per monthSlack and Teams push, credit-based, US-only person-level
    VectorPerson-level plus ad audience activationAround $399 per month, scaling to $999Strongest when identified contacts feed paid retargeting
    WarmlyCompany and person-level with orchestrationFrom $10,000 per year as published on its pricing page in mid-2026, with a 10,000-credit floor on every tierBundles alerts, chat, and sequencing on top of identification
    Leadfeeder (Dealfront)Company-levelGenuine free tier, paid from around $99 per monthThe most defensible option for EU and UK traffic
    Clearbit RevealCompany-levelRetired as a standalone productFolded into HubSpot Breeze Intelligence; requires a paid HubSpot subscription, and non-HubSpot teams cannot buy the successor

    The Clearbit entry deserves emphasis because it still appears on comparison lists as a live option. HubSpot acquired Clearbit and rebranded the enrichment as Breeze Intelligence; the standalone Reveal product and free tools were sunset, and buying it now means buying HubSpot. If you were evaluating it, the practical replacements are in best Clearbit alternatives. For a detailed look at the person-level leader, see our RB2B review and alternatives.

    Running a trial that tells you something

    Every vendor in this category publishes a match rate measured across its whole customer base, and your traffic is not that base. The only number worth planning on is the one your own site produces, and a two-week trial answers it if you decide in advance what you are measuring.

    Measure matched-and-in-ICP, not matched. A match rate counts resolutions. What you are buying is qualified resolutions, and the gap between the two is decided by your traffic mix rather than by the vendor. A site with heavy consumer or job-seeker traffic can post a healthy headline match rate and produce very few accounts anyone would work.

    Compare against what you already know. Run the trial alongside your existing form fills and CRM for the same fortnight. Identified accounts that were already in an open opportunity are not new signal, and on most sites they are a meaningful share of the matches. Subtract them before you calculate a cost per usable account.

    Spot-check the person-level names by hand. Person-level identification is probabilistic, and a shared device or a stale graph entry produces a confident wrong name. Take twenty resolutions, check each against LinkedIn and the company site, and count how many you would be comfortable emailing. That number is the one to budget against.

    Decide the routing rule before the data arrives. A trial that ends with a Slack channel full of company names and no agreed action is a trial that proves nothing, because the failure it demonstrates is organisational rather than technical.

    Turning identification into pipeline

    The failure mode is universal and it is not the software. A Slack channel fills with company names, everyone admires it for two weeks, and then it becomes noise. Three things prevent that.

    Turning identification into pipeline
    • Yes: Filter before you route
    • Yes: Weight by page, not by visit
    • Yes: Never mention the surveillance
    Three rules that stop an identification channel becoming a Slack channel nobody reads.

    Filter before you route. Score every identified visitor against ICP fit before it reaches a human. An identified visitor who is not in your ICP is not a lead, and letting those into the channel is what trains people to ignore it.

    Weight by page, not by visit. A pricing page view, a docs page view, and a careers page view are three different events. Route on the first two and suppress the third.

    SignalActionResponse window
    ICP-fit person views pricingDirect outreach on the underlying problem24 hours
    Multiple people from one ICP account in a weekMultithread the account across email and LinkedIn48 hours
    Company-level ICP match, no person resolvedAdd the account to a targeted sequence, source contacts separately5 days
    Repeat visitor already in an open opportunityAlert the owning rep, do not sequenceSame day
    Non-ICP visitSuppress entirelyNone

    Never mention the surveillance. "I saw you visited our pricing page" is the single fastest way to lose the account. Reference the problem the page addresses. The whole point of the signal is timing, not a conversation starter.

    Speed is the variable that decides whether this works. Identification data ages out in days, so the play is a short, ready sequence run across both email and LinkedIn at once, not a queue for someone to work on Friday. The sequencing patterns in the outbound sales playbook apply directly.

    Routing rules for identified visitors: each signal paired with an action and a response window, from 24 hours on a pricing-page view to suppressing non-ICP visits entirely

    Where it sits in the signal stack

    Schematic: Where it sits in the signal stack (Visitor ID is first-party, Account came to you, Third-party: wider, weaker, Instrument own traffic first)

    Visitor identification is first-party intent, and it is the strongest signal most companies are not yet using: the account came to you. Third-party topic data from a co-op is a wider, weaker, and far more expensive net. Instrument your own traffic before you buy a feed, and read the B2B intent data guide for how the two layers combine. Once both are firing, the routing itself is worth automating, along the lines described in 8 GTM agent workflows.

