Cookiebees
All pieces
Tracking6 min read

Your "first-party" tracking is still third-party to Safari, and it is being capped

Setting a cookie from JavaScript on your own domain feels first-party. Safari disagrees, and the seven-day cap it applies is quietly eating your attribution.

When purchases actually happen31% land after day 7
Same day41%
Days 1-317%
Days 4-711%
Days 8-1418%
Day 15+13%
A seven-day cookie forgets everyone in the highlighted rows. They come back looking like new visitors, and the ad that found them gets nothing.

There is a widespread and comfortable belief that if a cookie is set on your own domain, it is first-party and therefore safe. It is half true, and the half that is false is expensive.

What actually gets capped

Safari's Intelligent Tracking Prevention does not only look at which domain a cookie belongs to. It looks at how the cookie was created and where the script that created it came from.

  • A cookie written by JavaScript via document.cookie is capped at seven days. It does not matter that the domain is yours.
  • That cap drops to 24 hours when the visitor arrived on a link carrying tracking parameters - which describes essentially every paid click.
  • A CNAME subdomain pointing at a vendor is detected and capped too. That workaround was closed years ago.

So the analytics script on your site, setting a cookie on your domain, is producing an identifier that expires long before most of your customers get round to buying.

Why that matters more than it sounds

A seven-day identifier is fine if everyone buys within seven days. Look at your own time-to-purchase distribution before assuming they do. For most considered purchases a meaningful share of revenue lands after that window, and a large share of paid traffic is under the 24-hour rule rather than the seven-day one.

When the identifier expires, the returning customer looks like a new visitor. The purchase they make gets credited to whatever brought them back that day - usually Direct, or the branded search they were always going to make - and the campaign that actually found them gets nothing.

This is the single most common reason a store's ad platform reports one number and its own analytics reports another. Neither is lying. One of them has a shorter memory.

What survives

Cookies set by the server in an HTTP response header, from a request to your own root domain, are not subject to the JavaScript cap. That is the distinction that matters: not "whose domain" but "who set it, and how".

Getting there means the request has to genuinely reach your domain rather than a vendor's, which is what the next post covers.

What to do next

Check whether your current setup sets its identifier from JavaScript or from a server response. If your tag is a script tag pointing at a vendor domain, it is JavaScript, and it is capped. That is worth knowing before you spend another month arguing with your ad platform about discrepancies.

Read next

First-party tracking on a path: how to stop losing customers to the seven-day cap

Close the loop on your next lead

Transform your brand with signals.Your first order, credited, in ten minutes.

Measurement first, then everything else. Spin up your workspace in minutes and watch the first signal go back on your very first order. 30-day free trial, no card required.