Full Answer
The root problem is session isolation. Instagram and TikTok embed a WebView — a stripped-down browser inside the app — rather than handing the URL to Safari or Chrome. That WebView maintains its own cookie storage, local storage and JavaScript context. Any tracking cookie set by GA4, Meta Pixel or a server-side endpoint lives only inside that WebView. The moment the visitor closes the app and reopens the site in their default browser, those cookies are gone.
Click identifiers compound the problem. The fbclid or ttclid attached to the ad URL gets read and stored inside the in-app browser session. When the visitor returns via Safari, there is no stored click ID to match the conversion back to the ad. Safari's Link Tracking Protection may strip the identifier from the URL entirely if the visitor copies and pastes the link. The result is a conversion that WooCommerce records but that Meta or TikTok Ads Manager never attributes — it falls into the direct or organic bucket instead.
Server-side tracking mitigates this by capturing the click identifier at the server level on the initial landing page request, before the in-app browser's cookie jar becomes relevant. Storing the click ID in a first-party HTTP cookie set from your own domain gives it a better chance of surviving the browser switch. For the broader context on how these gaps compound, see [Ad blocking didn't peak — 1.77 billion users entrenched in 2026](https://seresa.io/blog/data-loss/ad-blocking-didnt-peak-1-77-billion-users-entrenched-in-2026).