Skip to content

First-party tracking

First-party tracking that keeps every conversion when the third-party cookie is gone.

Your own server sets a first-party identifier on a subdomain you own, so the journey holds all the way to the lead.

  • No third-party cookie set
  • Nothing personal before consent
  • Hosted in Frankfurt, DPA signed

Rated by teams that stopped depending on the cookie

  • Google
  • TrustpilotRated 4.9 out of 5 on Trustpilot4.9
  • G2Rated 5.0 out of 5 on G25.0
  • CapterraRated 5.0 out of 5 on Capterra5.0

First-party tracking at

  • Trading.de logo
  • Swedish Cold logo
  • Trustfactory logo
  • MLK Digital logo
  • CPC AG logo
  • DaxoMedia logo
  • Contentbär logo
  • Hivebuy logo
  • OBVIOUS logo

Same site, same month, five ways to lose a cookie

Your workspace
Capture by scenarioCookie pixel against first-party tracking, last 30 days
412Recorded by LeadJourney
268Seen by the cookie pixel
0Third-party cookies set
ScenarioCookie pixelLeadJourney
Consent accepted268 conversions268, deduplicated
Consent declined0, no cookie set71, no personal data
Safari, day 80, new visitor38, same person
Ad blocker on0, script blocked29, first-party
Phone, then desktop0, two strangers6, stitched on the form

The pixel's 268 all sit in the first row. Every row below it needed a cookie that was not there.

The definition

What is first-party tracking?

In short

First-party tracking records visits and conversions without third-party cookies. A pseudonymous identifier is set by your own domain and server, joined to a person only when they fill in a form or call, and hashed before anything reaches an ad platform. It is consent-aware, not consent-free: what you may collect stays the same, how reliably you collect it changes.

  • Set nothing from a third party

    The identifier comes from your own domain, such as track.yourdomain.com, not from a tracking domain the browser and the blocklists treat as a third party. That is what first-party means here.

  • Keep the identifier on the server

    The event is recorded on your server and the identifier lives there, so a seven-day cookie cap or a cleared browser does not reset it. How it is captured and forwarded is server-side tracking.

  • Read the consent state, and act on it

    Before consent the event carries no personal data. After it, the full record. First-party tracking that ignores the banner is not first-party tracking, it is a workaround with a new name.

  • Become a person only on the form or the call

    The visits stay pseudonymous until the visitor identifies themselves. At that moment the sessions are stitched to the lead, and what goes to the ad platforms goes hashed.

Why the cookie stopped working

The cookie was the pixel's memory. The browsers have been deleting it for years.

A conversion pixel remembers a visitor with a third-party cookie, and every major browser now limits or blocks that cookie. The pixel does not report what it forgot.

  • Safari caps a script-set cookie at seven days. A lead that clicks on an iPhone and converts the week after arrives as a stranger, with no click to credit.
  • Firefox blocks third-party cookies by default, and Brave and most ad blockers block the tracking script along with them.
  • Chrome has spent years announcing, delaying and redesigning its cookie changes. Whatever it ships next, a measurement plan built on the third-party cookie has no floor under it.
  • The consent banner holds the cookie until the visitor agrees. Declined or ignored, the pixel records nothing at all, and a share of visitors decline.
  • A cookie lives on one device. The phone that saw the ad and the laptop that filled in the form never share one, so the journey splits into two people.
  • The workaround is worse than the gap. A tool that sets its cookie anyway, or fingerprints around the banner, turns a measurement problem into a legal one.

The pixel is not failing at random. It is failing exactly where the browsers and the regulators told it to. Tracking that depends on a cookie inherits every one of those limits.

Watch it

Measurement without the cookie

What is left of your conversion data once consent, iOS and the ad blockers are done with it, and how the gap gets closed.

45 secondsAll videos

Case studies

What changes once the attribution is right

One measured result per customer, with the person, the role and the company behind it.

  • Portrait of Karsten Guhr

    Tax and accounting

    54% better lead quality after using LeadJourney for marketing

    Karsten Guhr

    Managing Director

    Read the story
  • Portrait of Nikita Yatsun

    SEO agency

    95% clarity about marketing KPIs and a foundation to scale

    Nikita Yatsun

    Managing Director

    Read the story
  • Portrait of Florian Buck

    Klickkraft GmbH

    Business coaching

    €10-20k in monthly Meta spend, tied to qualified leads and revenue per ad

    Florian Buck

    Managing Director

    Read the story
  • Portrait of Marc Richard

    LinkedIn growth agency

    2x customer retention, once every LinkedIn touchpoint was tracked to revenue

    Marc Richard

    CEO

    Read the story
  • Portrait of Andreas Malkow

    Digital publishing

    Which article produced the lead and the revenue, across AI and organic search

    Andreas Malkow

    CEO & Head of PR

    Read the story
  • Portrait of Philipp Nessmann

    SEO and GEO agency

    Proven ROI on every retainer, from organic and AI search leads through to revenue

    Philipp Nessmann

    Managing Director

    Read the story
  • Getreach

    Backlinks marketplace (SaaS)

    0 to 100k in revenue from paid ads alone, inside the first month

    Getreach

    getreach.com

    Read the story

Every source, every CRM

First-party on every source, stitched to every CRM.

