Glossary · Privacy & compliance

What are first-party vs third-party cookies?

A first-party cookie is set by the website you are visiting, under its own domain; a third-party cookie is set by a different domain embedded in that page — such as an ad network or social widget — and can follow you across every site that embeds it.

Also called: First-party cookie, Third-party cookie

Updated

How first-party and third-party cookies differ

First-partyThird-party
Set byThe site in the address barAnother domain loaded on the page
Readable onThat site (and its subdomains)Every site that embeds the third party
Typical usesLogin sessions, carts, preferences, first-party analyticsCross-site ad targeting, retargeting, cross-site measurement
Safari / FirefoxAllowed, but script-set cookies capped by Safari (7 days)Blocked by default
Chrome (as of October 2026)AllowedStill allowed; Google dropped its phase-out plan

Where browsers stand

Safari has blocked third-party cookies by default since 2020 and Firefox's Total Cookie Protection partitions them by site. Chrome planned to remove them, then reversed course: in April 2025 Google said it would keep them and not introduce a separate choice prompt, and in October 2025 it retired most Privacy Sandbox APIs. Safari's Intelligent Tracking Prevention also limits first-party cookies set by JavaScript (document.cookie) to 7 days, or 24 hours in some link-decoration cases.

Example

You visit example.com, which sets a session cookie to keep you logged in (first-party) and loads an ad tag from ads.example-network.com, which sets an id cookie (third-party). When you later visit a news site that loads the same ad tag, the network reads its id cookie again and knows it's you — that cross-site recognition is what third-party cookies enable and what browsers restrict.

Why the distinction matters for analytics

  • Analytics using first-party cookies works in all major browsers; analytics relying on third-party cookies breaks in Safari and Firefox.
  • Under the EU's ePrivacy rules, both generally need consent unless strictly necessary — first-party doesn't mean exempt.
  • Under the UK's PECR, since February 2026 there's an exception for cookies used only for statistical purposes, provided users get clear information and a simple way to object.
  • Safari's 7-day cap means a returning visitor after a week may be counted as new even with first-party cookies.

Which cookies does VisitTrack use?

VisitTrack never uses third-party cookies. In standard mode it sets one first-party cookie, _vt_vid, on your own root domain (mirrored to localStorage) holding a random anonymous visitor id, so www. and app. share visitors. In cookieless mode it stores nothing at all, and hybrid mode stores nothing for visitors in the EU/EEA, UK and Switzerland. See script configuration.

Frequently asked questions

Are first-party cookies exempt from GDPR consent?

No. In the EU, the ePrivacy Directive requires consent to store non-essential cookies whether they're first- or third-party; analytics cookies usually aren't considered strictly necessary. Some national regulators allow narrow exemptions for audience measurement.

Is Chrome still removing third-party cookies?

No. Google announced in 2025 that Chrome would keep third-party cookies and later retired most Privacy Sandbox APIs. Safari and Firefox continue to block or partition them by default.

Related terms

Tools and guides

See which channels actually bring paying customers

VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.