IdukkiIdukki
Strategy

First-party data strategies post-cookie for ecommerce personalization

Chrome kept third-party cookies, but Safari and Firefox block them by default and consent rules still apply. Where each browser stands in 2026, which first-party signals to collect, and how durable each one really is.

The personalization vendor's demo, built entirely on third-party cookie data, worked beautifully right up until the first browser update that quietly broke half the signals it depended on.

In this article

For five years the ecommerce plan was "prepare for the end of third-party cookies in Chrome". The end never came. Google changed course twice, and in 2026 Chrome still supports third-party cookies by default. That does not make the plan wrong. The reasons to build on first-party data were never only about Chrome, and most of them got stronger while everyone watched Google.

Where the browsers actually stand in 2026

BrowserThird-party cookies by defaultWhat changed and when
ChromeAllowed; users can restrict them in settingsJuly 2024: replaces deprecation with a proposed user-choice experience. April 2025: keeps current user choice, no new standalone prompt. October 2025: retires Topics, Protected Audience, Attribution Reporting and other Privacy Sandbox APIs, citing low adoption
SafariBlockedMarch 2020 (Safari 13.1): full third-party cookie blocking; script-writable storage deleted after seven days of Safari use without interaction on the site
FirefoxPartitioned per siteJune 2022: Total Cookie Protection on by default for all desktop users, confining each cookie to the site that created it
Third-party cookie behaviour by browser, from each vendor's own announcements.

Google's own words from April 2025: it would "maintain our current approach to offering users third-party cookie choice in Chrome, and will not be rolling out a new standalone prompt for third-party cookies." Six months later it listed ten Privacy Sandbox technologies it was retiring "in light of their low levels of adoption", while keeping CHIPS, FedCM and Private State Tokens. The browser-native replacement for cross-site ad targeting is gone, and so is the deadline.

Why first-party data still matters if Chrome kept cookies

Safari and Firefox never waited. Every iPhone shopper using Safari has been browsing without third-party cookies for years. Any personalization or measurement that depends on cross-site tracking is already blind to them.

Consent applies either way. Cookie law regulates storing and reading information on a device, not who owns the cookie. A first-party cookie used to personalize content still needs a lawful basis. (More on that below.)

Shoppers trust it more. Signals a customer created on your own site are the ones they can connect to what you show them. That plausibility test is the subject of personalization without creepiness, and Gartner's 2025 research recommends building on data customers share rather than data collected without their direct involvement.

You control its quality. Third-party audiences are modelled by someone else. Your order table is not.

This is the misconception that causes real trouble. In the UK, the Data (Use and Access) Act 2025 added new exceptions to cookie consent, and the ICO's guidance on storage and access technologies spells them out: strictly necessary, statistical purposes (analytics to improve the service), and an "appearance" exception for adapting the service to a user's preferences. The ICO is explicit that the appearance exception "is not about adapting the content to display to a user on your service based on known or inferred interests or behaviours about them", for example using previous browsing history to decide what content to promote.

In practice: first-party analytics may now sit outside the consent banner in the UK if it meets the conditions, but behaviour-based personalization that stores or reads data on the device still belongs inside it. EU rules under the ePrivacy Directive are stricter still. Get the categorisation right in your consent tool before you build anything on top. The GDPR consent and UGC piece covers the content side of the same question.

The signals worth collecting, ranked by durability

First-party signals: value versus durability

Strong intentWeaker intent
Useful now, fragile
Session browsing and searchUGC views, taps and add-to-cart
Build on these first
Order historyStated preferencesWishlist and saved items
Nice to have
Device and referrer
Context, not targeting
Email and SMS engagement
Short-livedDurable
Durability means how long the signal survives browser rules and device changes. Start top-right; fill the top-left gap with accounts and email.

Server-side beats browser-side. Anything you store on your own server against an order or an account survives browser changes, new devices and cleared storage. Anything you keep only in the browser is subject to the browser's rules, and Safari's Intelligent Tracking Prevention deletes all of a site's script-writable storage after seven days of Safari use without interaction on that site. Treat browser-stored signals as short-term context and move anything that should last into the account.

UGC engagement is the underused one. Which customer videos a shopper watches, which photo they tap to see the tagged product, and which post they add to cart from reveals interest in a specific use case, fit or look, detail that a generic page view can't. The AI-assisted UGC personalization loop covers how that feeds back into what a gallery shows next.

