How a cookie works

A cookie is a key-value pair the browser stores locally and attaches automatically to HTTP requests for the matching domain.

The simplified cycle:
1. The visitor opens the site for the first time.
2. The server responds with the header Set-Cookie: user_id=abc123; Max-Age=2592000; Secure.
3. The browser stores the cookie.
4. On the next request to the same domain the browser adds Cookie: user_id=abc123 by itself.
5. The server identifies the visitor and serves personalized content.

The attributes that matter

Attribute Meaning Why it exists
Max-Age / Expires Lifetime A cookie with no lifetime is a session cookie, dropped when the browser closes
Secure HTTPS only Protects against interception over an unencrypted connection
HttpOnly Not readable from JS Protects against XSS — document.cookie cannot see it
SameSite=Strict/Lax Cross-site sending policy Protects against CSRF
Domain Which domain it belongs to .example.com covers every subdomain

Cookies in personalization and A/B testing

For a personalization platform, cookies carry two critical jobs:

1. Anonymous identification. Until the visitor signs in they are anonymous. A cookie ties their views, add-to-cart events and clicks to one profile and makes that history usable for recommendations.

2. Sticky assignment in A/B tests. When groups are allocated, the cookie records the membership: ab_group=variant_b. Delete the cookie and the visitor may end up in a different group, which contaminates the results of the test.

Important: when integrating a personalization platform, make sure its cookie is set as first-party, on the store’s own domain, rather than third-party. Browsers block third-party cookies ever more aggressively and the data will simply drain away.

The decline of cookies, and the alternatives

Safari has blocked third-party cookies since 2020 through ITP, Firefox since 2019, and Chrome has announced plans to phase them out under the Privacy Sandbox. That materially changes the ecosystem of ad attribution and analytics.

For personalization it matters less, because:
– The personalization platform sets a first-party cookie on the store’s domain.
– Signed-in visitors are identified by an ID in the database rather than a cookie.
– LocalStorage is an alternative for session data that never needs to reach the server.