Full Answer
ITP's cookie cap is a classification-based system, not a blanket rule. Safari maintains a list of domains known to participate in cross-site tracking. When a user visits your WooCommerce store and your JavaScript sets a first-party cookie — say a _ga or _fbp cookie — Safari checks whether any script on the page loaded from a classified domain. If it did, every JavaScript-set cookie on that page gets capped to seven days. If the URL also contains a click identifier from an ad platform, the cap drops to 24 hours.
The practical effect on WooCommerce stores is severe. A visitor clicks a Google Ads link on Monday, browses products, and returns on Saturday to buy. On Chrome, the gclid cookie is still there and the purchase attributes correctly. On Safari, the cookie expired after 24 hours — the returning visitor looks like a new Direct session, and Google Ads never learns the click converted.
Server-set cookies bypass ITP entirely because Safari's restrictions apply only to cookies written by JavaScript in the browser. When your server-side tracking endpoint sets the cookie via an HTTP Set-Cookie header from your own first-party domain, Safari treats it as a genuine server cookie with no automatic expiry cap. The cookie persists for its full declared lifetime — typically 390 days — giving the full attribution window back. This is why server-side tracking recovers attribution on Safari that no amount of client-side workaround can preserve.