A 90-day plan to start collecting properly

From thin data to usable first-party signals

  1. 01

    Days 1 to 15: audit

    List every signal your site captures, where it is stored (server or browser) and which consent category it sits in.

  2. 02

    Days 15 to 30: consent

    Recategorise tags in your consent tool: analytics, personalization and advertising as separate purposes.

  3. 03

    Days 30 to 60: accounts

    Give shoppers a reason to save preferences and wishlists to an account: fit notes, back-in-stock alerts, faster reorder.

  4. 04

    Days 60 to 75: events

    Instrument gallery, video and review interactions as named events tied to product ids.

  5. 05

    Days 75 to 90: use one signal

    Ship one personalized surface on your strongest signal, with a label and a holdout test.

Each phase is a few days of work for a small team; the value is that history starts accumulating now.

Resist the urge to buy a personalization engine before the audit. A sophisticated ranker on thin data has nothing to rank with. For measuring whatever you ship, the A/B testing guide for UGC and social proof explains how to set up a holdout, and over-fitting to the last purchase covers the most common weighting mistake once the data exists.

What this looks like in a UGC widget

Idukki's widget records impressions, clicks and add-to-cart events against each UGC post, which is the first-party engagement signal described above, and ties them to the product and the widget. For on-site personalization it reorders galleries toward interests a shopper picks and, where retargeting is enabled on the embed, toward products they recently viewed or saved. Those personalization signals are held in the shopper's browser with an expiry the merchant sets, so they are short-term context by design and sit inside your site's consent setup like any other personalization storage.

Frequently asked questions

  • Is Chrome still getting rid of third-party cookies?

    No. In April 2025 Google said Chrome would keep its current approach of offering users a third-party cookie choice and would not roll out a new standalone prompt. In October 2025 it retired most Privacy Sandbox APIs, including Topics and Protected Audience.

  • Does Safari block third-party cookies?

    Yes, by default since Safari 13.1 in March 2020. Safari also deletes a site's script-writable storage after seven days of Safari use without interaction on that site.

  • Do first-party cookies need consent?

    Often, yes. Cookie rules cover storing and reading data on a device regardless of whose cookie it is. In the UK some first-party analytics can now rely on the statistical purposes exception, but the ICO says personalizing content from browsing history or inferred interests is not covered by the appearance exception.

  • What is the most valuable first-party data for ecommerce personalization?

    Order history and preferences customers state on their account, because they are strong intent signals stored on your own server. Session browsing and UGC engagement are strong but short-lived, so use them for in-session relevance.

  • What is the difference between first-party and zero-party data?

    Zero-party is a marketing term for data a customer intentionally tells you, such as quiz answers or size preferences. It is a subset of first-party data, and usually the most plausible to personalize with.

Sources

  1. 1Google Privacy Sandbox (July 2024): A new path for Privacy Sandbox on the web · Instead of deprecating third-party cookies, proposes an informed-choice experience in Chrome.
  2. 2Google Privacy Sandbox (April 2025): Next steps for Privacy Sandbox and tracking protections in Chrome · Chrome keeps third-party cookie choice; no new standalone prompt.
  3. 3Google Privacy Sandbox (October 2025): Update on plans for Privacy Sandbox technologies · Retires Attribution Reporting, Topics, Protected Audience and others; keeps CHIPS, FedCM, Private State Tokens.
  4. 4WebKit (March 2020): Full third-party cookie blocking and more · Safari 13.1 blocks third-party cookies by default; seven-day cap on script-writable storage.
  5. 5Mozilla (June 2022): Firefox rolls out Total Cookie Protection by default to all users worldwide
  6. 6ICO: Guidance on storage and access technologies, what are the exceptions?
  7. 7Gartner (2025): Redefining personalized digital interactions with customer-shared data
#first-party-data#personalization#privacy#ecommerce-strategy

Continue reading

2 pieces in this cluster

These long-form pieces on the Idukki blog link back to this article, go deeper on the cluster.

More from Rohin Aggarwal

We use cookies

We use essential cookies to run this site and optional analytics cookies to understand how it’s used. You can change your choice anytime in our privacy policy.