Glossary · Tracking technology
What is first-party proxy?
A first-party proxy is a setup where the analytics script and the endpoint it reports to are served from your own domain — through a rewrite, reverse proxy or CDN rule — so the browser treats the requests as first-party instead of calls to a third-party analytics domain.
Also called: Analytics proxy, Reverse proxy for analytics, Custom domain tracking
Updated
How does a first-party proxy work?
yoursite.com/a/tracker.js → vendor.com/tracker.js yoursite.com/a/api/collect → vendor.com/api/collect (forward X-Forwarded-For)
Instead of loading https://analytics-vendor.com/script.js, your page loads https://yoursite.com/a/script.js. Your server or CDN forwards that request, and the script's data requests to /a/collect, to the vendor. Most frameworks and hosts support this with a rewrite rule (Next.js rewrites, Netlify and Vercel redirects, Cloudflare Workers, Nginx proxy_pass).
Why use a first-party proxy?
- Fewer blocked requests. Many blocklists match on known analytics domains; a request to your own domain often isn't matched.
- Content Security Policy. One less external origin to allow.
- Cookie lifetime. Some browsers treat cookies set via server responses on your domain more favorably than script-set ones.
The IP-forwarding catch
Through a proxy, every request reaches the vendor from your server's IP address. Unless the proxy forwards the visitor's real IP (typically in X-Forwarded-For), country detection breaks, bot filtering sees one IP for everyone, and IP-based cookieless hashing merges all visitors into one. Test with a VPN after setting it up.
Is proxying analytics ethical?
Proxying changes where requests go, not what's collected — so it's only as respectful as the analytics behind it. Routing privacy-preserving, first-party analytics through your own domain is common practice. Using a proxy to sneak invasive third-party tracking past a visitor's explicit choice (an ad blocker, or a refused consent banner) is not, and doesn't change your legal obligations.
First-party proxy with VisitTrack
The VisitTrack script sends events to the same origin it was loaded from (<script origin>/api/collect), so serving /tracker.js and /api/collect through a rewrite on your own domain makes both first-party; session replays, if enabled, load /replay.js from that origin too. There's no dedicated proxy guide in the docs yet, so treat it as an advanced setup: make sure your proxy passes the visitor's IP in X-Forwarded-For (VisitTrack reads the first entry), or locations, bot filtering and cookieless counting will be wrong. If your site sends a Content-Security-Policy, see the install guide.
Frequently asked questions
Does a proxy make analytics immune to ad blockers?
It reduces blocking, because many blockers match on known third-party analytics domains, but it doesn't guarantee anything. Some blockers also match script file names or request patterns, and users can block any request they like.
Does a first-party proxy remove the need for cookie consent?
No. Consent rules depend on what is stored on or read from the device and what data is processed, not on which domain serves the script.
Related terms
- Ad blockers (and analytics)Ad blockers are browser extensions and built-in browser features that stop ads and tracking requests from loading; most also block popular analytics scripts, so visitors using them disappear from client-side analytics entirely.
- Server-side trackingServer-side tracking is sending analytics or conversion events from your own server to the analytics or ad platform, instead of (or in addition to) from a script running in the visitor's browser.
- First-party vs third-party cookiesA first-party cookie is set by the website you are visiting, under its own domain; a third-party cookie is set by a different domain embedded in that page — such as an ad network or social widget — and can follow you across every site that embeds it.
- Cookieless trackingCookieless tracking is web analytics that counts visitors without storing any identifier on the visitor's device — no cookies, localStorage or similar — typically by deriving a short-lived anonymous id on the server instead.
- Bot trafficBot traffic is any website visit made by automated software rather than a person — search crawlers, AI crawlers, uptime monitors, scrapers, headless browsers and spam bots.
Tools and guides
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.