Slightly off topic: Plausible claim that their cookieless tracking is GDPR compliant but this seems a bit shaky to me. Unless they are doing something that isn't specified in their docs their fingerprinting seems reversible which would make their user identifiers PII like any session ID you'd store in a cookie. AIUI the GDPR doesn't particularly care about cookies, it cares about you tracking people without their con…
The GDPR allows for collection and processing without consent for several reasons including (but not limited to) legal requirement (e.g. anti-fraud) and legitimate interests (e.g. app install conversions).
The GDPR is also quite clear that consent is not required to collect _anonymous_ data, i.e. data which in no way can be traced back to the individual, but this requires balancing with the other principles of the regulation. Recital 26 of the GDPR states:
“…The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.”