A tracking pixel is a small piece of code on a web page or in an email that sends information to an analytics or advertising company when it loads, so that company knows a page was viewed, an email was opened or an action was taken. The name comes from the original technique: a transparent image one pixel square, invisible to the reader.
How a tracking pixel works
In its simplest form the pixel is an image request. When the browser or email app fetches the image, the request carries information to the server: the page address, the time, the device and browser, and often an identifier. In an email, the image address contains a code unique to the recipient, so the sender knows that particular person opened it.
On websites, “pixel” now usually means a JavaScript tag that does far more, such as the Meta Pixel, the TikTok Pixel or the LinkedIn Insight Tag. These scripts read and set cookies, record events such as add to cart or lead, and send them with identifiers the platform can match to its users. That matching is what makes website custom audiences and conversion-optimised campaigns possible.
Because pixels run in the visitor’s browser, they are affected by ad blockers, browser privacy features such as Safari’s Intelligent Tracking Prevention, and consent choices. That is why platforms now pair them with server-to-server connections such as Meta’s Conversions API, using a shared event ID so the same purchase is not counted twice.
Why it matters
For advertisers, the pixel is the feedback loop. Meta and other platforms bid automatically for people likely to complete the event you optimise for, and they learn who those people are from the pixel and its server-side partner. A missing or misfiring pixel leaves the algorithm guessing with your budget.
For UK businesses, pixels sit squarely under PECR. The rule on storing or accessing information on a person’s device is not limited to cookies, and the ICO’s guidance names tracking pixels, including those in emails, among the technologies it covers. Advertising pixels are not strictly necessary, so they need consent before they run. The Data (Use and Access) Act 2025 added some exemptions for low-risk uses such as certain analytics, but advertising tracking is not among them; at the time of writing (October 2026), check the ICO’s current guidance for which changes are in force.
Email pixels have also become less reliable. Apple Mail Privacy Protection loads images through Apple’s servers whether or not anyone reads the message, which inflates open rates on most UK lists.
Common mistakes
- Hard-coding the pixel into the site template so it fires before the visitor has made any consent choice.
- Installing it twice, once directly and once through a plugin or tag manager, which doubles every event.
- Sending personal data in event details or page addresses, such as an email address in a thank-you page URL.
- Leaving pixels from old agencies or abandoned platforms running, collecting data for nobody’s benefit.
- Judging email campaigns on open rate when pixel-based opens are inflated.
How to act on it
List every pixel on your site. Meta Pixel Helper, Google’s Tag Assistant and the network tab in your browser’s developer tools will show what loads. Remove anything you no longer use. Load the rest through a tag manager connected to your consent platform, so each pixel fires only for the category the visitor accepted.
Then test it. Decline cookies in a private window and confirm the advertising pixels stay silent; accept, complete a test action and confirm each event reaches the platform once. Add a server-side connection where the platform offers one, passing the consent status with it. Setting this up properly is part of how I run Facebook and Instagram ads management, because campaign results depend on it.
