The SDK builds the visitor and the session on its own, and sends them with every recommendation request and every signal. You don’t code any of it: you create the instance and you’re done.

What you need to do

With the SDK, just create the instance. The visitor_id, the session_id and the browser context travel on their own with every tryGetRecommendations and every track.*.
If your store asks for cookie consent, one option:
With the API, without the SDK, send the visitor you generate in the visitor field of the request and of every signal:

What travels

What CrossUp uses it for

With the visitor and the session, CrossUp follows each shopper’s journey through your store: which pages they view, which products they look at, add or remove from the cart, which campaign brought them, how long the visit lasts and whether they come back days later. With that journey SalesPilot learns what to recommend to whom and when, ties every click and every purchase to the recommendation that produced it, and measures attributed sales order by order. No personal data ever travels. The visitor is a random id: not an email, a phone number or your platform’s customer id, and the context only describes the browser.

Report signals

Signals travel with the same visitor.

Signals and attribution

How that journey turns into measured sales.