First-party tracking
Tracking that loads
from your own address.
Safari and ad blockers judge a script by where it comes from. Serve the Cookiebees tag from a path on your own site and it is your site: nothing on a blocker’s list, and a visitor id that lasts 400 days instead of 7.
30-day free trialNo card requiredSet up in minutes
Why does Safari forget my customers after a week?
Is an ad blocker stopping my tracking?
Cookies · yourstore.com
Name
cb_cid
Value
mmc_7f3e…a91
Set by
your server
Expires
in 400 days
Can I serve tracking from my own domain without a developer?
How do I know my own address is really working?
What it is worth
Fewer strangers, fewer sales with no source
A returning iPhone shopper is still the same person
On your own path the visitor id lasts 400 days and the server re-issues it. A buyer who comes back after a week keeps their history and their ad.
Nothing for a blocker to match
No Cookiebees hostname in the page and no DNS record to look up. The tag loads, so the visit and the order keep their source.
No events lost while you switch
Until your address carries real traffic, the snippet loads from our domain and says so. If your rule stops working later, it falls back on its own.
Three addresses, one tag
Same script. The address decides how browsers treat it.
Our domain needs no setup but reads as a third party. A subdomain of yours takes one DNS record. A path on your own site, forwarded to us by one rule, is the strongest: Safari sees your own site, and there is nothing in DNS for anyone to find.
- Path through Cloudflare, nginx or Next.js middleware, copy-paste rules for each
- Subdomain: one CNAME, with a certificate issued for your own hostname
- Shopify on its own cannot carry a path; the setup says so and offers the subdomain
- The snippet switches to your address once a real request comes through it
The tag on every page
<script src="https://app.cookiebees.io/api/commerce/px.js?key=…" async></script>Cookies put back
When Safari deletes Meta’s cookie, the same value comes back.
Meta’s _fbp and Google’s _ga name the browser to those platforms, and Safari deletes any cookie a script wrote after 7 days. The tag keeps its own copy and writes the same value back on the next page view, so the platform still sees the browser it already knows.
- Put back a lost cookie: on by default
- Create one when the platform never did: off by default, for your consent notice to decide
- On a path, the server also re-issues these cookies at their full life
- Nothing is written while your consent banner says no
The cookie
Past the blockers
A blocker cannot stop what it cannot recognise.
Blockers work from lists of tracking hostnames. On your own path there is no hostname of ours and no DNS record, only your site. And working means a real request came through your rule in the last 24 hours, not that a form was saved: if it stops, the owner gets one email and the snippets fall back to our domain until it is fixed.
- A chip in the header: not first-party, stopped, or pages still on the old tag
- Pages still loading the old tag are listed, with when each was last seen
- Every tracker path on every address is checked daily against the live server
- Remove the path and every snippet goes back to our domain
Third-party pixel
blocked
cdn.some-tracker.com/px.js
First-party path · your own domain
arrives
yourstore.com/a7f2k/collect
Attribution coverage
0%
of orders tied to a real source on live stores
First-party tracking, on your own site.
Start a workspace and watch it work on your next order or lead, or let us walk you through it.
Switching it on
One rule or one DNS record
Settings, Tracking walks you through it in order, with the exact rule for where your site runs.
- 1
Choose path or subdomain
A path if your site runs behind Cloudflare, nginx or Next.js. A subdomain if it is a plain Shopify store.
- 2
Create your address
Type your site, press Create my path. Or name a subdomain such as track.yourstore.com.
- 3
Add the rule or the record
Paste the forwarding rule where your site is served, or add the CNAME in your DNS.
- 4
Check it, then replace the snippet
Press Check it works. Then copy the new snippet over the old one, on every page.
Inside the module
What is inside
Each of these is a screen or a switch in Settings, Tracking.
Where it is served
Our domain, your subdomain or your path, compared row by row: DNS, Safari, cookie life, blocker lists
Forwarding rules
Ready rules for a Cloudflare Worker, nginx and Next.js middleware, each complete
Check it works
Proves a request came through your rule, and names the domain your cookies are set on
Identity cookies
Put back a lost _fbp or _ga, and optionally create one, both behind consent
Tracking domain status
Working, stopped or never carried traffic, from the requests that arrived
Pages on the old tag
Every page that still loaded a tag from our domain in the last 7 days
Open Settings, Tracking: the line at the top says where your tag is served from today, judged from the requests that actually arrived.
Where this sits
One of the four steps an order goes through.
Every feature reads the same identity. Open any of them; each has its own page.
1Capture
Every visit, on your own domain.
2Understand
First click to delivered order.
3Send back
Real revenue back to the ads.
4Act
Turn it into the next sale.
Move your tag to your own address
Your site, your address.Your visitors, remembered.
Start on our domain today, then add one rule or one DNS record. The snippet moves itself once your address carries traffic.