Privacy & Consent

Third-Party Cookies

In short

Third-party cookies are set by a domain other than the site you are visiting. They enable cross-site tracking and are increasingly blocked by browsers.

Also known as: third-party cookie

Third-party cookies are cookies set not by the website you are visiting but by another domain, typically an ad network. For years they were the backbone of cross-site tracking and retargeting.

How do third-party cookies work?

When a website embeds a script or image from another domain, that domain can set its own cookie in the browser. When the same user later visits a different site with the same script, the third-party domain reads its cookie again. Repeat that across thousands of sites and you get a cross-site profile.

A first-party cookie, by contrast, belongs to the domain being visited and only works there.

What do third-party cookies mean for advertisers?

Third-party cookies are in decline:

  • Safari has fully blocked them by default since 2020 through Intelligent Tracking Prevention.
  • Firefox blocks known tracker cookies with Enhanced Tracking Protection.
  • Chrome postponed deprecation several times and now leans on user choice. Do not build your measurement on it.
  • An ad blocker often stops the scripts from loading in the first place.

On top of that, under the GDPR, third-party cookies for advertising need consent through a cookie banner.

For conversion tracking, the takeaway is simple: the more you depend on third-party cookies, the bigger your signal loss. More resilient options are first-party data, click IDs from the URL and server-side tracking, where events travel directly from server to server.

Example

A user clicks an ad in Safari, reads your blog, comes back directly three days later and buys. The ad platform's third-party cookie was never set in Safari. The conversion can only be attributed if the click ID was stored as first-party information on the first visit and sent along with the purchase.

Third-Party Cookies with LeadSignal

LeadSignal does not rely on third-party cookies. Its script captures click IDs such as gclid, fbclid and ttclid plus UTM parameters on the first visit and works with a first-party identity after consent. For Meta, LinkedIn and TikTok, events can also be sent server-side through each platform's Conversions API. Read why that matters in Server-Side Tracking: Why Your Ad Campaigns Are Flying Blind.

Frequently asked questions

What is the difference between first-party and third-party cookies?+

A first-party cookie is set by the domain you are visiting. A third-party cookie comes from another domain, such as an ad network whose script is embedded on the page.

Is Chrome getting rid of third-party cookies?+

Google postponed full deprecation several times and later dropped the plan in favour of a user-choice approach. Safari and Firefox, however, have blocked third-party cookies by default for years.

Guides on this topic

Articles on this topic

Related terms