The channels a first-party click can come from, and the CRMs the identity is read back from once the person is known.

Ad platforms

Spend, campaign structure and click IDs come in. Closed deals go back out as offline conversions.

All traffic channels

Organic channels

Unpaid clicks from search and social, attributed per post, per video and per keyword.

All traffic channels

AI search engines

The traffic your analytics still files under direct. No setup, the tracking script separates it.

All traffic channels

CRM and sales

Lead stage and deal value flow in. Every campaign sees the revenue it actually produced.

All CRM and sales tools

What first-party tracking does

Everything the third-party cookie used to do, done without one.

Your own first-party subdomain

Tracking runs on track.yourdomain.com, a domain you own. To Safari, Firefox and the blocklists it is your site talking to itself, so nothing in the setup is a third-party cookie or a third-party request.

An identifier set on the server, not in a third-party cookie

The visitor is recognised by a pseudonymous first-party identifier the server issues and keeps, together with the click ID from the first visit, so the seven-day cap and a cleared browser do not reset the journey.

Consent-aware from the first request

The consent state travels with every event. Before consent, the event is recorded without personal data; after it, the full record. A declined banner stays declined, and the conversion is still counted.

Identity stitched on the form or the call

The visits stay anonymous until the person fills in a form, books or calls. At that moment the touchpoints, across sessions and devices, are stitched to the lead. See cross-device journeys.

Hashed fields to the platforms, never raw ones

Email, phone and the click ID go to Meta, Google, LinkedIn and Microsoft hashed, with an event ID for deduplication, so match quality rises without a personal field ever leaving in the clear.

Hosted in Frankfurt, DPA signed

Data is processed and stored in Frankfurt, encrypted at rest, an Art. 28 data processing agreement is signed and the sub-processor list is public, so the vendor review has a named control for every row.

What first-party tracking does not do

First-party is not consentless. The banner still decides what you may keep.

Removing the third-party cookie removes a dependency, not an obligation. Consent still governs personal data, and a tool that quietly rebuilds the cookie with a fingerprint has only moved the problem to legal. LeadJourney reads the consent state and records the conversion either way, without the person.

Inside the layer

What first-party tracking looks like once it is running.

Your workspace
Lead journeyOne lead, three sessions, two devices, no cookie
LVLena VogtFintoryStitched on the form
  1. Meta AdsClicked a lead ad in Instagram, iPhone SafariDay 1
  2. Safari, return visitRead /pricing again. A pixel cookie would have expired on day 7Day 9
  3. DesktopRequested a demo on /request-demo. Journey stitched to the leadDay 12
  4. HubSpotDeal moved to Closed won, €38,000Day 34
First click creditedMeta Ads

Three sessions, two devices, and nothing stored in the browser between them.

One journey

One lead across Safari, an expired cookie and a desktop form.

Open the lead and read the path no cookie could have held: the Meta click on an iPhone, the return after the seven-day cap, the form at a desk, the deal in the CRM.

  • First click with its fbclid, kept for months on the server
  • Return visits after the cookie would have expired
  • Phone and desktop sessions stitched when the form is submitted
  • CRM stages and the closed amount on the same timeline
Your workspace
Event logRecorded first-party, last hour
Live
  • Lead · /request-demoConsent accepted · Lena Vogt (Fintory)Full event, hashed fieldsSent to Meta
  • Booked callConsent declined · CalendlyAnonymous eventNo personal data
  • Lead · /pricingAd blocker active · Tom BeckerRecorded first-partyRecovered
  • Qualified leadHubSpot stage change · BuildRightHashed email + gclidSent to Google Ads

The declined row is still a conversion. It just is not a person.

Consent in the log

Every event with the consent state it was recorded under.

The log shows what was recorded for each visitor and under which consent: the full event where the banner was accepted, an anonymous one where it was declined. See GDPR compliant tracking.

