Glossary · Privacy & compliance
What are first-party vs third-party cookies?
A first-party cookie is set by the website you are visiting, under its own domain; a third-party cookie is set by a different domain embedded in that page — such as an ad network or social widget — and can follow you across every site that embeds it.
Also called: First-party cookie, Third-party cookie
Updated
How first-party and third-party cookies differ
| First-party | Third-party | |
|---|---|---|
| Set by | The site in the address bar | Another domain loaded on the page |
| Readable on | That site (and its subdomains) | Every site that embeds the third party |
| Typical uses | Login sessions, carts, preferences, first-party analytics | Cross-site ad targeting, retargeting, cross-site measurement |
| Safari / Firefox | Allowed, but script-set cookies capped by Safari (7 days) | Blocked by default |
| Chrome (as of October 2026) | Allowed | Still allowed; Google dropped its phase-out plan |
Where browsers stand
Safari has blocked third-party cookies by default since 2020 and Firefox's Total Cookie Protection partitions them by site. Chrome planned to remove them, then reversed course: in April 2025 Google said it would keep them and not introduce a separate choice prompt, and in October 2025 it retired most Privacy Sandbox APIs. Safari's Intelligent Tracking Prevention also limits first-party cookies set by JavaScript (document.cookie) to 7 days, or 24 hours in some link-decoration cases.
Example
You visit example.com, which sets a session cookie to keep you logged in (first-party) and loads an ad tag from ads.example-network.com, which sets an id cookie (third-party). When you later visit a news site that loads the same ad tag, the network reads its id cookie again and knows it's you — that cross-site recognition is what third-party cookies enable and what browsers restrict.
Why the distinction matters for analytics
- Analytics using first-party cookies works in all major browsers; analytics relying on third-party cookies breaks in Safari and Firefox.
- Under the EU's ePrivacy rules, both generally need consent unless strictly necessary — first-party doesn't mean exempt.
- Under the UK's PECR, since February 2026 there's an exception for cookies used only for statistical purposes, provided users get clear information and a simple way to object.
- Safari's 7-day cap means a returning visitor after a week may be counted as new even with first-party cookies.
Which cookies does VisitTrack use?
VisitTrack never uses third-party cookies. In standard mode it sets one first-party cookie, _vt_vid, on your own root domain (mirrored to localStorage) holding a random anonymous visitor id, so www. and app. share visitors. In cookieless mode it stores nothing at all, and hybrid mode stores nothing for visitors in the EU/EEA, UK and Switzerland. See script configuration.
Frequently asked questions
Are first-party cookies exempt from GDPR consent?
No. In the EU, the ePrivacy Directive requires consent to store non-essential cookies whether they're first- or third-party; analytics cookies usually aren't considered strictly necessary. Some national regulators allow narrow exemptions for audience measurement.
Is Chrome still removing third-party cookies?
No. Google announced in 2025 that Chrome would keep third-party cookies and later retired most Privacy Sandbox APIs. Safari and Firefox continue to block or partition them by default.
Related terms
- Cookieless trackingCookieless tracking is web analytics that counts visitors without storing any identifier on the visitor's device — no cookies, localStorage or similar — typically by deriving a short-lived anonymous id on the server instead.
- Consent bannerA consent banner, or cookie banner, is the notice a website shows to ask visitors for permission before storing or reading non-essential cookies and similar identifiers on their device, and to record their choice.
- ePrivacy DirectiveThe ePrivacy Directive (Directive 2002/58/EC, amended in 2009) is the EU law on privacy in electronic communications whose Article 5(3) requires consent before storing information on, or reading it from, a user's device — which is why it's called the "cookie law."
- PECRPECR, the Privacy and Electronic Communications Regulations 2003, is the UK law that implements the ePrivacy Directive's rules on cookies and similar technologies, electronic marketing and communications security, enforced by the Information Commissioner's Office (ICO).
- Unique visitorA unique visitor is a distinct person — in practice a distinct browser or device — that visited a website at least once during a given period, counted only once no matter how many pages they viewed or how often they returned.
Tools and guides
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.