Email me

Dental website user behaviour analysis: what visitors do, and what you may record

Last reviewed against the regulators’ own text, linked in the sources below.

This is general information, not legal advice.

On this page
  1. What behaviour data can and cannot tell you
  2. Paths and drop-off in GA4
  3. Heatmaps and scroll depth
  4. Session recordings and patient data
  5. Turning what you see into fixes
  6. Sources

Dental website user behaviour analysis means looking at what visitors actually do on your site: which pages they read, where they leave, how far they scroll and what they tap. It shows you where the site loses people, but not why. On a dental site one of its tools, session recording, can capture data about a patient's health, so it needs a data protection decision before anyone switches it on.

Behaviour data is how you check whether you have a site that carries the strategy. Below is what each source shows, and my position on recording.

What behaviour data can and cannot tell you

Behaviour data is the record of actions on the page: page views, clicks, scrolls, form starts. It's good at "where" and poor at "why". It also stops at the edge of the website, so it never sees the phone call to reception the next morning.

QuestionCan behaviour data answer it?Where the answer lives
Which page do visitors leave from?YesGA4 paths and funnels
Do they reach the fees section?YesScroll depth, heatmaps
Do they tap the phone number?Yes, if the tap is tracked as an eventGA4 events
Why did they leave?NoReception notes, patient questions, enquiry calls
Did the visit lead to a booked treatment?No, not on its ownYour practice management system (PMS)

Behaviour data tells you where to look. Bookings tell you whether a change worked.

Paths and drop-off in GA4

GA4 is Google Analytics 4, Google's free analytics tool. Two of its reports do most of the work.

A path exploration shows the sequence of pages or events visitors follow, forwards from a starting page or backwards from an ending point1. Working back from the booking confirmation shows which treatment pages feed it.

A funnel exploration shows the steps towards a goal and how many visitors fall out at each. GA4 allows up to 10 steps, and a visitor who misses a step isn't counted in later ones2.

Drop-off is the share of visitors who leave between one step and the next. The biggest drop is the first page to look at. Building these reports is covered in explorations and funnels in GA4.

Two limits apply. GA4 only sees visitors your cookie setup lets it see; how consent affects what analytics can see covers that. And Google's policy is that nothing it could recognise as personally identifiable reaches it, with its help page warning that page URLs and titles are where this often slips through3. A confirmation URL carrying a patient's email address is one way. Check yours.

Heatmaps and scroll depth

A heatmap is an image of a page coloured by where visitors clicked, tapped or scrolled, added up across many visits. Scroll depth is how far down a page a visitor got.

GA4's enhanced measurement scroll event fires once, when a visitor reaches 90 per cent of the page height4. That shows who reached the bottom, nothing about the middle. Google Tag Manager's scroll depth trigger fires at percentages you choose5, enough to see whether visitors reach the fees on an implant page.

Heatmaps need a separate tool, such as Microsoft Clarity or Hotjar. In both, heatmaps and recordings come from the same script67, so the consent question below applies to heatmaps too.

On a treatment page, checkReportWhat it can reveal
Do visitors reach the price?Scroll depth, scroll mapFees placed too low on the page
Do they tap things that are not links?Click mapText that looks like a button, such as "finance options"
Do they tap the phone number or the booking button?Click map, GA4 eventsWhich route patients prefer on that page
Where does attention stop on a phone?Scroll map on mobileA long introduction pushing the answer out of view

Session recordings and patient data

A session recording is a replay of one visitor's visit: pages, scrolling, taps and mouse movement, rebuilt so you can watch it like a video. It's the most detailed behaviour data there is, which is the problem on a dental site.

My position: I do not switch on session recording until the practice has made a written data protection decision, and I never record a visitor who has not agreed to it.

PECR. The Privacy and Electronic Communications Regulations cover any technology that stores or reads information on a visitor's device. The ICO's guidance, updated 29 April 20268, names scripts, cookies and local storage among them9. The analytics exemption is narrow: the sole purpose must be statistics about how the site is used, to improve it10, and visitors must be told and given a simple, free way to object. In my reading, watching one visit back isn't statistics, so recording needs consent.