  • Consent state on every row, read from your consent platform
  • Anonymous events for declined banners, no personal data attached
  • Hashed fields listed per event, so you can see what left
  • Transparent logs for clicks, conversions and postbacks, readable by compliance too
Your workspace
Consented Lead eventSent to the Meta Conversions API, consent accepted
8.4/10Event match quality5.1 pixel only, same form
  • Email, hashed on your server
  • Phone, hashed (the form did not ask)
  • Click ID (fbclid) from your subdomain
  • IP address and user agent, from the server
  • External ID, pseudonymous
  • Event ID shared with the pixel

Meta scores the event on what arrives. Every field here arrived hashed, and only because the visitor accepted.

What leaves your domain

What travels with a consented event, and in what form.

Open a consented event and see what reached the platform: the email and phone hashed on your server, the click ID, the IP and user agent, and the shared event ID. No raw personal field on the list.

  • Email and phone hashed before they leave
  • Click ID (fbclid, gclid) captured on your subdomain, not read from a cookie
  • IP address and user agent from the server request
  • Match quality per event, as the platform reports it back

Live in 21 minutes

First-party tracking set up in three steps

No fingerprinting library, no container to host, no engineering ticket.

  1. 1About 5 minutes

    Point a subdomain, add one script

    Point track.yourdomain.com at LeadJourney and paste one script into your site header. From the first visit the identifier is first-party and set on the server, and no third-party cookie is written.

  2. 2About 15 minutes

    Connect consent, ad accounts and CRM

    The consent state comes from the banner you already run. Connect Meta, Google, LinkedIn and Microsoft Ads by OAuth for the conversion APIs, and your CRM for the outcomes: native for HubSpot, Pipedrive, Close and Attio, a webhook for Salesforce and the rest.

  3. 3Same day

    Map the events

    Decide what each event becomes: the consented lead to Meta with hashed fields, the declined one as an anonymous count, the closed deal back to Google with its value. The pixel can stay and is deduplicated from the first hour.

How it compares

The cookie pixel, analytics behind a consent gate, and a first-party layer built without the cookie.

What you needMeta AdsGoogle AdsThird-party cookie pixelsGoogle Analytics 4Consent-gated GA4LeadJourney
Works without third-party cookiesNo: Built on themPartly: First-party cookie, consent-gatedYes: First-party identifier on the server
Survives Safari's seven-day capNo: Cookie gone on day 8No: Script-set _ga cookie, same capYes: Identifier kept on the server
Loads with an ad blocker onNo: Script on every blocklistNo: gtag.js is blocked tooYes: First-party request to your subdomain
What a declined banner leaves youNo: NothingPartly: Cookieless pings and modelled numbersYes: An anonymous conversion, no personal data
Knows the person once they identifyPartly: Advanced matching a developer wiresPartly: A user ID you implementYes: Stitched on the form or the call, hashed
Hosting, DPA and sub-processorsNo: Meta's infrastructure, Meta's termsPartly: Google's infrastructure, Google's termsYes: Frankfurt, Art. 28 DPA, public list

What changes

What changes once the tracking no longer needs a cookie.

Up:

Conversions that outlive the cookie

A lead that returns on day nine, on another device, is still the same person with the same first click, so the campaign that started it keeps its credit.

Done:

A vendor review with an answer per row

Hosting, cookies, DPA, sub-processors, DPO: the questions legal asks first each name a control. Regulated teams such as financial and legal advisors run on it.

Down:

Consent risk

Nothing personal is recorded before consent and nothing raw leaves, so the tracking setup stops being the thing compliance worries about.

Up:

Match quality at the platforms

Hashed email, phone and click ID on consented events give Meta and Google more to match on than a cookie ever carried.

Done:

One journey across devices

The phone that saw the ad and the laptop that converted are one record once the person identifies, in the report and in the CRM.

Lasting:

The same page for marketing and the DPO

The log that proves what was recorded and under which consent is the log marketing reads every day. No second tool, no second story.

Original reviews

What our customers wrote, word for word

4.9 out of 5 across 11 public reviews. Quoted as they were left, shortened only by dropping whole sentences.

  • 5 out of 5 starsGoogle

    Before LeadJourney, we had no reliable tracking concept for our five-figure ad spend. We were manually building spreadsheet and CRM reports, inaccurate and time-consuming. Within two days, everything was set up. For the first time, I know exactly what I pay per lead and which campaigns actually bring in the best-qualified prospects.

    Florian BuckCEO, Klickkraft GmbH
  • With LeadJourney we are able to track all our leads and connect them with sales and attribution data to make better decisions. In the first month of using it we scaled from 0 to 100k revenue from paid ads only.

