A third-party cookie is a small piece of data that a website drops into your browser through a domain you weren’t actually visiting. Sounds a bit odd when you first hear it. You’re reading a news site, say, but some other company leaves a cookie behind while the page loads.

How Does a Third-Party Cookie Work?

Say you’re reading an article somewhere. There’s an ad on the page from an advertising company. Your browser loads that ad from the advertiser’s own domain, and along the way, the advertiser can quietly set a cookie.

Later on, you visit a totally different site that happens to use the same ad company. The cookie tells them, hey, this is the same browser from before. Your name isn’t attached to any of it necessarily. What the browser gets is an identifier, something that lets activity get connected across different sites.

First-Party vs Third-Party Cookies

Easiest way to tell them apart is just asking who set the cookie. First-party comes from the site you’re actually on. Third-party comes from some other domain embedded inside that site.

Your shopping cart usually runs on first-party cookies, since the store itself needs to remember what you tossed in. An advertising cookie belongs to a completely different domain, even though its content is sitting right there on the page you’re reading. Analytics tools land somewhere in between, really depends on how the site’s set things up and what tracking it’s using.

Why Were Third-Party Cookies Used?

For years these quietly ran a huge chunk of online advertising. You probably never noticed them working. That was kind of the point, honestly, that’s part of why it worked so well for so long.

A company could use third-party cookies to spot the same browser across a bunch of different sites. Made measuring ad campaigns easier, made building a picture of what people were into easier too. Retargeting got especially common this way, an advertiser could show you an ad again after you’d already been to their site once.

I’ll be honest, this went too far in plenty of cases. One relevant ad here and there, fine, no big deal. Feeling like the whole internet was quietly following you from tab to tab is a different feeling entirely.

Are Third-Party Cookies Still Used?

This is where things have shifted quite a bit. Major browsers have clamped down harder on third-party cookies, and the web’s been moving toward other ways of handling advertising and measurement altogether.

Chrome’s been changing its own approach here too. So it’s probably not safe anymore to assume the old system just works everywhere the way it used to.

That shift’s a good thing for privacy, in my opinion. Sites still need some way to remember users and measure what’s actually working, sure, but tracking people across unrelated sites deserves way more scrutiny than it used to get.