Tracking

First-Party Cookies

In short

First-party cookies are set by the domain you are currently visiting. They store things like logins, shopping carts or tracking IDs for that same website.

Also known as: first-party cookie, first party cookie

First-party cookies are small text files set by the domain shown in the address bar. When you visit example.com, only example.com (and its subdomains) can read these cookies. They remember logins, language settings and shopping carts – and in marketing, mainly tracking IDs that connect one person's visits across multiple page views.

How first-party cookies are set

There are two ways:

  • Via JavaScript in the browser (document.cookie): simple, but more restricted by browsers like Safari.
  • Via an HTTP header from your own domain's server: more robust, because the browser treats them as real server cookies.

The Meta Pixel also sets a first-party cookie on your domain with _fbp, and it stores the fbclid as _fbc.

First-party vs. third-party cookies

Third-party cookies come from a different domain, such as an ad network embedded on many websites. They enable tracking across websites and are blocked by default in Safari and Firefox. First-party cookies still work, but they're limited to your own website.

Example

A user clicks a Meta ad on Monday, looks at the landing page and leaves. On Thursday they come back directly and fill out the form. The lead can only be attributed to the original campaign if a first-party cookie with Monday's ID still exists. If Safari deleted the cookie after 7 days and the user returns after 10 days, the cookie-based connection is gone.

First-party cookies in lead generation

For leads with long decision cycles, a cookie alone often isn't enough. It's more robust to also match the lead to an earlier session via email address or phone number.

That's why LeadMetrics matches leads to sessions not only by session ID but also by email and phone number, up to 90 days back. Depending on your plan, you can also use a custom tracking domain via CNAME so that lead tracking runs on a subdomain of your website.

Common mistakes

  • Ignoring consent: In the EU, first-party marketing cookies usually require consent too.
  • Assuming long lifetimes: If you plan around a 90-day cookie lifetime, you underestimate how many browsers cut it short.
  • Domain changes in the funnel: If the user moves from your website to a funnel on another domain, the cookie doesn't apply there – that's where cross-domain tracking helps.

Ready for better tracking?

Try LeadMetrics free for 10 days and see which campaigns actually drive revenue.
Start a 10 day trial

Frequently asked questions

Strictly necessary cookies, such as for logins or shopping carts, usually don't. In the EU, analytics and marketing cookies generally require consent – whether first party or third party. Get legal advice for your specific case.

Guides on this topic

Related terms

All terms