Cookiebees
All pieces
Tracking7 min read

First-party tracking on a path: how to stop losing customers to the seven-day cap

Not a subdomain, not a CNAME - a path on your own root domain. It is the only arrangement Safari treats as genuinely yours, and it is simpler to set up than it sounds.

Signal delivery

Third-party pixel

blocked

cdn.some-tracker.com/px.js

ITP · blocker

First-party path · your own domain

arrives

yourstore.com/a7f2k/collect

Attribution coverage

0%

of orders tied to a real source on live stores

The identity lives on the visitor, not the browser - so it survives the wipe.

If a JavaScript-set cookie lasts seven days and a CNAME subdomain is detected and capped, the only remaining option is for tracking to be served from your actual root domain, by your actual origin, as part of your actual site.

What "on a path" means

Instead of loading a script from a vendor domain, your site loads it from something like yourstore.com/a7f3c2/px.js, and events post back to the same path. To the browser this is not tracking infrastructure at all. It is your website, serving a file, the way it serves everything else.

  • The cookie can be set by the server in a response header, so the JavaScript cap does not apply.
  • There is no third-party domain to match against a blocklist, because there is no third-party domain.
  • The path is random per store, so it cannot be added to a filter list the way a known vendor path can.

How the request actually gets to us

Your origin has to forward that path. There are three normal ways, and which one you use depends on what your site runs on.

  1. 1A Cloudflare Worker, if you are already on Cloudflare. A few lines, no server access needed.
  2. 2A Shopify App Proxy, if you are on Shopify. Configured in the app settings, no code.
  3. 3An nginx location block, if you control your own server.

All three do the same thing: take requests on that path and pass them through, keeping the request first-party from the browser's point of view.

The organisation is resolved from a token inside the request, never from the Host header. That matters because it means the same setup works whether the request arrives via a Worker, a proxy or nginx, and a misconfigured host cannot silently route one store's data into another's.

What you get back

An identifier that survives past seven days, so a customer who buys three weeks after the ad still credits that ad. Journeys that stay whole across sessions instead of fragmenting into strangers. And click ids that are still there at checkout, which is what makes conversions match on the ad platform side.

What it does not fix

It does not defeat a customer clearing their cookies, using a different browser, or buying on a device they have never used before. Nothing does. That is why identity also resolves off the order itself - email, phone, address - so a purchase can be joined to a person even when the browser link is gone entirely.

What to do next

Find out which of the three forwarding options applies to you. If you are on Shopify and Cloudflare, you already have two, and either takes about ten minutes.

Read next

How the visitor id survives checkout, and why so many orders arrive anonymous

Close the loop on your next lead

Transform your brand with signals.Your first order, credited, in ten minutes.

Measurement first, then everything else. Spin up your workspace in minutes and watch the first signal go back on your very first order. 30-day free trial, no card required.