The industry spent six years and a great deal of money preparing for an event that was cancelled, and the infrastructure built to replace it was switched off too. What is left is messier than either outcome anyone planned for.
If you have read anything about first-party data in the last few years, it almost certainly opened by telling you third-party cookies were going away. That framing is now wrong, and it is worth correcting properly rather than quietly, because a lot of strategy was built on it.
Here is the honest version: cookies survived, their replacement did not, and the measurement environment is more fragmented than it would have been under either the old world or the promised new one. Meanwhile a genuinely new force arrived that nobody was planning for in 2020 — AI systems sitting between your brand and your customer.
The conclusion happens to be the same one everyone was already reaching. The reasoning is completely different, and reasoning is what tells you where to spend.
First-party data — information collected directly from your own customers and visitors through your own properties and relationships, with their knowledge. It is distinguished from third-party data, purchased or inferred from external sources, and from second-party data, which is another organisation's first-party data shared with you. The defining characteristic is not accuracy but ownership: it survives platform policy changes, browser changes and channel disruption because no intermediary controls your access to it.
What Actually Happened To Cookies
| Date | What happened |
|---|---|
| January 2020 | Google announces intent to phase out third-party cookies in Chrome |
| 2021–2024 | Repeated delays: late 2022, then late 2023, then mid-2024, then 2025 |
| July 22, 2024 | Pivot announced — a user choice experience instead of deprecation |
| April 22, 2025 | Reversal confirmed. Chrome will not deprecate third-party cookies, and no standalone choice prompt will ship |
| October 17, 2025 | Google announces retirement of most Privacy Sandbox APIs |
| Chrome 144, Jan 2026 | Deprecation of the retired APIs begins |
| Chrome 150, Jul 2026 | Removal targeted |
What died instead
Topics, Protected Audience, Attribution Reporting and most of the rest of the Privacy Sandbox stack. A narrow set of components survives for specific purposes, but there is no single Google-led replacement for third-party cookie functionality, because none was needed once the cookies stayed.
Reported reasons include low adoption of the new APIs, regulatory and antitrust pressure, and testing by the UK competition regulator that raised serious questions about attribution accuracy under the proposed system.
Under the original plan the industry would have moved to one common, if imperfect, replacement. Under the actual outcome there is no common standard at all. Advertisers now run a patchwork of cookie-based signals where they work, modelled and aggregated data where they do not, server-side event capture, and platform-specific reporting that does not reconcile. Fragmentation is the outcome, and fragmentation is harder to work with than either alternative.
What did not change
- Safari, Firefox and Brave still block third-party cookies by default. Roughly a fifth of global traffic is cookieless irrespective of Chrome, and published estimates vary depending on how ad blockers are counted.
- Ad blockers remove more on top of that.
- Safari limits first-party cookie lifetime in some circumstances, so even your own cookies are not permanent.
- Privacy law is untouched by browser policy. Consent obligations under GDPR, ePrivacy and CPRA are exactly what they were.
The Two Forces That Still Make This Urgent
Force one: signal degradation without a floor
The cookie story is not that cookies vanished. It is that the signal you get is now inconsistent, partial and platform-dependent, with no agreed standard arriving to fix it. You are measuring some of your traffic well, some badly, and some not at all, with the proportions varying by browser, device and region.
That is a worse planning environment than a clean break would have been, because a clean break forces migration and ambiguity permits drift.
Force two: AI intermediation
This is the genuinely new one, and it was not in anyone's 2020 planning.
When a shopper asks an AI assistant which product to buy and receives a recommendation, the traditional discovery relationship never forms. There is often no click to attribute, no session to cookie, no landing page to optimise, and no retargetable visitor. The model consulted sources, formed an answer, and delivered it.
You may win that recommendation. You may even get the sale. But you did not get the relationship, and you cannot rebuild the interaction from analytics because much of it happened somewhere you have no visibility into.
If discovery increasingly happens inside systems you do not control, the only durable connection is one that does not depend on discovery at all — a customer who already knows your name, has your email, and can be reached without an intermediary deciding whether to surface you. That is not a new insight, but AI intermediation makes it structural rather than merely prudent.
The visibility side of this is covered across our AI search work; this article is about the half you own.
What Counts as First-Party Data
Deliberately shared preferences and intentions. Highest quality, because the customer chose to tell you.
Purchase history, site behaviour, email engagement, support contact. Collected through your own properties.
Another organisation's first-party data shared with you. Useful, but you hold it on their terms.
Aggregated from external sources. Degrading in quality, legally scrutinised, and never yours.
