How a cookie works
A cookie is a key-value pair the browser stores locally and attaches automatically to HTTP requests for the matching domain.
The simplified cycle:
1. The visitor opens the site for the first time.
2. The server responds with the header Set-Cookie: user_id=abc123; Max-Age=2592000; Secure.
3. The browser stores the cookie.
4. On the next request to the same domain the browser adds Cookie: user_id=abc123 by itself.
5. The server identifies the visitor and serves personalized content.
The attributes that matter
| Attribute | Meaning | Why it exists |
|---|---|---|
Max-Age / Expires |
Lifetime | A cookie with no lifetime is a session cookie, dropped when the browser closes |
Secure |
HTTPS only | Protects against interception over an unencrypted connection |
HttpOnly |
Not readable from JS | Protects against XSS — document.cookie cannot see it |
SameSite=Strict/Lax |
Cross-site sending policy | Protects against CSRF |
Domain |
Which domain it belongs to | .example.com covers every subdomain |
Cookies in personalization and A/B testing
For a personalization platform, cookies carry two critical jobs:
1. Anonymous identification. Until the visitor signs in they are anonymous. A cookie ties their views, add-to-cart events and clicks to one profile and makes that history usable for recommendations.
2. Sticky assignment in A/B tests. When groups are allocated, the cookie records the membership: ab_group=variant_b. Delete the cookie and the visitor may end up in a different group, which contaminates the results of the test.
Important: when integrating a personalization platform, make sure its cookie is set as first-party, on the store’s own domain, rather than third-party. Browsers block third-party cookies ever more aggressively and the data will simply drain away.
The decline of cookies, and the alternatives
Safari has blocked third-party cookies since 2020 through ITP, Firefox since 2019, and Chrome has announced plans to phase them out under the Privacy Sandbox. That materially changes the ecosystem of ad attribution and analytics.
For personalization it matters less, because:
– The personalization platform sets a first-party cookie on the store’s domain.
– Signed-in visitors are identified by an ID in the database rather than a cookie.
– LocalStorage is an alternative for session data that never needs to reach the server.