How a third-party cookie works
When you open a shop’s website, the page may load resources from dozens of outside domains:
advertising pixels, analytics scripts, widgets. Every one of those scripts can set a cookie under
its own domain.
The user visits: shoes.com, sport.com, fashion.com
The ads.net pixel loads on all three sites
The ads.net cookie: user_id=XYZ (the same ID every time)
Result: ads.net knows the user's full path across three sites
That is exactly what allowed ad networks to run follow-me advertising — retargeting based on the
sites a person had visited.
The blocking timeline
| Browser | When | What happened |
|---|---|---|
| Safari (ITP) | 2017–2019 | Full blocking after 7 days, then after 24 hours |
| Firefox | 2019 | Enhanced Tracking Protection on by default |
| Chrome | 2024 onwards | Gradual restriction, with dates repeatedly moved |
Safari holds roughly 20% of the browser market — a significant share of the iOS audience is already
out of reach for cross-site tracking.
The effect on e-commerce personalization
Personalization platforms that run on first-party data — on-site behaviour, purchase history,
explicit preferences — do not depend on the fate of the third-party cookie. Personalization built on
your own data is more precise than retargeting through outside networks: the signal added to cart
but did not buy is known to the shop itself, not to the ad network.
Important: the move to first-party data is not a stopgap but a structural advantage. A shop
that has accumulated its own user profiles holds an asset competitors cannot copy.
What changes in attribution
Advertising attribution was historically built on third-party cookies: the system could see that a
user clicked an advert on one site and bought on another. Without cross-site tracking, attribution
becomes incomplete. For e-commerce that means moving to server-side tracking and matching data
through first-party identifiers.