What people wrongly call first-party data
- Your Meta or Google audience lists. Built from your activity, held on their platform, subject to their policy. If the account is disabled, it is gone.
- Amazon customer data. You are not the merchant of record for the relationship. You get aggregated reporting, not customers.
- Analytics data alone. Aggregate behaviour without identity is measurement, not an asset you can activate.
- A list you bought. Third-party data with a friendly name, and frequently a compliance problem.
The ownership test
Ask one question: if this platform terminated your account tomorrow, would you still have it? If the answer is no, it is not an owned asset regardless of how it was generated. Your email list passes. Your Meta custom audience does not.
On-Site Collection
The mechanisms, ordered by value
- Account creation at checkout. Highest-value because it carries identity and purchase history together, and it converts best when framed around order tracking rather than marketing.
- Email and SMS capture with a real reason. A discount buys an address from someone who wanted a discount. Genuinely useful content or early access buys one from someone who wants your product.
- Preference quizzes, which collect zero-party data while providing something the visitor wanted.
- Back-in-stock and price alerts, which capture high-intent visitors at the exact moment they would otherwise leave.
- Wishlists and saved items, which are stated future intent.
The trade to be deliberate about
Discount-led capture builds a list of discount-responsive buyers. That is not automatically wrong — some businesses run on promotional cadence — but you should choose it knowingly, because a list assembled entirely with 15% off codes will underperform on full-price campaigns and you will wrongly conclude that email does not work.
If your margin cannot support permanent discounting, buy addresses with value rather than money.
The mistake that quietly costs the most
Collecting only an email address. One extra well-chosen question at signup makes the entire list more valuable, because it enables segmentation from day one instead of waiting for behavioural data that may never accumulate. Ask what problem they are solving, or which category they care about — one question, not five.
The build detail is in our guides to building an ecommerce email list and why your email list is not making money.
Post-Purchase Collection
The highest-conversion moment available to you, and the one most brands leave entirely unused.
Why post-purchase outperforms
Because the person has already transacted. Trust exists, the product is in hand, and the interaction is genuinely useful to them rather than an interruption. Capture rates at this moment are not comparable to a pop-up on a cold visit.
The mechanisms
- Packaging inserts offering something real — a usage guide, a care sheet, an extended warranty. This is the primary route for marketplace buyers you otherwise cannot reach.
- Warranty or product registration, which is a natural reason to collect identity and is expected by customers.
- Usage guides and setup help delivered digitally in exchange for an address.
- Replenishment reminders for consumables, which customers actively want.
- Community or membership access where the category supports it.
Marketplaces restrict what packaging inserts may do. Offering genuine post-purchase value and inviting registration is generally acceptable; attempting to divert future transactions off the marketplace, or conditioning anything on a review, is not. Read the current policy before printing, since the cost of getting this wrong lands on your account rather than on the insert.
The framing that works
Not "join our newsletter". "Register your product for the extended warranty" or "get the care guide that doubles its life". Both collect the same address. The second converts substantially better because it offers the customer something they want at a moment they want it.
The Amazon Problem, and What You Can Do
The uncomfortable structural fact: on Amazon, Amazon owns the customer relationship. You receive orders and aggregated reporting. You do not receive customers.
What is actually available to brand-registered sellers
- The Customer Engagement Tool, which allows email to brand followers and repeat customers within Amazon's system and templates.
- Brand Tailored Promotions, targeting defined audience segments such as recent customers or high-spend buyers with an offer.
- Brand Analytics, which is aggregated and anonymised but genuinely useful for understanding search and purchase behaviour.
- Amazon Attribution, connecting off-Amazon activity to on-Amazon outcomes.
- Packaging inserts, within policy, which remain the main bridge to an owned relationship.
The honest assessment
These are useful and you should use all of them. None of them gives you an owned asset. Every one operates inside Amazon's system, under Amazon's rules, and disappears if your account does. Treat them as the best available tools within a rented relationship rather than as a substitute for building your own.
The strategic implication
For a brand that sells predominantly through marketplaces, the owned-data question is really a channel question: you need somewhere customers can transact with you directly, even at low volume, because that is the only place the relationship can exist. That is the argument for a direct store, and it is a strategic argument rather than a revenue one.
Covered further in Shopify vs Amazon and owning your customers, the Customer Engagement Tool guide, and Brand Tailored Promotions.
Want your data stack mapped?
We will audit what you are collecting, what you actually own versus rent, and where the highest-return gaps are across site, post-purchase and marketplace.
