Cherry Seed

What is a first-party tracking subdomain?

first-party-subdomain server-side itp cookies woocommerce

Quick Answer

A first-party tracking subdomain is a subdomain on your own domain that hosts a server-side tracking endpoint, letting a genuine same-domain server set cookies the browser treats as first-party. A typical example is data.yourstore.com. Because those cookies arrive via HTTP headers rather than JavaScript, they escape Safari ITP's seven-day cookie cap and persist up to 400 days (Snowplow, 2026). Ad blockers that filter third-party tracking domains cannot block your own subdomain without blocking your entire site — which is why first-party server-side tracking survives where third-party pixels fail.

Full Answer

Browsers decide what counts as first-party by the registrable domain, not the hosting arrangement. When your tracking endpoint lives at data.yourstore.com and yourstore.com is the site the visitor is on, every request to that endpoint is same-site traffic. The cookies it sets belong to your domain, and privacy features built to police third-party trackers have no jurisdiction over them.

Here's the thing most guides miss: the subdomain alone is not enough. Since Safari 16.4, ITP caps even server-set cookies to seven days when it judges the setting server disconnected from your primary domain — a CNAME pointing to a third-party vendor or a mismatched IP range is exactly what triggers it, which catches most basic server-side GTM setups (Snowplow, 2026). Only a genuine same-domain server, setting cookies through the Set-Cookie response header, keeps the full 400-day lifetime. Translation: the subdomain must resolve to infrastructure Safari recognises as genuinely yours.

The same architecture defeats ad blockers. Filter lists work by blocking known tracking domains, and data.yourstore.com appears on none of them — blocking it would mean blocking your store. Self-hosted endpoints, such as Seresa's Transmute Engine plugin for WooCommerce, deploy this way by design, which is why the approach recovers sessions that client-side pixels never see. For the full mechanics of the seven-day cap and what survives it, see our related article on why first-party cookies still die in seven days.

Sources

Programmatic Access

GET https://seresa.io/wp-json/cherry-tree-by-seresa/v1/seeds/1115

Cite This Answer

Cherry Tree by Seresa - https://seresa.io/seed/server-side-tracking/what-is-a-first-party-tracking-subdomain