Skip to content
Anderson Collaborative

HomeKnowledge BaseCookie Tracking: Definition, Privacy, and Marketing Guide

Cookie Tracking: Definition, Privacy, and Marketing Guide

Cookie tracking uses small files a site or embedded service stores in a browser. First-party cookies belong to the site in the address bar. Third-party cookies belong to other domains. This is general measurement guidance, not legal advice.

Updated September 19, 2026· 8 min read

Cookie tracking uses small files that a website or an embedded service stores in a browser so the site can remember a visit, a preference, or a measurement identifier. Chrome’s cookie help distinguishes two types: first-party cookies, created by the site shown in the address bar, and third-party cookies, created by other sites that the page embeds, such as images, ads, or widgets.

This article describes current browser and analytics behavior from official vendor documentation. It is not legal advice. Privacy, consent, and retention rules vary by country, state, and sector. Record purpose, consent, retention, and access with counsel before you enable a cookie.

The next reporting and analysis decision should state how cookie availability affected the numbers. Related measurement topics include event tracking, conversion tracking, and first-party data.

When a page loads, the site or an embed can instruct the browser to store a cookie with a name, value, domain, and expiry. On a later request to a permitted domain, the browser may send that cookie back. That is how a site recognizes a returning browser, keeps a login, or stitches analytics hits.

Cookies cannot open files on the device. They can still identify a browser across visits on that site, and third-party cookies can, when allowed, identify activity across sites.

TypeSet byCommon usesCross-site tracking
First-partyThe site in the address barLogins, preferences, on-site analyticsLimited to that site’s context
Third-partyAnother domain embedded on the pageAds, audience tools, some embedsCan follow activity across sites when the browser allows it

What major browsers currently do

Browser rules are not identical. Do not describe a single “cookieless internet.”

Chrome. Users can allow or block third-party cookies in Privacy and Security settings, add site exceptions, and delete cookies. Incognito blocks third-party cookies by default. On 22 April 2025, Chrome said it would maintain that existing user choice and would not roll out a new standalone prompt for third-party cookies. That followed the 22 July 2024 decision not to deprecate third-party cookies for everyone. Privacy Sandbox APIs remain available as optional tools. Sites should still work when a user blocks third-party cookies.

Firefox. Enhanced Tracking Protection blocks known cross-site tracking cookies by default. In Standard mode, Total Cookie Protection confines cookies to the site that created them. Strict mode blocks all cross-site cookies, which can break some logins and embeds. See also Firefox’s third-party trackers article.

Safari. Prevent cross-site tracking is designed to stop third-party content providers from tracking people across sites. Unless you visit and interact with that provider as a first-party site, Safari deletes their cookies and website data. On iPhone, Safari limits third-party cookies and data by default. Blocking all cookies is a stronger setting and can break sites.

Google Analytics 4’s website cookie documentation says the GA4 tags use first-party _ga and _ga_ cookies with a default expiration of two years, and that browsers cap lifespan if the user does not return: a maximum of 400 days in Chrome and 7 days in Safari. GA4 libraries can send data without you setting extra cookies, but identity durability still depends on the browser.

Server-side tagging is not cookieless

Google’s introduction to server-side tagging describes a container that runs on a server you control, receiving events from the browser or app and forwarding them. That can improve control, first-party collection, and page performance. It does not mean measurement no longer uses cookies. It does not restore every audience, attribution, or cross-site identifier that third-party cookies used to provide. Browser limits, consent, ad blockers, and incomplete event design still remove data.

What to collect, and what not to claim

  • Collect the smallest set that supports a stated purpose.
  • Document who can access the data and how long it is kept.
  • Separate on-site functional cookies from advertising cookies in your notices.
  • When reports drop after a browser or consent change, treat the gap as missing observation, not proof that marketing stopped working.

Hand using a laptop beside a cup of coffee and a plate of cookies

Frequently Asked Questions

What exactly are tracking cookies?

Cookies are files a website creates in the browser to save information about a visit. Chrome describes first-party cookies as created by the site in the address bar and third-party cookies as created by other embedded sites. Tracking cookies are the subset used to remember or measure activity across visits or sites.

What is the difference between first-party and third-party cookies?

First-party cookies are set by the site you are visiting. They commonly support login, preferences, and on-site analytics. Third-party cookies are set by another domain, often an ad, analytics, or embed partner, and can be used across sites when the browser allows it.

Did Chrome turn off all third-party cookies?

No. In April 2025 Chrome said it would keep the existing third-party cookie choice in Privacy and Security settings and would not roll out a new standalone prompt. Users can allow or block third-party cookies. Incognito blocks them by default.

Is server-side tagging cookieless?

No. Google describes server-side tagging as processing measurement on a server you control. It can still use first-party cookies and still depends on what the browser and consent setup send. It does not restore every signal lost when third-party cookies are blocked.

Are tracking cookies safe?

Cookies do not read personal files on your device. They can store identifiers and activity the site or partner is allowed to collect. Safety and lawfulness depend on purpose, consent, retention, and access. This page is not legal advice.

PUT THIS KNOWLEDGE TO WORK

NEED MORE HELP?

Talk with our team about applying Cookie Tracking to your marketing.

Get a free marketing audit call