Book a Strategy Call →The Ecom Profit Box
Eleven playbooks on listings, conversion, images, and email. Built for operators, no fluff, no email sequence.
Grab It Free →Zero-Party Data
The category with the best quality-to-effort ratio, and the one most brands never deliberately collect.
Why volunteered data outperforms observed data
- It is stated rather than inferred. Behaviour requires interpretation and interpretation is frequently wrong.
- It captures intent, not just history. Someone browsing baby products may be an expectant parent or shopping for a friend, and only one of those is a long-term segment.
- It survives every technical change. No cookie, pixel or browser policy is involved.
- Consent is inherent. They chose to tell you.
How to collect it without annoying people
- Give something back immediately. A quiz that produces a genuine recommendation is a service; a quiz that produces a discount code is a form.
- Ask one thing at a time, across the relationship, rather than a long form at signup.
- Ask at natural moments — post-purchase, at registration, in a preference centre.
- Visibly act on it. If someone tells you their category and you keep sending everything, they will not answer again and you have trained them not to.
The preference centre nobody builds
A page where subscribers set what they want to hear about and how often is unglamorous and disproportionately valuable. It reduces unsubscribes, improves deliverability by lowering complaint rates, and collects segmentation data as a by-product of a genuine courtesy.
Activation: Segmentation That Changes Messaging
Collection without activation is a cost centre. Most brands have far more data than they use, which is a different problem from not having enough.
The test for a useful segment
If the message does not change, the segment does not exist. Splitting a list into groups that all receive the same campaign is administration, not segmentation.
| Segment | What changes |
|---|---|
| First-time vs repeat | Education versus replenishment and range |
| Category preference | Which products appear at all |
| Purchase recency | Reactivation versus routine cadence |
| Spend level | Whether premium range is shown |
| Engaged but never purchased | Objection handling instead of promotion |
| Lapsed high-value | Personal outreach, worth real effort |
Start with four, not forty
Most brands get the majority of the available value from a small number of segments executed properly. Elaborate segmentation trees usually collapse under their own maintenance cost, and a fourteen-segment model that nobody updates performs worse than four segments that are actually used.
Predictive value, honestly
Lifetime value modelling is genuinely useful once you have enough purchase history — identifying likely high-value customers early changes what acquisition cost you can justify. But it needs real data volume to be meaningful, and a brand with eight months of history and three thousand customers should not be building predictive models. They should be sending better segmented email.
The framework is in our customer lifetime value guide, and campaign execution in our email marketing service overview.
Server-Side Measurement
The technical layer that matters more now precisely because no common standard replaced the cookie.
What it does
Instead of relying on a browser-based pixel that may be blocked, restricted or expired, conversion events are sent from your server directly to the advertising platform. It works across browsers regardless of cookie policy, survives ad blockers, and is not subject to browser cookie lifetime limits.
Where it helps most
- Recovering conversion signal from browsers that block or restrict client-side tracking.
- Improving platform optimisation, since algorithms optimise on the conversions they can see.
- More consistent measurement across devices and sessions.
- Better data quality for the modelled attribution that platforms increasingly rely on.
The honest caveats
- It does not restore perfect attribution. Nothing does, and vendors claiming otherwise are selling.
- Consent still applies. Moving collection server-side does not remove your legal obligations, and treating it as a consent workaround is a serious mistake.
- It requires implementation effort and is easy to get subtly wrong, producing double-counted conversions that look like improvement.
- Match quality depends on the identifiers you send, which brings you back to first-party data. This is the connection most implementations miss: server-side measurement is only as good as the customer data behind it.
Governance and Consent
I am not a lawyer and this section is descriptive rather than advisory. Privacy obligations depend on where your customers are, what you collect and what you do with it. Take your specific situation to a qualified professional — this area carries real penalties and the rules differ meaningfully between jurisdictions.
The principle that survives every regulatory change
Collect what you will use, tell people plainly what you are doing, and make leaving easy. Most compliance failures are not sophisticated legal edge cases; they are brands collecting data they never use, describing it vaguely, and making unsubscribing difficult.
The operational basics
- Consent capture that records what was consented to and when, retrievably. If you cannot evidence it, you may not have it.
- A privacy policy that describes what you actually do, not a template describing a business you are not running.
- Data retention limits. Holding everything indefinitely increases both risk and breach exposure with no upside.
- A documented process for access and deletion requests, before one arrives.
- Vendor due diligence, since your processors' failures land on you.
- Separate consent for separate purposes. Agreeing to order updates is not agreeing to marketing.
