[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTobsNf8Fcvl7hYoa7crbxKfNoV3O5wbgMNRbB48Xq0I":3,"$fG91H0FDD3CAFuK-YOL8kl5neaXL1I49nQHChF_QgrjE":14},{"slug":4,"locale":5,"title":6,"section":7,"orderIndex":8,"blocks":9,"seoTitle":7,"seoDescription":7,"updatedAt":13},"50-tracking","de","50 — Tracking-Cookie & Klick-Erfassung",null,50,[10],{"type":11,"value":12},"markdown","# 50 — Tracking-Cookie & Klick-Erfassung\n\nDas Tracking-System sorgt dafür, dass ein Klick auf einen Partner-Link später als Conversion dem richtigen Partner zugeordnet wird — auch wenn zwischen Klick und Sale Stunden oder Tage liegen.\n\n## Lebenszyklus eines Klicks\n\n```\n1. Besucher klickt Partner-Link  \n   ┌─────────────────────────────────────────────┐\n   │ \u003Ctenant>.partnerdesk.io\u002Ft\u002F\u003Ccampaign>?       │\n   │   pid=\u003CpartnerId>&sub1=...&utm_source=...   │\n   └─────────────────────────────────────────────┘\n                       │\n                       ▼\n2. TrackingController erfasst Klick\n   - speichert TrackingClick (IP, UA, Referer, UTM, SubIDs)\n   - setzt Cookie pa_tracking (clid, pid, cid, ts)\n   - redirected zur Kampagnen-Landing-URL\n                       │\n                       ▼\n3. Besucher kauft (eventuell Tage später)\n                       │\n                       ▼\n4. Provider sendet Webhook an PartnerDesk\n                       │\n                       ▼\n5. PartnerResolver ordnet Sale dem Partner zu\n   (5-stufige Logik, siehe unten)\n                       │\n                       ▼\n6. Provision wird berechnet + persistiert\n```\n\n## Tracking-Cookie `pa_tracking`\n\n### Inhalt (Base64-encoded JSON)\n\n```json\n{\n  \"clid\": \"uuid-des-clicks\",\n  \"pid\":  \"P-001\",\n  \"cid\":  \"summer-promo-2026\",\n  \"ts\":   1716800000\n}\n```\n\n### Eigenschaften\n\n| Eigenschaft | Wert |\n|-------------|------|\n| **Lifetime** | Aus `Campaign.cookieLifetimeDays` (Default 30 Tage). |\n| **Scope** | Path `\u002F`, Domain = Tenant-Subdomain. |\n| **SameSite** | `Lax` — wirkt bei Cross-Site-Redirects, schützt aber gegen CSRF. |\n| **Secure** | Immer `true` (nur über HTTPS). |\n| **HttpOnly** | `false` — JavaScript kann den Cookie lesen, damit das Tracking-Snippet auf der Tenant-Site Conversions per Postback senden kann. |\n\n### Cookie-Consent\n\nDer Cookie wird **nur gesetzt**, wenn der Besucher in der Kategorie „marketing\" zugestimmt hat (Cookie-Consent-Banner, siehe **[95](95-cookie-consent.md)**).\n\n**Wichtig**: Das **server-seitige Click-Recording** (`TrackingClick`-Datensatz) läuft auch ohne Consent — das ist nicht consent-pflichtig, weil keine Cookies gesetzt werden und die Daten nur aggregiert verwendet werden (TTDSG-konform).\n\n## Die 5-stufige Partner-Auflösung\n\nBei einem eingehenden Webhook entscheidet der `PartnerResolver`, welchem Partner der Sale zugeordnet wird:\n\n| Stufe | Quelle | Bedingung |\n|------:|--------|-----------|\n| **1** | **Customer-Lock** | Customer ist `lifetime`-assigned ODER Kampagne hat `allow_partner_change=false` → bestehende Zuordnung gewinnt **gegen** jeden anderen Hinweis |\n| **2** | **Explicit** | Provider-Webhook enthält `partner_id`, `affiliate_id` o. ä. — Partner muss in selbem Tenant aktiv sein |\n| **3** | **Cookie** | `pa_tracking`-Cookie im Browser, Click-Record noch innerhalb Lifetime |\n| **4** | **Fingerprint** | IP + User-Agent matcht einen Klick innerhalb Cookie-Lifetime |\n| **5** | **Unassigned** | Keine Quelle liefert einen aktiven Partner → TX wird trotzdem persistiert (`STATUS_UNASSIGNED`), Admin kann manuell zuordnen |\n\n## Customer-Lock im Detail\n\nDie wichtigste Eigenschaft: ein einmal zugeordneter Customer kann nicht **versehentlich oder absichtlich** einem anderen Partner zugeschlagen werden, wenn:\n\n- Die Zuordnung als **`lifetime`** markiert ist (häufig: erste Sale → Lifetime).