Full Answer
Apple's Safari privacy stack has accumulated three distinct but overlapping protection layers, and the naming creates genuine confusion for WooCommerce store operators trying to understand which restrictions apply to their visitors.
ITP launched in 2017 as Safari's first systematic tracking prevention. It uses on-device machine learning to classify domains based on cross-site tracking behaviour, then enforces restrictions: complete third-party cookie blocking since Safari 13.1, a 7-day cap on JavaScript-set first-party cookies, and a 24-hour cap when the visitor arrived via a URL containing tracking parameters like gclid or fbclid from a classified domain. ITP operates silently in the background for all Safari users with no toggle to disable it.
ATFP — Advanced Tracking and Fingerprinting Protection — arrived with Safari 17 in 2023 as a superset that bundles ITP with two additional protections. Link Tracking Protection strips known click identifiers from URLs before the page loads. Network-level blocking prevents requests to domains on known tracker lists. ATFP is enabled by default in Private Browsing windows but remains opt-in for standard browsing, which limits its current reach.
Safari 26 introduced a third layer: Advanced Fingerprinting Protection, or AFP, which is default-on for all users in all browsing modes. AFP restricts known fingerprinting scripts from accessing high-entropy JavaScript APIs — Canvas readback, WebGL parameters, audio buffer sampling — returning generic values instead. For WooCommerce stores, each Safari version compounds the tracking restrictions, and the protections that matter most — ITP and AFP — are on by default with no user action required.