Session recording is a tool that captures how individual visitors interact with a website (where they scroll, click, pause and type) so the session can be replayed later as a video-like reconstruction. It shows the behaviour behind the numbers in your analytics.
How session recording works
A script on the page records events rather than filming the screen: mouse movements, taps, scrolls, clicks, page changes and the structure of the page at each moment. The tool then rebuilds the visit, so you watch a visitor’s cursor move across a copy of your page.
Tools such as Microsoft Clarity and Hotjar usually combine recordings with a heatmap, which summarises clicks and scrolling across many visits. They also flag patterns worth watching, such as “rage clicks” (repeated clicks on something that does not respond) and “dead clicks” on elements that look clickable but are not.
The script stores an identifier on the visitor’s device so it can stitch page views into one session, and it can capture whatever appears on the page. Most tools mask typed text by default, but settings vary and can be changed, so check rather than assume.
Why it matters
Analytics tells you that most mobile visitors leave your booking page. A recording can show you why: the date picker will not open on an iPhone, the “Next” button is hidden behind the cookie banner, or people keep tapping a photo that is not a link. These are problems nobody on the team sees, because they use the site on a desktop and know where everything is.
For a UK business, recordings also raise clear privacy obligations. Because the script stores information on the device and can capture personal data, session recording on UK sites normally loads only after the visitor gives consent under PECR, with UK GDPR covering what you then do with the data. Form fields should be masked so names, emails, addresses and anything typed into a message box are never captured, and payment pages should be excluded altogether. Your privacy and cookie notices should name the tool and say what it does. UK law has added a limited consent exemption for some analytics storage, but at the time of writing (October 2026), check current ICO guidance before assuming it covers session recording, which captures far more than visit counts.
Common mistakes
- Installing the tool through a tag manager so it fires before consent.
- Leaving form masking off, or unmasking fields to “see what people type”.
- Recording logged-in account areas where pages show names, addresses and order histories.
- Watching hours of random sessions without a question, then drawing conclusions from the strangest ones.
- Recording every visit indefinitely, rather than for a defined period with a sensible retention setting.
How to act on it
Start with a question your analytics has raised, such as why mobile visitors drop off at step two of the quote form. Filter recordings to sessions that match: mobile, that page, no conversion. Watch 15 to 30, note each obstacle you see, and fix the ones that recur.
Before any of that, set the tool up properly. Connect it to your consent banner so it loads only after the visitor agrees, turn on masking for all inputs, exclude checkout and account pages, set a short retention period, and update your privacy notice. Then check, in a private window and with consent refused, that no recording script loads.
Recordings are one of the first things I look at before a website redesign, because they show which problems the new site has to fix and which parts of the old one people already use well.
