Launch offer: the first 1,000 users get Business free. Claim your spot →
All posts
Conversion trackingBy the directinapp team6 min read

First-party vs third-party cookies: what the shift means for your tracking

Third-party cookies are going away, and a lot of ad tracking goes with them. Here is the difference between the two, what actually breaks, and what keeps working.

Chocolate chip cookies on a table
Photo by Taylor Cole on Unsplash

A first-party cookie is set by the website you are actually visiting and remembers you on that site. A third-party cookie is set by another domain, usually an ad or analytics network, and follows you across sites. Browsers are phasing out third-party cookies, which breaks a lot of cross-site tracking while leaving first-party measurement intact.


For years, most online tracking leaned on a quiet piece of infrastructure: the third-party cookie. It is now being switched off across browsers, and a lot of measurement people took for granted is going with it. Knowing which kind of cookie your tracking depends on is the difference between a small adjustment and a broken dashboard.

There are two kinds, and they are not variations of the same thing. They are set by different parties, for different reasons, and only one of them is on the way out.

First-party: the site you are on

A first-party cookie is set by the website in your address bar. It is how a site keeps you logged in, remembers your cart, and counts you as one returning visitor rather than five new ones. It works because the site setting it is the site you chose to visit.

First-party cookies are not going anywhere. Browsers, regulators and users all accept them, because they serve the visit you actually asked for. Measurement built on first-party data is the stable ground to stand on.

Third-party: the domains following you around

A third-party cookie is set by a domain other than the one you are visiting, typically an ad network or tracker embedded in the page. Because the same network is embedded across thousands of sites, its cookie lets it recognise you as you move around the web. That is what powered cross-site retargeting and the ads that seem to follow you.

That same power is why third-party cookies are being killed. They enable tracking across sites the visitor never agreed to, so browsers now block them by default. When they go, cross-site recognition goes with them.

What breaks, what survives

Depends onThird-party cookiesFirst-party + click ids
Cross-site retargetingBreaksNot affected the same way
View-through attributionBreaks or degradesNever relied on it
Counting your own conversionsWas never neededWorks
Tying a click to a saleFragileReliable

The move to first-party and server-side

The response to the third-party cookie going away is not to find a sneakier cross-site tracker; it is to lean on data you own. First-party measurement and server-side tracking do not depend on a shared cookie following someone across the web. They depend on your own link, your own click id, and your own server confirming the sale.

A click id carried through a link and returned with the conversion is a first-party signal by nature. It ties your click to your sale without ever needing to recognise the same person on another site, which is exactly why it survives the change, the way a postback survives an ad blocker.

Tracking that outlives the cookie

directinapp attributes on a click id and confirms revenue server-side, so it never depended on third-party cookies in the first place. As browsers finish phasing them out, your channel and conversion numbers keep working, because they were built on your own data, not on a tracker following people around the web.

Found this useful? Tell Google to show you more of it.

Add us as a preferred source

Related guides

Put this into practice

Create smart short links that open the right app, with analytics built in. No credit card required.

Start free