Conversion and UX

Session Recording

Also called session replay, screen recording, visitor recording

A tool that captures how individual visitors scroll, click and move through a website, so you can replay their visits and spot where they struggle.

Quick facts: Session Recording

Category
Conversion and UX
Also called
session replay, screen recording, visitor recording
Level
Intermediate
Affects
Conversion research, form and checkout fixes, bug finding, privacy compliance
Where to see it
Microsoft Clarity, Hotjar, other replay tools, your consent management platform, GA4 for choosing which sessions to watch
In this article4
  1. How session recording works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

Session recording is a tool that captures how individual visitors interact with a website (where they scroll, click, pause and type) so the session can be replayed later as a video-like reconstruction. It shows the behaviour behind the numbers in your analytics.

How session recording works

A script on the page records events rather than filming the screen: mouse movements, taps, scrolls, clicks, page changes and the structure of the page at each moment. The tool then rebuilds the visit, so you watch a visitor’s cursor move across a copy of your page.

Tools such as Microsoft Clarity and Hotjar usually combine recordings with a heatmap, which summarises clicks and scrolling across many visits. They also flag patterns worth watching, such as “rage clicks” (repeated clicks on something that does not respond) and “dead clicks” on elements that look clickable but are not.

The script stores an identifier on the visitor’s device so it can stitch page views into one session, and it can capture whatever appears on the page. Most tools mask typed text by default, but settings vary and can be changed, so check rather than assume.

Why it matters

Analytics tells you that most mobile visitors leave your booking page. A recording can show you why: the date picker will not open on an iPhone, the “Next” button is hidden behind the cookie banner, or people keep tapping a photo that is not a link. These are problems nobody on the team sees, because they use the site on a desktop and know where everything is.

For a UK business, recordings also raise clear privacy obligations. Because the script stores information on the device and can capture personal data, session recording on UK sites normally loads only after the visitor gives consent under PECR, with UK GDPR covering what you then do with the data. Form fields should be masked so names, emails, addresses and anything typed into a message box are never captured, and payment pages should be excluded altogether. Your privacy and cookie notices should name the tool and say what it does. UK law has added a limited consent exemption for some analytics storage, but at the time of writing (October 2026), check current ICO guidance before assuming it covers session recording, which captures far more than visit counts.

Common mistakes

  • Installing the tool through a tag manager so it fires before consent.
  • Leaving form masking off, or unmasking fields to “see what people type”.
  • Recording logged-in account areas where pages show names, addresses and order histories.
  • Watching hours of random sessions without a question, then drawing conclusions from the strangest ones.
  • Recording every visit indefinitely, rather than for a defined period with a sensible retention setting.

How to act on it

Start with a question your analytics has raised, such as why mobile visitors drop off at step two of the quote form. Filter recordings to sessions that match: mobile, that page, no conversion. Watch 15 to 30, note each obstacle you see, and fix the ones that recur.

Before any of that, set the tool up properly. Connect it to your consent banner so it loads only after the visitor agrees, turn on masking for all inputs, exclude checkout and account pages, set a short retention period, and update your privacy notice. Then check, in a private window and with consent refused, that no recording script loads.

Recordings are one of the first things I look at before a website redesign, because they show which problems the new site has to fix and which parts of the old one people already use well.

Do and do not

Do

  • Load the tool only after the visitor consents
  • Mask form fields and any personal or payment information
  • Start from a question, then filter recordings that can answer it

Do not

  • Record checkout or account pages without checking what is captured
  • Watch random recordings in the hope something turns up
  • Treat one odd session as proof of a widespread problem

Questions people ask about this

Do I need consent for session recording in the UK?

In most cases, yes. Session recording tools store information on the visitor's device and can capture personal data, so PECR consent rules and UK GDPR apply. Load the tool only after the visitor agrees through your cookie banner, mask form fields and explain the tool in your privacy and cookie notices.

Can session recordings capture passwords or card numbers?

Reputable tools are designed not to capture password fields, and most mask typed input by default. Settings can be changed, though, and some custom fields may not be recognised. Exclude payment and account pages entirely and test what is captured before relying on it.

How many session recordings should I watch?

Enough to see patterns, which is usually 15 to 30 sessions filtered around one specific question. Watching hundreds at random wastes time and tends to highlight odd one-off visits. Use analytics or heatmaps to choose where to look, then use recordings to understand why.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.