UK GDPR special category data. Health data is personal data about physical or mental health, "including the provision of health care services", that reveals someone's health status. The ICO's examples include appointment details11. A recording of someone on your booking page, or typing into a "tell us about your problem" box, sits very close to that line. Special category data needs a lawful basis under Article 6 and a separate condition under Article 9. The ICO says explicit consent must be a clear statement, specify the nature of the data, and be separate from other consents12. An "accept all" cookie click is a weak fit. Whether another Article 9 condition applies is for your data protection adviser, not me.

Risk assessment. The ICO's list of processing likely to result in high risk includes tracking behaviour online, with web tracking as an example13. A data protection impact assessment (DPIA), the written risk assessment UK GDPR expects in such cases, is where this decision belongs.

What the tools do today

Checked against vendor documentation on 1 October 2026.

Microsoft ClarityHotjar
Default maskingBalanced mode: numbers and email addresses masked, other page text shown14User input suppressed; on-page numbers and email addresses suppressed; other text shown unless you turn on text suppression7
Form fieldsInput boxes and drop-downs masked in all modes14Keystrokes suppressed by default7
Page addressesURL parameter masking on request to support; referrer and clicked URLs not masked6Unverified
Without consentConsent signals enforced for UK visitors from 31 October 2025. With no consent, no cookies, but page views and basic interactions are still collected156Help pages point you to stopping the tracking code loading until a visitor accepts16
Recording retention30 days; favourites and a random sample up to 9 months6365 days17

Two rows matter most. Clarity's default shows the words on the page, and the page address (a dentures page, say) says something about the visitor. And Clarity's consent mode controls cookies, not collection. PECR covers reading from a device as well as storing on it, so I stop the script loading at all until the visitor agrees. Banner and tag setup is on the cookie consent page.

Turning what you see into fixes

A finding is a guess until a change proves it. I make one change at a time and judge it against booked consultations, not clicks.

What you seePossible cause to testChange to try
Few visitors reach the fees sectionPrice buried under long introductionShort price summary near the top
Taps on "finance options" textVisitors expected a linkLink it to finance details
Funnel drop between booking page and confirmationBooking widget hard to use on a phoneTest the booking on a phone yourself
Paths loop between two treatment pagesVisitors cannot tell the treatments apartA comparison section on both pages
High exits from the contact pageForm asks too much too earlyFewer required fields

Testing changes like these without fooling yourself is covered in conversion rate optimisation for a practice site. Behaviour analysis is one part of what an engagement includes, alongside tracking that joins visits to bookings.

If you want to know how your site's paths, funnels and recording setup hold up, email me at Fayez@imfayez.com with your web address. The first look is free: I go through your site's key paths from the outside and reply with what I find. You can read how I work first.

Sources

  1. Google Analytics Help: Path exploration, accessed 1 October 2026. ↩

  2. Google Analytics Help: Funnel exploration, accessed 1 October 2026. ↩

  3. Google Analytics Help: Best practices to avoid sending personally identifiable information, accessed 1 October 2026. ↩

  4. Google Analytics Help: Enhanced measurement events, accessed 1 October 2026. ↩

  5. Tag Manager Help: Scroll depth trigger, accessed 1 October 2026. ↩

  6. Microsoft Learn: Clarity, frequently asked questions, accessed 1 October 2026. ↩ ↩2 ↩3 ↩4

  7. Hotjar Help: How to suppress text, images, videos and user input from collected data, accessed 1 October 2026. ↩ ↩2 ↩3

  8. ICO: Guidance on the use of storage and access technologies, last updated 29 April 2026, accessed 1 October 2026. ↩

  9. ICO: What are storage and access technologies?, accessed 1 October 2026. ↩

  10. ICO: What are the exceptions?, accessed 1 October 2026. ↩

  11. ICO: What is special category data?, last updated 9 April 2024, accessed 1 October 2026. ↩

  12. ICO: What are the conditions for processing?, last updated 18 December 2023, accessed 1 October 2026. ↩

  13. ICO: Examples of processing likely to result in high risk, accessed 1 October 2026. ↩

  14. Microsoft Learn: Clarity, masking content, accessed 1 October 2026. ↩ ↩2

  15. Microsoft Learn: Clarity, Consent Mode, accessed 1 October 2026. ↩

  16. Hotjar Help: Cookies set by the Hotjar tracking code, accessed 1 October 2026. ↩

  17. Hotjar Help: Privacy FAQs, accessed 1 October 2026. ↩