Full Answer
ITP launched in 2017 and has evolved through multiple versions, each closing workarounds that marketers discovered in the previous one. The current system uses on-device machine learning to classify domains based on cross-site tracking behaviour patterns. When Safari determines a domain has tracking capabilities, it enforces progressively stricter restrictions on how that domain's data persists in the browser.
The restrictions stack. Third-party cookies are blocked completely — no exceptions since Safari 13.1. First-party cookies set via JavaScript expire after 7 days of Safari use without a return visit. When a visitor arrives via a decorated link from a classified tracking domain — which includes Google and Facebook — JavaScript-set cookies expire after just 24 hours. Site data for classified domains is deleted entirely after 30 days without user interaction.
The 24-hour window is the critical constraint for WooCommerce stores running paid advertising. Google Ads uses a 30-day click attribution window, but for Safari visitors the gclid cookie storing that click ID expires after a single day. Any customer who clicks an ad on Monday and purchases on Wednesday is invisible to Google Ads attribution. Since consideration periods for many ecommerce categories routinely exceed 24 hours, a significant share of real conversions from Safari visitors never gets attributed.
Server-side tracking with first-party cookies set via HTTP headers from the store's own subdomain bypasses ITP's JavaScript cookie restrictions, because ITP's 7-day cap targets document.cookie, not server-issued Set-Cookie headers.