    When to skip the category entirely

    Three situations where identification is the wrong purchase, and where teams buy it anyway.

    Traffic is too thin to matter. The arithmetic is unforgiving: a site with 800 monthly visitors, a fifth of them in ICP, at a realistic person-level match rate, produces a handful of names a month. That is a list a human could assemble by hand, and the tool costs more than the hour.

    Nobody owns the response. Identification data ages out in days, so the value is entirely in a same-week response. If the honest answer to "who works these on Tuesday" is nobody, the subscription buys a dashboard and the dashboard buys nothing.

    The traffic is mostly outside the United States. Person-level coverage is a function of the co-op, and the co-op is US-heavy. A European-majority audience gets company-level identification at best, which is a genuinely useful and much cheaper product, so buy that instead of paying for a person-level tier that cannot resolve your visitors.

    If none of those apply, start company-level. It is cheaper, defensible in more jurisdictions, and it proves whether anyone will act on the signal before you take on the litigation exposure that comes with naming individuals.

    Bottom line

    Company-level identification is cheap, global, defensible in the EU, and roughly half as useful. Person-level identification is powerful, US-practical only, and carries litigation risk that needs real legal review. Both are worthless without a filtered routing rule and a same-week response.

    If you want the response motion built rather than another dashboard, get a free campaign plan and we will design the sequence that fires when a named account shows up.

    Questions

    Frequently asked questions.

    Frequently asked questions
    What is website visitor identification?
    Software that turns anonymous site traffic into named accounts or named individuals. Company-level tools resolve the visitor's IP address against a commercial IP-to-organisation database and work globally. Person-level tools match a device or browser signature against an identity co-op and return a named individual, which works mainly on United States traffic.
    Is person-level identification legal in the EU?
    It is very difficult to justify without consent, and most person-level vendors do not attempt to support it in Europe. An IP address is personal data under GDPR, and identifying a natural person who took no action to identify themselves is hard to defend under legitimate interest. Company-level identification is the commonly used posture there instead.
    What match rate should I expect?
    Lower than the vendor's headline, because that number is measured across its whole customer base rather than on your traffic mix. Plan on a modest figure until a trial on your own site proves otherwise, and measure matched-and-in-ICP rather than matched, since resolutions outside your ideal customer profile are not leads.
    How quickly do we have to act on the data?
    Within days, and ideally within 24 hours for a pricing-page visit from an in-profile person. Identification data ages out fast, so the value is entirely in a same-week response run across email and LinkedIn. Never reference the visit itself in the message; reference the problem the page addresses instead.
    Website Visitor IdentificationGTM StrategyBuying SignalsFirst-Party Data
    Byline

    About the author.

    Fernando Cao

    Fernando Cao is CEO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Accenture Strategy. Studied at University of Bath.

    Fernando Cao · CEO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    GTM Strategy

    B2B Intent Data: What It Predicts, Which Providers Pay Off

    Intent data predicts that an account is researching a topic more than usual. That is the whole signal. What the providers cost, and why most programs disappoint.

    8 min readRead →
    GTM Strategy

    Old GTM vs New GTM: What Changed in the Last Two Years

    Most teams still run the 2019 playbook: buy a list, load a sequencer, hire BDRs. Here is the signal-based model that replaced it, and the honest cost of switching.

    8 min readRead →
    GTM Strategy

    What Is a GTM Engineer? The Role, the Stack, the Pay

    A GTM engineer builds the systems that produce pipeline. The role, the day-to-day ownership, the stack by layer, verified salary ranges, and how to hire one.

    7 min readRead →
    GTM Strategy

    How to Build an ICP That Changes Your Target List

    Most ICPs never change the target list. Here is the count test, the five inputs, a worked TAM, SAM and SOM example with full arithmetic, and an eight-field worksheet.

    7 min readRead →
    GTM Strategy

    Anthropic's Labour Market Report Is a Management Story

    The interesting number is not what the models can do. It is the gap between that and what companies have actually built into how they operate. That gap is an org-design problem, not a talent problem.

    5 min readRead →
    GTM Strategy

    The 7-Layer GTM AI Stack for 2026 (The Order Matters)

    Your outbound will plateau this year. Not because of the tools you picked, but because of the order you stacked them in. Each layer caps every layer above it.

    8 min readRead →