First-party tracking on a path: how to stop losing customers to the seven-day cap
Not a subdomain, not a CNAME - a path on your own root domain. It is the only arrangement Safari treats as genuinely yours, and it is simpler to set up than it sounds.
Third-party pixel
blocked
cdn.some-tracker.com/px.js
First-party path · your own domain
arrives
yourstore.com/a7f2k/collect
Attribution coverage
0%
of orders tied to a real source on live stores
If a JavaScript-set cookie lasts seven days and a CNAME subdomain is detected and capped, the only remaining option is for tracking to be served from your actual root domain, by your actual origin, as part of your actual site.
What "on a path" means
Instead of loading a script from a vendor domain, your site loads it from something like yourstore.com/a7f3c2/px.js, and events post back to the same path. To the browser this is not tracking infrastructure at all. It is your website, serving a file, the way it serves everything else.
- The cookie can be set by the server in a response header, so the JavaScript cap does not apply.
- There is no third-party domain to match against a blocklist, because there is no third-party domain.
- The path is random per store, so it cannot be added to a filter list the way a known vendor path can.
How the request actually gets to us
Your origin has to forward that path. There are three normal ways, and which one you use depends on what your site runs on.
- 1A Cloudflare Worker, if you are already on Cloudflare. A few lines, no server access needed.
- 2A Shopify App Proxy, if you are on Shopify. Configured in the app settings, no code.
- 3An nginx location block, if you control your own server.
All three do the same thing: take requests on that path and pass them through, keeping the request first-party from the browser's point of view.
The organisation is resolved from a token inside the request, never from the Host header. That matters because it means the same setup works whether the request arrives via a Worker, a proxy or nginx, and a misconfigured host cannot silently route one store's data into another's.
What you get back
An identifier that survives past seven days, so a customer who buys three weeks after the ad still credits that ad. Journeys that stay whole across sessions instead of fragmenting into strangers. And click ids that are still there at checkout, which is what makes conversions match on the ad platform side.
What it does not fix
It does not defeat a customer clearing their cookies, using a different browser, or buying on a device they have never used before. Nothing does. That is why identity also resolves off the order itself - email, phone, address - so a purchase can be joined to a person even when the browser link is gone entirely.
What to do next
Find out which of the three forwarding options applies to you. If you are on Shopify and Cloudflare, you already have two, and either takes about ten minutes.
Read next
How the visitor id survives checkout, and why so many orders arrive anonymous