Given that web industry uses no-server-state for *authentication* (with all the issues it implies), i would expect tracking also be no-server-state.