Cookie
Why it matters
Without cookies, a hundred visits to a pricing page look like a hundred strangers. With them, a business can see that one browser came back four times, which is a very different signal from cold traffic. Cookies also power logins, baskets and the measurement behind conversion tracking.
The catch is privacy law. In the EU and the UK, a site needs consent before it sets non-essential cookies, and a banner that fires tags before anyone clicks "accept" is a compliance problem. Safari and Firefox also block third-party cookies by default, so any plan that depends on them already has gaps.
How to apply it
- Rely on first-party cookies for anything that needs to be measured over time.
- Put a consent tool in front of every non-essential tag, then test that declining really stops it firing.
- Use the return-visit signal for something a person notices, such as a different page for a repeat reader or a note to sales when a target account comes back.
- Store an identifier in the cookie and keep personal details on the server, never in the cookie itself.
What it is
A cookie is a short piece of text, usually a random identifier, that a website sends to a browser. The browser keeps it and sends it back with every later request to that site. That is how a site knows the same browser has been there before, without asking anyone to log in.
A first-party cookie is set by the site the visitor is on. A third-party cookie is set by another domain, such as an ad network whose code is embedded in the page. A session cookie disappears when the browser closes, while a persistent cookie lasts days or months. Some are essential, such as the one that keeps a basket filled. Others exist only for analytics or advertising.
Common mistakes
- Loading analytics and advertising tags before the visitor has agreed, then relying on a banner that only records the choice afterwards.
- Treating "essential" as a broad category. Only cookies the service cannot work without are essential. Advertising cookies, and analytics cookies in most set-ups, are not, even when the business finds them necessary.
- Storing personal details, such as an email address, in the cookie itself, instead of an identifier matched on the server.
- Building a plan on third-party cookies. Safari and Firefox block them by default, so attribution has gaps.
- Never testing the declined case. Open the site, decline, and check that no non-essential cookie is set.