Full Answer
Browsers decide what counts as first-party by the registrable domain, not the hosting arrangement. When your tracking endpoint lives at data.yourstore.com and yourstore.com is the site the visitor is on, every request to that endpoint is same-site traffic. The cookies it sets belong to your domain, and privacy features built to police third-party trackers have no jurisdiction over them.
Here's the thing most guides miss: the subdomain alone is not enough. Since Safari 16.4, ITP caps even server-set cookies to seven days when it judges the setting server disconnected from your primary domain — a CNAME pointing to a third-party vendor or a mismatched IP range is exactly what triggers it, which catches most basic server-side GTM setups (Snowplow, 2026). Only a genuine same-domain server, setting cookies through the Set-Cookie response header, keeps the full 400-day lifetime. Translation: the subdomain must resolve to infrastructure Safari recognises as genuinely yours.
The same architecture defeats ad blockers. Filter lists work by blocking known tracking domains, and data.yourstore.com appears on none of them — blocking it would mean blocking your store. Self-hosted endpoints, such as Seresa's Transmute Engine plugin for WooCommerce, deploy this way by design, which is why the approach recovers sessions that client-side pixels never see. For the full mechanics of the seven-day cap and what survives it, see our related article on why first-party cookies still die in seven days.