# No-JavaScript tracking pixel

> Count pageviews without JavaScript using a 1×1 tracking pixel, with its parameters for page URL and referrer and its limits: pageviews only, no events.

`GET /api/pixel` records a pageview and returns a transparent 1×1 GIF.

```html
<noscript>
  <img src="https://privatusanalytics.com/api/pixel?s=pa_YOURSITEID"
       alt="" width="1" height="1" referrerpolicy="no-referrer-when-downgrade">
</noscript>
```

## Parameters

| Parameter | Required | Meaning |
|---|---|---|
| `s` | Yes | Site id (`pa_…`) |
| `u` | No | Full page URL. Defaults to the request's `Referer` header, which is why the example sets `referrerpolicy` so the browser sends the full URL |
| `r` | No | The page's own referrer (where the visitor came from). URL-encode it |

If your pages are rendered on the server, fill `u` and `r` in yourself:

```erb
<noscript>
  <img src="https://privatusanalytics.com/api/pixel?s=pa_YOURSITEID&u=<%= CGI.escape(request.original_url) %>&r=<%= CGI.escape(request.referer.to_s) %>" alt="" width="1" height="1">
</noscript>
```

Query parameters in `u` are minimized exactly like tracker hits: only UTM
parameters, `ref`, and your allowlisted parameters are kept.

## Limitations

- **Pageviews only.** No events, time on page or scroll depth.
- **Bots and proxies.** Image requests from email clients' image proxies and
  from data centers are filtered as bots. Don't use the pixel to measure
  email opens.
- Visits from the pixel and the JavaScript tracker are counted separately
  only if both run. Inside `<noscript>` they never do.