\n- **ODER** die Kampagne `allow_partner_change=false` gesetzt hat.\n\nDamit wird verhindert, dass ein konkurrierender Partner den Endkunden „abgreift\".\n\n## UTM-Parameter & SubIDs\n\nBeim Klick werden zusätzlich aus URL-Parametern erfasst:\n\n- `utm_source`, `utm_medium`, `utm_campaign` — Standard UTM-Felder für Analytics.\n- `sub1`, `sub2`, `sub3` — freie SubIDs für eigene Aufteilung (z. B. nach Landingpage-Variante).\n\nDiese erscheinen in der späteren Transaction als zusätzliche Metadaten.\n\nDetails: **[52 — UTM & SubIDs](52-utm-subid.md)**.\n\n## Tracking-Snippet für Tenant-Site\n\nAuf Tenant-eigener Webseite kann das Tracking via JS-Snippet integriert werden:\n\n```html\n\u003Cscript src=\"https:\u002F\u002F\u003Cslug>.partnerdesk.io\u002Ftracking.js\" async>\u003C\u002Fscript>\n```\n\nDas Snippet bietet ein `window.PartnerTracking`-Objekt mit:\n\n- `getPartnerId()` — aktueller Partner aus Cookie.\n- `getClickId()`.\n- `sendConversion(data, callback)` — manueller Postback für JS-getriebene Conversions (z. B. Newsletter-Anmeldung).\n\nAuch automatische `?pid=`-\u002F`?ref=`-Erkennung aus URL-Parametern beim ersten Seitenaufruf.\n\n## Was wird *nicht* getrackt\n\nPartnerDesk trackt **keine** personenbezogenen Daten in Cookies:\n\n- Kein Vor-\u002FNachname.\n- Keine Email-Adresse.\n- Keine IP im Cookie (IP nur in server-seitigem `TrackingClick`-Datensatz).\n\nDamit ist das Cookie selbst nach DSGVO als **pseudonym** klassifizierbar — was nicht heißt, dass es ohne Consent gesetzt werden darf (ePrivacy\u002FTTDSG fordern Consent für **alle** nicht-essentiellen Cookies).\n\n## Verwandte Kapitel\n\n- **[51 — Attribution-Modelle](51-attribution.md)**\n- **[52 — UTM, Sub-IDs, Fingerprint](52-utm-subid.md)**\n- **[95 — Cookie-Consent](95-cookie-consent.md)**\n- **[58 — Lead-Capture-API (für externe Tools)](..\u002F058-unified-tracking.md)**\n\n---\n\n**Technische Tiefen-Doku**: [`..\u002F001-initial-setup.md`](..\u002F001-initial-setup.md) (TrackingService), [`..\u002F058-unified-tracking.md`](..\u002F058-unified-tracking.md) (PartnerResolver)\n","2026-06-01T21:39:08+02:00",{"data":15},[16,20,24,28,32,36,40,44,48,52,56,60,64,68,72,76,80,84,88,92,96,100,104,108,112,116,120,124,128,132,136,140,141,145,149,153,157,161,165,169,173,177,181,185,189,193,197,201,205,209,213,217,221,225,229,233,237,241,245,249,253,257,261,265,269],{"slug":17,"locale":5,"title":18,"section":7,"orderIndex":19},"01-ueberblick","01 — Kurzüberblick & Architektur",1,{"slug":21,"locale":5,"title":22,"section":7,"orderIndex":23},"02-schnellstart","02 — Schnellstart für neue Tenants",2,{"slug":25,"locale":5,"title":26,"section":7,"orderIndex":27},"03-rollen","03 — Rollen & Berechtigungen",3,{"slug":29,"locale":5,"title":30,"section":7,"orderIndex":31},"10-kampagnen","10 — Kampagnen verwalten",10,{"slug":33,"locale":5,"title":34,"section":7,"orderIndex":35},"11-provisionen","11 — Provisionsmodelle (Tiers & Gruppen)",11,{"slug":37,"locale":5,"title":38,"section":7,"orderIndex":39},"12-mlm","12 — MLM-Struktur & Downline",12,{"slug":41,"locale":5,"title":42,"section":7,"orderIndex":43},"13-bonus","13 — Bonusprogramme",13,{"slug":45,"locale":5,"title":46,"section":7,"orderIndex":47},"14-holdback-reserve","14 — Reifezeit & Reserve (Schutz vor Rückbuchungen)",14,{"slug":49,"locale":5,"title":50,"section":7,"orderIndex":51},"15-programm-bewertungen","15 — Programm-Bewertungen im Marktplatz",15,{"slug":53,"locale":5,"title":54,"section":7,"orderIndex":55},"16-externe-bewertungen","16 — Externe Bewertungen verbinden (Anbieter)",16,{"slug":57,"locale":5,"title":58,"section":7,"orderIndex":59},"17-joint-venture-partner","17 — Joint-Venture-Partner",17,{"slug":61,"locale":5,"title":62,"section":7,"orderIndex":63},"18-vertriebsmitarbeiter","18 — Vertriebsmitarbeiter (VM)",18,{"slug":65,"locale":5,"title":66,"section":7,"orderIndex":67},"19-profitabilitaet","19 — Profitabilität einer Kampagne",19,{"slug":69,"locale":5,"title":70,"section":7,"orderIndex":71},"20-partner-anlegen","20 — Partner anlegen",20,{"slug":73,"locale":5,"title":74,"section":7,"orderIndex":75},"21-partner-status","21 — Partner-Status & Lifecycle",21,{"slug":77,"locale":5,"title":78,"section":7,"orderIndex":79},"22-partner-profile","22 — Partner-Profile & Stammdaten",22,{"slug":81,"locale":5,"title":82,"section":7,"orderIndex":83},"23-customers","23 — Customers (Endkunden)",23,{"slug":85,"locale":5,"title":86,"section":7,"orderIndex":87},"24-partner-merge","24 — Doppelte Partner zusammenführen",24,{"slug":89,"locale":5,"title":90,"section":7,"orderIndex":91},"30-webhooks","30 — Webhook-Übersicht",30,{"slug":93,"locale":5,"title":94,"section":7,"orderIndex":95},"31-stripe","31 — Stripe-Integration",31,{"slug":97,"locale":5,"title":98,"section":7,"orderIndex":99},"32-digistore24","32 — Digistore24-Integration",32,{"slug":101,"locale":5,"title":102,"section":7,"orderIndex":103},"33-copecart","33 — CopeCart-Integration",33,{"slug":105,"locale":5,"title":106,"section":7,"orderIndex":107},"34-ablefy","34 — Ablefy-Integration (vormals elopage)",34,{"slug":109,"locale":5,"title":110,"section":7,"orderIndex":111},"35-easybill","35 — easybill-Integration",35,{"slug":113,"locale":5,"title":114,"section":7,"orderIndex":115},"36-lexoffice","36 — lexoffice-Integration",36,{"slug":117,"locale":5,"title":118,"section":7,"orderIndex":119},"37-custom-webhook","37 — Custom Webhook (Zapier, Make, n8n, eigene Systeme)",37,{"slug":121,"locale":5,"title":122,"section":7,"orderIndex":123},"40-auszahlungen","40 — Auszahlungs-Workflow",40,{"slug":125,"locale":5,"title":126,"section":7,"orderIndex":127},"41-gutschriften","41 — Gutschriften (§14 UStG)",41,{"slug":129,"locale":5,"title":130,"section":7,"orderIndex":131},"42-sepa","42 — SEPA-XML-Export",42,{"slug":133,"locale":5,"title":134,"section":7,"orderIndex":135},"43-stripe-connect","43 — Stripe Connect (Express-Auszahlungen)",43,{"slug":137,"locale":5,"title":138,"section":7,"orderIndex":139},"44-buchhaltung-sync","44 — Externe Buchhaltung-Sync (easybill \u002F lexoffice)",44,{"slug":4,"locale":5,"title":6,"section":7,"orderIndex":8},{"slug":142,"locale":5,"title":143,"section":7,"orderIndex":144},"51-attribution","51 — Attribution-Modelle",51,{"slug":146,"locale":5,"title":147,"section":7,"orderIndex":148},"52-utm-subid","52 — UTM, Sub-IDs & Fingerprint",52,{"slug":150,"locale":5,"title":151,"section":7,"orderIndex":152},"53-werbemittel","53 — Werbemittel: Banner & Coupons",53,{"slug":154,"locale":5,"title":155,"section":7,"orderIndex":156},"54-links-landingpages","54 — Short-Links & Landing-Pages",54,{"slug":158,"locale":5,"title":159,"section":7,"orderIndex":160},"60-marketing-site","60 — Marketing-Site (Apex-Domain)",60,{"slug":162,"locale":5,"title":163,"section":7,"orderIndex":164},"61-popup-widget","61 — Popup-Widget für Tenant-Sites",61,{"slug":166,"locale":5,"title":167,"section":7,"orderIndex":168},"62-cross-promotion","62 — PartnerDesk Cross-Promotion (PartnerDesk empfehlen)",62,{"slug":170,"locale":5,"title":171,"section":7,"orderIndex":172},"63-lead-aff","63 — Lead-Affiliate-Programm (Partner werben Partner)",63,{"slug":174,"locale":5,"title":175,"section":7,"orderIndex":176},"70-notifications","70 — Notification-System",70,{"slug":178,"locale":5,"title":179,"section":7,"orderIndex":180},"71-email-whitelabel","71 — Email-Whitelabel",71,{"slug":182,"locale":5,"title":183,"section":7,"orderIndex":184},"72-email-templates","72 — Email-Templates",72,{"slug":186,"locale":5,"title":187,"section":7,"orderIndex":188},"73-lifecycle-mails","73 — Lifecycle-Mails",73,{"slug":190,"locale":5,"title":191,"section":7,"orderIndex":192},"80-akademie","80 — Akademie: Kurse & Lektionen",80,{"slug":194,"locale":5,"title":195,"section":7,"orderIndex":196},"81-quiz","81 — Quiz-System",81,{"slug":198,"locale":5,"title":199,"section":7,"orderIndex":200},"82-zertifikate","82 — Zertifikate nach Kurs-Komplettierung",82,{"slug":202,"locale":5,"title":203,"section":7,"orderIndex":204},"90-2fa","90 — Two-Factor-Authentication (2FA)",90,{"slug":206,"locale":5,"title":207,"section":7,"orderIndex":208},"91-rate-limiting","91 — Rate-Limiting",91,{"slug":210,"locale":5,"title":211,"section":7,"orderIndex":212},"92-audit-log","92 — Audit-Log",92,{"slug":214,"locale":5,"title":215,"section":7,"orderIndex":216},"93-dsgvo","93 — DSGVO-Tools",93,{"slug":218,"locale":5,"title":219,"section":7,"orderIndex":220},"94-legal","94 — Legal-Pages",94,{"slug":222,"locale":5,"title":223,"section":7,"orderIndex":224},"95-cookie-consent","95 — Cookie-Consent",95,{"slug":226,"locale":5,"title":227,"section":7,"orderIndex":228},"100-billing-plaene","100 — Stripe-Billing-Pläne",100,{"slug":230,"locale":5,"title":231,"section":7,"orderIndex":232},"101-trial","101 — Trial & Subscription-Status",101,{"slug":234,"locale":5,"title":235,"section":7,"orderIndex":236},"102-customer-portal","102 — Stripe Customer-Portal",102,{"slug":238,"locale":5,"title":239,"section":7,"orderIndex":240},"110-superadmin","110 — Plattform-Admin (Superadmin)",110,{"slug":242,"locale":5,"title":243,"section":7,"orderIndex":244},"111-health","111 — Health-Endpoints",111,{"slug":246,"locale":5,"title":247,"section":7,"orderIndex":248},"112-webhook-event-log","112 — Webhook-Event-Log",112,{"slug":250,"locale":5,"title":251,"section":7,"orderIndex":252},"113-failed-messages","113 — Failed-Messages",113,{"slug":254,"locale":5,"title":255,"section":7,"orderIndex":256},"120-pwa-partner","120 — PWA Partner-Portal",120,{"slug":258,"locale":5,"title":259,"section":7,"orderIndex":260},"121-cross-tenant-hub","121 — Cross-Tenant-Hub",121,{"slug":262,"locale":5,"title":263,"section":7,"orderIndex":264},"130-public-api","130 — Public-API (für Tenant-Integratoren)",130,{"slug":266,"locale":5,"title":267,"section":7,"orderIndex":268},"131-outgoing-webhooks","131 — Outgoing-Webhooks",131,{"slug":270,"locale":5,"title":271,"section":7,"orderIndex":272},"132-exports","132 — Datenexporte (CSV, PDF-Report)",132]