Full Answer
Safari ITP specifically targets cookies set by JavaScript through document.cookie because this is the mechanism third-party tracking scripts use. GA4, Meta Pixel, and most tracking tags set their cookies this way — which is why Safari restricts them to seven days.
Server-set cookies use a different mechanism. When a browser requests a page from your domain, the server can include a Set-Cookie header in the HTTP response. These cookies are created by the server, not by JavaScript executing in the browser. Safari applies fewer restrictions to server-set cookies from genuine first-party origins because they represent a legitimate relationship between the user and the website operator.
The implementation requires server-side infrastructure. A first-party server — running on a subdomain you own and control, with its own IP address and server configuration — responds to tracking requests and sets cookies via HTTP headers. When a visitor lands on your WooCommerce store, the first-party server sets an identification cookie with a 400-day lifespan. On subsequent visits, even weeks later, the cookie persists and the visitor is recognized as a returning user.
CNAME cloaking is the approach to avoid. Some tracking solutions point a subdomain via CNAME record to a third-party tracking domain like a GTM server container. Safari and Firefox both detect this pattern and apply third-party cookie restrictions to CNAME-cloaked subdomains. The workaround collapsed because browsers learned to trace the DNS resolution chain.
The genuine first-party approach works because there is nothing to detect — the server is real infrastructure on your domain, not a redirect to someone else's. The cookies it sets are legitimate first-party cookies by every technical definition.