    GetreachBacklinks Marketplace (SaaS)
  • 5 out of 5 starsG2

    LeadJourney finally fixed my Marketing Analytics. It goes way beyond basic Ad Tracking Software. The Customer Journey Report saves hours of digging, and capturing everything from Offline Conversions to AI Search Tracking makes it the Best B2B Attribution Platform available.

    Sascha LenzMarketing Manager
  • 5 out of 5 starsTrustpilot

    Connected LeadJourney for 2 clients, setup took literally 20 minutes each. The data became more accurate, the reports actually make sense. Now clients look at the dashboard and the 'why don't the numbers match?' questions are gone.

    Alexander SamarPerformance Marketing Agency
  • 5 out of 5 starsGoogle

    With LeadJourney, we have finally found a tool that provides us with the data we need to scale our performance marketing campaigns. The most important KPI is no longer lead price but cost per qualified lead.

    Steffen SiesingCEO, Bilanzmanufaktur GmbH
  • 5 out of 5 starsG2

    The ability to track both online and offline conversions in one unified dashboard has given us insights we never had before. Our ROI has improved dramatically since we started integrating LeadJourney with our CRM. We're finally able to see the full customer journey, and it's been a game changer for our strategy.

    Andre WitzelFounder, Trading.de
  • 5 out of 5 starsTrustpilot

    The ability to seamlessly integrate data from multiple channels and see real-time insights has significantly improved our campaign results. We now focus on metrics that truly matter, like ROI and qualified leads.

    Nikita YatsunCEO, RLV Media GmbH

Common questions

First-party tracking, the questions buyers ask

What marketers and their privacy teams want to know before they take the third-party cookie out of the setup.

What is the difference between first-party tracking and server-side tracking?

Server-side tracking is about where the event is recorded: on a server, on your own domain, instead of in the browser. First-party tracking is about how the visitor is identified while that happens: with an identifier set by your own domain and server instead of a third-party cookie. LeadJourney is both, which is why the two pages exist. The server-side page covers the capture and the forwarding; this one covers the identity.

Does first-party tracking mean I no longer need a cookie banner?

No. Consent law covers personal data and anything stored on or read from the visitor's device, not the word cookie. What changes is how much still works when the banner is declined: LeadJourney records the conversion without the person, and records the person only after consent. The GDPR page lists the controls and the sub-processors.

How does it recognise a returning visitor without a third-party cookie?

With a pseudonymous first-party identifier set by your own subdomain and kept on the server rather than in a third-party cookie, together with the click ID recorded on the first visit. Until the visitor fills in a form, books or calls, that identifier is not a person. Once they do, the sessions are stitched to the lead.

What happens on Safari after seven days, or when the visitor switches devices?

Safari caps script-set cookies at seven days, so a pixel meets a returning lead as a stranger. LeadJourney's identifier and the click ID are on the server, so day nine is the same journey. A device switch is stitched the moment the person identifies, because the phone's sessions and the laptop's form both belong to the lead they became.

Is first-party tracking GDPR compliant?

First-party is a design choice, not a certificate. Compliance comes from what is recorded and where: no personal data before consent, hashed fields to the platforms, processing and storage in Frankfurt, an Art. 28 DPA, a public sub-processor list and an appointed Data Protection Officer. The guide to GDPR compliant conversion tracking goes through the setup end to end.

Which ad platforms receive the hashed events, and does the pixel double count?

Meta through the Conversions API, Google Ads through Enhanced Conversions and offline conversion import, LinkedIn through its Conversions API and Microsoft Ads through offline conversions. Every event carries an event ID, so a conversion your pixel also saw is counted once, and you can keep the pixel running as long as you like.

Does it work with my consent management platform?

Yes. LeadJourney reads the consent state from the banner you already run and records accordingly: an anonymous event before consent, the full event after it. You do not replace the banner and you do not configure a second one, and the consent state is written onto every event in the log.

How long does setup take, and do I need a developer?

About 21 minutes: point a subdomain, add one script, connect the ad accounts and the CRM by OAuth, choose the event mapping. There is no fingerprinting library to add, no container to host and no engineering ticket. Onboarding is guided, on a call, if you want it.

See it on your own consent rates

See what your tracking keeps once the cookie is out of it.

Book a demo and we look at your own traffic: what the pixel sees per browser and consent state, and what a first-party layer would record.

Your workspace
Capture by browserCookie pixel against first-party tracking, last 30 days
What the cookie pixel saw268conversions, where the cookie was set and held
What LeadJourney recorded412conversions, first-party, no cookie, deduplicated
Recovered+144 conversions
BrowserCookie pixelFirst-party
Safari, iPhone61118
Chrome, desktop172196
Firefox3162
Brave or ad blocker436

Safari is where the seven-day cap bites. Brave is where the script never loads. Neither touched the server.