The point worth repeating from section one
Browser policy changed and privacy law did not. Google's reversal altered nothing about GDPR, ePrivacy or CPRA obligations. Any strategy that treated the cookie deprecation timeline as the compliance driver was mis-specified from the start.
Primary sources: California Attorney General on CCPA, the California Privacy Protection Agency, and FTC privacy and security guidance.
What Good Looks Like By Tier
| Revenue | What you should have | What to ignore |
|---|---|---|
| Under $1M | Email capture, purchase history, welcome and post-purchase flows, one segment split | CDPs, predictive models, complex attribution |
| $1M–$3M | Four working segments, packaging inserts, preference collection, server-side conversions | Multi-touch attribution, custom infrastructure |
| $3M–$10M | Zero-party collection, cross-channel identity resolution, LTV by cohort, governance process | Enterprise CDP unless genuinely warranted |
| $10M+ | Unified customer profile, predictive LTV, formal data governance, dedicated ownership | — |
The failure mode at every tier
Buying infrastructure before having the discipline. A customer data platform does not fix an organisation that is not acting on the data it already has, and it is a large cost that produces a feeling of progress without any.
The reliable sequence is: collect a little well, act on it, notice the constraint, then buy the tool that removes that specific constraint. Brands that buy first almost always end up with an expensive system feeding reports nobody opens.
The metric that tells you it is working
Not list size. Revenue per contact, and repeat purchase rate among identified customers versus anonymous ones. If those numbers are not moving, more collection will not help — the problem is activation, and adding data to an unused pile makes it worse rather than better.
The 90-Day Build
| Weeks | Focus | Output |
|---|---|---|
| 1–2 | Audit | What you collect, what you own vs rent, where the gaps are |
| 3–4 | Consent and governance | Consent capture, privacy policy accuracy, retention rules |
| 5–6 | On-site collection | Capture with a real value exchange, plus one qualifying question |
| 7–8 | Post-purchase | Packaging inserts, registration flow, digital guide delivery |
| 9–10 | Server-side conversions | Implemented and validated against existing data |
| 11–12 | Activation | Four segments live with genuinely different messaging |
| 13 | Measure | Revenue per contact baseline, repeat rate by identified vs anonymous |
Why governance comes second, not last
Because retrofitting consent onto data you already collected is painful and sometimes impossible. Getting the consent architecture right before you scale collection is the cheapest sequencing decision on this list, and the one most commonly deferred until it becomes expensive.
The thing to remember when this feels like a lot
Every other asset in your marketing stack is rented. Your ad accounts operate under platform policy. Your marketplace rankings move with algorithm changes. Your organic visibility now passes through AI systems that decide whether to mention you at all. Cookies survived this time, and the infrastructure built to replace them did not, which should tell you something about how much of this you control.
The list of customers who know your name and chose to hear from you is the only part of that stack nobody else can switch off. That was true before the cookie story started, it stayed true when the story was cancelled, and it is the reason this is the right place to end.
The Short Version
- Google confirmed on April 22, 2025 that it would not deprecate third-party cookies in Chrome, then announced on October 17, 2025 that it was retiring most Privacy Sandbox APIs. Most published first-party data advice still repeats the old premise.
- Measurement got worse rather than better, because the industry received neither the clean break it prepared for nor the common replacement it was promised. Fragmentation is the outcome.
- Safari, Firefox and Brave still block third-party cookies by default, so roughly a fifth of traffic is cookieless regardless of Chrome, and privacy law obligations are entirely unaffected by browser policy.
- The genuinely new force is AI intermediation: when a model answers a shopper's question, the discovery relationship never forms and there is often nothing to attribute or retarget.
- The ownership test is simple — if the platform terminated your account tomorrow, would you still have it? Your email list passes; your Meta custom audience and your Amazon customer data do not.
- Post-purchase is the highest-converting collection moment and the most under-used. Frame it as warranty registration or a care guide rather than a newsletter.
- Collection without activation is a cost centre. If the message does not change, the segment does not exist — start with four segments, not forty, and never buy infrastructure before having the discipline.
External Sources Cited in This Article
- Google Privacy Sandbox — announcements on third-party cookie policy and API retirement
- California Attorney General — California Consumer Privacy Act
- California Privacy Protection Agency — CPRA regulations
- FTC — Privacy and data security business guidance
- GDPR — General Data Protection Regulation reference
- Amazon Seller Central — Customer Engagement Tool, Brand Tailored Promotions, Brand Analytics
- UK Competition and Markets Authority — Privacy Sandbox testing and commitments monitoring

