Your "first-party" tracking is still third-party to Safari, and it is being capped
Setting a cookie from JavaScript on your own domain feels first-party. Safari disagrees, and the seven-day cap it applies is quietly eating your attribution.
There is a widespread and comfortable belief that if a cookie is set on your own domain, it is first-party and therefore safe. It is half true, and the half that is false is expensive.
What actually gets capped
Safari's Intelligent Tracking Prevention does not only look at which domain a cookie belongs to. It looks at how the cookie was created and where the script that created it came from.
- A cookie written by JavaScript via document.cookie is capped at seven days. It does not matter that the domain is yours.
- That cap drops to 24 hours when the visitor arrived on a link carrying tracking parameters - which describes essentially every paid click.
- A CNAME subdomain pointing at a vendor is detected and capped too. That workaround was closed years ago.
So the analytics script on your site, setting a cookie on your domain, is producing an identifier that expires long before most of your customers get round to buying.
Why that matters more than it sounds
A seven-day identifier is fine if everyone buys within seven days. Look at your own time-to-purchase distribution before assuming they do. For most considered purchases a meaningful share of revenue lands after that window, and a large share of paid traffic is under the 24-hour rule rather than the seven-day one.
When the identifier expires, the returning customer looks like a new visitor. The purchase they make gets credited to whatever brought them back that day - usually Direct, or the branded search they were always going to make - and the campaign that actually found them gets nothing.
This is the single most common reason a store's ad platform reports one number and its own analytics reports another. Neither is lying. One of them has a shorter memory.
What survives
Cookies set by the server in an HTTP response header, from a request to your own root domain, are not subject to the JavaScript cap. That is the distinction that matters: not "whose domain" but "who set it, and how".
Getting there means the request has to genuinely reach your domain rather than a vendor's, which is what the next post covers.
What to do next
Check whether your current setup sets its identifier from JavaScript or from a server response. If your tag is a script tag pointing at a vendor domain, it is JavaScript, and it is capped. That is worth knowing before you spend another month arguing with your ad platform about discrepancies.
Read next
First-party tracking on a path: how to stop losing customers to the seven-day cap