Cookiebees
1Capture: Every visit, on your own domain

First-party tracking

Tracking that loads
from your own address.

Safari and ad blockers judge a script by where it comes from. Serve the Cookiebees tag from a path on your own site and it is your site: nothing on a blocker’s list, and a visitor id that lasts 400 days instead of 7.

30-day free trialNo card requiredSet up in minutes

Why does Safari forget my customers after a week?

Is an ad blocker stopping my tracking?

yourstore.com · Networkall first-party
MethodNameTypeStatus
GETyourstore.com/3f9a1c07be/px.js?key=…script200
POSTyourstore.com/3f9a1c07be/t/pv/…page view200
POSTyourstore.com/3f9a1c07be/t/attr/…click ids200
POSTyourstore.com/3f9a1c07be/c/event/…add to cart200

Cookies · yourstore.com

Name

cb_cid

Value

mmc_7f3e…a91

Set by

your server

Expires

in 400 days

Every request goes to your own site. Nothing names a tracker, so there is nothing on a list to block.

Can I serve tracking from my own domain without a developer?

How do I know my own address is really working?

What it is worth

Fewer strangers, fewer sales with no source

A returning iPhone shopper is still the same person

On your own path the visitor id lasts 400 days and the server re-issues it. A buyer who comes back after a week keeps their history and their ad.

Nothing for a blocker to match

No Cookiebees hostname in the page and no DNS record to look up. The tag loads, so the visit and the order keep their source.

No events lost while you switch

Until your address carries real traffic, the snippet loads from our domain and says so. If your rule stops working later, it falls back on its own.

Three addresses, one tag

Same script. The address decides how browsers treat it.

Our domain needs no setup but reads as a third party. A subdomain of yours takes one DNS record. A path on your own site, forwarded to us by one rule, is the strongest: Safari sees your own site, and there is nothing in DNS for anyone to find.

  • Path through Cloudflare, nginx or Next.js middleware, copy-paste rules for each
  • Subdomain: one CNAME, with a certificate issued for your own hostname
  • Shopify on its own cannot carry a path; the setup says so and offers the subdomain
  • The snippet switches to your address once a real request comes through it
Tracking · where it is servednot first-party
Our domainYour subdomainYour own path

The tag on every page

<script src="https://app.cookiebees.io/api/commerce/px.js?key=…" async></script>
Safari reads it asa third party
Visitor id lasts7 days in Safari
Ad-blocker listscan list our hostname
One script tag. Only its address changes, and the snippet moves to the new address once real traffic comes through it.

Cookies put back

When Safari deletes Meta’s cookie, the same value comes back.

Meta’s _fbp and Google’s _ga name the browser to those platforms, and Safari deletes any cookie a script wrote after 7 days. The tag keeps its own copy and writes the same value back on the next page view, so the platform still sees the browser it already knows.

  • Put back a lost cookie: on by default
  • Create one when the platform never did: off by default, for your consent notice to decide
  • On a path, the server also re-issues these cookies at their full life
  • Nothing is written while your consent banner says no
One shopper's browser · yourstore.comcookie present

The cookie

_fbpfb.1.1727712000000.4810293751set
Day 1Meta's pixel sets _fbp
Day 8Safari deletes it: a script wrote it, so it got 7 days
Day 9Next page view: the tag writes the same value back
The same value, not a new one, so Meta still sees the same browser. Nothing is written while your consent banner says no.

Past the blockers

A blocker cannot stop what it cannot recognise.

Blockers work from lists of tracking hostnames. On your own path there is no hostname of ours and no DNS record, only your site. And working means a real request came through your rule in the last 24 hours, not that a form was saved: if it stops, the owner gets one email and the snippets fall back to our domain until it is fixed.

  • A chip in the header: not first-party, stopped, or pages still on the old tag
  • Pages still loading the old tag are listed, with when each was last seen
  • Every tracker path on every address is checked daily against the live server
  • Remove the path and every snippet goes back to our domain
Signal delivery

Third-party pixel

blocked

cdn.some-tracker.com/px.js

ITP · blocker

First-party path · your own domain

arrives

yourstore.com/a7f2k/collect

Attribution coverage

0%

of orders tied to a real source on live stores

The identity lives on the visitor, not the browser - so it survives the wipe.

First-party tracking, on your own site.

Start a workspace and watch it work on your next order or lead, or let us walk you through it.

Switching it on

One rule or one DNS record

Settings, Tracking walks you through it in order, with the exact rule for where your site runs.

  1. 1

    Choose path or subdomain

    A path if your site runs behind Cloudflare, nginx or Next.js. A subdomain if it is a plain Shopify store.

  2. 2

    Create your address

    Type your site, press Create my path. Or name a subdomain such as track.yourstore.com.

  3. 3

    Add the rule or the record

    Paste the forwarding rule where your site is served, or add the CNAME in your DNS.

  4. 4

    Check it, then replace the snippet

    Press Check it works. Then copy the new snippet over the old one, on every page.

Inside the module

What is inside

Each of these is a screen or a switch in Settings, Tracking.

Where it is served

Our domain, your subdomain or your path, compared row by row: DNS, Safari, cookie life, blocker lists

Forwarding rules

Ready rules for a Cloudflare Worker, nginx and Next.js middleware, each complete

Check it works

Proves a request came through your rule, and names the domain your cookies are set on

Identity cookies

Put back a lost _fbp or _ga, and optionally create one, both behind consent

Tracking domain status

Working, stopped or never carried traffic, from the requests that arrived

Pages on the old tag

Every page that still loaded a tag from our domain in the last 7 days

Open Settings, Tracking: the line at the top says where your tag is served from today, judged from the requests that actually arrived.

Where this sits

One of the four steps an order goes through.

Every feature reads the same identity. Open any of them; each has its own page.

Move your tag to your own address

Your site, your address.Your visitors, remembered.

Start on our domain today, then add one rule or one DNS record. The snippet moves itself once your address carries traffic.