Privacy & data7 min read

What visitor identification actually matches

Vendor demos show 80 to 90 percent company match. Production traffic runs 30 to 65. The gap is not a bug, it is the sales process working as designed.

Warmly published production match rates from more than 9 million monthly visits across over 1,600 organizations in March 2026. On US traffic, website visitor identification resolves 30 to 65 percent of visitors at the company level and 5 to 20 percent at the person level. The demo environments those same buyers were shown ran 80 to 90 percent company and 30 to 50 percent person.

So the company-level gap between demo and production is roughly 1.4x, which is survivable. The person-level gap is 3 to 5x, which is not. If you signed a contract on the strength of a demo that named individual visitors, you bought a different product than the one that arrived.

This is not an accusation of fraud. Demo environments run on traffic that is easy to resolve, which is exactly the traffic a demo would naturally use. The distortion is structural, and it means the number you should negotiate on is never the number on the screen.

The gap lives at the person level

Company-level identification answers a modest question: which organization is this session probably coming from. Person-level identification claims to name a human. Those are different technical problems with different failure modes, and vendors routinely blend them into one headline figure.

Warmly's production ranges degrade further as traffic gets harder. International traffic drops to 20 to 40 percent at company level and 3 to 8 percent at person level. Mobile drops to 15 to 30 percent and 2 to 5 percent. For a business whose audience is majority mobile and partly outside the US, the realistic person-level yield is a rounding error, and no vendor selection will change that.

The stale belief here is specific and still everywhere in the category's marketing: that modern tools identify 70 to 80 percent of your visitors. That figure is usually produced by quoting the company-level rate, or by computing against matchable visitors rather than total visitors. Both are technically defensible and neither describes what you will see in your dashboard on a Tuesday.

Your traffic mix decides your match rate

The most useful finding in Warmly's data is that variation by traffic source is larger than variation between vendors. In their sample, company-level match ran:

  • 70 to 85 percent on email-campaign traffic, where the click already carries an identifier you sent.
  • 60 to 75 percent on LinkedIn Ads traffic.
  • 40 to 55 percent on direct traffic.

Now put that next to where B2B traffic actually comes from. Direct accounted for 72.1 percent of visits to Gong, 71.6 percent to HubSpot, 71.1 percent to Outreach and 64.5 percent to Salesforce in Q4 2025. Direct is not a small residual bucket of bookmarks. At the best-instrumented B2B companies in the world it is the majority of traffic, and it is the bucket that identification handles worst.

Which produces the practical rule: forecast your match rate from your own source mix before you evaluate a single vendor. A business whose traffic is mostly email and paid social will get a genuinely useful tool. A business living on direct and organic mobile will pay the same license fee for a fraction of the coverage.

Match rate is the wrong metric anyway

Even a high match rate tells you less than it appears to, because a match rate is computed only over the records that matched. It is structurally blind to the miss rate and it says nothing at all about whether a match was correct.

The accuracy research is bleak. Research conducted by Truthset for CIMM and Go Addressable, benchmarked against two ISPs and an MVPD across roughly a billion IP records, found that commercially sold IP-to-postal linkages are accurate on average 13 percent of the time, and IP-to-email linkages 16 percent. Providers agree with each other on IP-to-postal linkages only 6.4 percent of the time and on IP-to-email only 2.8 percent. Across all providers measured, 77 percent of IP-to-postal linkages scored under 10 percent accuracy.

A separate July 2026 study from Adstra and InterMedia Advertising, reported by Adweek, found that only 23 percent of residential IP addresses reached their intended geographic target. IP is the foundation most B2B identification is built on, and as an identity signal it is closer to a guess than a lookup.

Then there is the denominator problem. Imperva's 2026 Bad Bot Report found automated traffic exceeded 53 percent of all web traffic in 2025, with human traffic down to 47 percent. Before you ask what share of visitors got identified, it is worth asking what share of visitors were people.

What it is genuinely good for

This is not a case for abandoning the category. It is a case for buying it as what it is: a prioritization aid, not a truth source.

Even third-party intent signals, which are weaker than first-party visitor data, hold up in that role. Median precision of topic-based third-party intent was 0.51 across 47 audited deployments, and 62 percent of buyers report that fewer than 70 percent of flagged accounts show corroborating activity within 30 days. And yet intent-prioritized accounts still convert at 21.3 percent versus 8.4 percent. A signal can be noisy and still beat calling in alphabetical order.

The context makes the case sharper. Gartner's survey of 646 B2B buyers, fielded August through September 2025 and published in March 2026, found 67 percent prefer a rep-free experience, and 45 percent used AI tools during a recent purchase. Buyers are researching without talking to you. Knowing which accounts are in the building has real value precisely because they will not announce themselves.

How we wire it, and where we refuse to

On our builds, identity resolution is the single most gated capability in the stack. It requires marketing consent, and it requires a US-location check that fails closed: if the geolocation signal is missing, the answer is no. A visitor whose browser sends Global Privacy Control can never be resolved at all, regardless of stored preferences. That is enforced in the render tree, so there is no code path that reaches the vendor before the conditions are met.

The privacy policy then says so in plain language, including what the technology can infer and the conditions under which it is permitted to run. On our sites those policies run to 23 sections, because a policy that contradicts the code is a factual error and we treat it as one.

The framing matters too. This is first-party intent data: signals your own visitors generate on your own property, used to prioritize your own follow-up. It is not an audience to resell, and we do not build it as one.

So if you are evaluating a vendor, replace the demo with one question: what is your company-level and person-level match rate on my traffic split, source by source, on my mobile share, on my international share. A vendor that will answer that is worth talking to. A vendor that answers with a single blended percentage has told you which number they want you to buy on.

intent dataidentity resolutiondark funnelb2b

Let's talk

Got something worth building?

Whether it's a brand-new site, a rebuild, or a product you can't find off the shelf — let's make it.

Or email hello@spiderdigitalgroup.com · reply within one business day · no pushy sales

Trusted by teams who ship

Belzona Baton RougeAmerica PremierAdvanced Applications SpecialistsPrime CoatSalyers ConstructionPolymer Nation