ConsentPixel – Privacy · Verified

Consent · Explainer · 2026

Website Trackers Explained: Tracking Cookies, Pixels & Tags

"Tracking cookies" is the phrase most people reach for, but it's only one piece of how websites watch their visitors. Pixels, tags, fingerprinting, session replay and server-side data flows all track people too — and several of them keep working even after cookies are blocked or deleted. This guide explains every kind of tracker in plain English: what each one does, how cross-site tracking works, how to stop them, and why "going cookieless" doesn't make the consent problem disappear.

CPConsentPixel Team Updated September 2026 15 min read Information, not legal advice
~30%
Of web traffic is already cookieless — Safari, Firefox and Brave block third-party cookies by default
6+ types
Trackers go far beyond cookies: pixels, tags, fingerprinting, session replay, local storage, server-side
Tech-neutral
Consent law applies whether the tracker is a cookie, a pixel, server-side — or nothing at all

Key takeaways

  • A tracking cookie is a third-party cookie that follows you across websites to build an advertising profile — distinct from the first-party cookies that keep you logged in.
  • Tracking is much bigger than cookies. Pixels, tags, browser fingerprinting, session replay and server-side data flows all track visitors, and many survive cookie deletion entirely.
  • Browsers fought back. Safari, Firefox and Brave block third-party cookies by default — but Chrome reversed course in 2025 and kept them, then shut down its Privacy Sandbox replacements.
  • "Cookieless" is not a compliance escape. Consent law is tech-neutral: it applies to pixels, fingerprinting and server-side tracking just as much as cookies — and server-side mostly makes tracking harder to see, not lawful.
  • For a site owner, the duty is yours. You can't rely on visitors deleting cookies; the law expects you to gate non-essential trackers until they consent — and to prove you did.

Start with the term everyone searches. A cookie is a small text file a website stores in your browser to remember something — and not all cookies track you. The distinction that matters is who set it:

  • First-party cookies are set by the site you're actually visiting. They keep you logged in, remember what's in your cart, and save your preferences. These are mostly benign and often essential — the site can't function without some of them.
  • Third-party cookies are set by a different domain — usually an advertising or analytics network embedded in the page. Because the same network is embedded across thousands of sites, its cookie can recognize you as you move around the web. That's a tracking cookie: a third-party cookie used to follow you across sites and build a profile, typically for ad targeting.

So when people ask "what are tracking cookies," the precise answer is: the third-party cookies that enable cross-site tracking. First-party cookies remembering your login aren't the problem; the ad network's cookie stitching your behavior together across the web is.

FIRST-PARTY COOKIE 🛒 shop.com — remembers your cart Set by the site you're on. Stays on that site. Mostly benign. ✓ often essential THIRD-PARTY TRACKING COOKIE shop.com news.com Same ad network embedded in both. Follows you between sites. = cross-site tracking

Tracking is bigger than cookies: the full family

Here's the reframe that most "tracking cookies" explainers miss, and it's the single most useful thing to understand in 2026: cookies are just one way to track people, and increasingly not even the main one. Block every cookie and a site can still identify and follow you through several other mechanisms. Meet the family:

TrackerWhat it isSurvives cookie deletion?
Tracking cookieThird-party cookie that follows you across sitesNo — deleting removes it
Tracking pixelA tiny invisible image or snippet (Meta Pixel, Google tag) that reports a visit or action to a third partyPartly — the pixel still fires
TagA snippet (often via Google Tag Manager) that loads other trackers — a container for pixels and analyticsYes — it just reloads
FingerprintingIdentifies your device from its configuration (fonts, screen, canvas) with no cookie at allYes — cookieless by design
Session replayRecords your clicks, scrolls and keystrokes to replay the sessionYes — not cookie-based
Server-side / S2SData collected on the site's server, then forwarded to vendors (Meta CAPI, server-side tag manager)Yes — invisible to the browser

Look at that right-hand column. Fingerprinting and server-side tracking don't use cookies at all, so "I deleted my cookies" or "we're going cookieless" does nothing to stop them. This is why the whole conversation has to move from "cookies" to "trackers." The question isn't whether a site uses cookies — it's what data leaves the visitor's browser (or your server), and to whom. We go deep on the session-replay category in session replay and GDPR.

Cross-site tracking explained

Several of your keywords circle the same idea — "cross-site tracking," "cross-website tracking," "what does allow cross website tracking mean" — so let's pin it down. Cross-site tracking is following a user across different websites to build a unified profile of their behavior, usually to target ads. A third-party cookie (or a fingerprint) set by an ad network embedded on Site A recognizes the same person on Site B, C and D, stitching a picture together.

That "Allow Cross-Website Tracking" toggle you've seen — most prominently in Safari's settings — controls exactly this. When it's on, sites can use third-party mechanisms to track you between sites; turning it off (which Safari does by default via its "Prevent Cross-Site Tracking" setting) blocks that stitching. On mobile, Apple's App Tracking Transparency (ATT) is the app-world equivalent: since 2021, iOS apps must show the "Ask App Not to Track" prompt before tracking you across other companies' apps and sites. Whether it's a browser toggle or an app prompt, the thing being controlled is the same: cross-context profiling.

How browsers fought back — and Chrome's U-turn

For years the story was "third-party cookies are dying." The 2026 reality is more interesting, and it changes how you should think about tracking. Here's where each major browser actually stands:

🧭Safari — Intelligent Tracking Prevention (ITP)Apple has restricted cross-site tracking since 2017 and has blocked third-party cookies by default since Safari 13.1 (March 2020). It now also caps JavaScript-set first-party cookies at a 7-day lifespan. Safari's "Prevent Cross-Site Tracking" is on by default.
🦊Firefox — Enhanced Tracking Protection (ETP)Firefox has blocked third-party tracking cookies by default since September 2019, and its Total Cookie Protection isolates cookies to the site that set them, breaking cross-site stitching.
🦁BraveBlocks third-party cookies and fingerprinting out of the box as a core feature.
🔵Chrome — the reversalAfter years of promising to remove third-party cookies, Google reversed course in April 2025 and kept them, then in October 2025 shut down the core Privacy Sandbox APIs (Topics, Protected Audience, Attribution Reporting and more) that were meant to replace them, citing low adoption. Chrome keeps third-party cookies on by default, with a user toggle in Privacy & Security settings.

The net effect is counterintuitive but important: Chrome kept cookies, but its "privacy-preserving replacements" died. Meanwhile Safari, Firefox and Brave keep blocking. Add it up and roughly 28–33% of web traffic is already cookieless by default — independent of anything Chrome does. So the "cookieless future" arrived in an inverted form: not because Chrome removed cookies, but because a large slice of your visitors already block them, and the industry's cookie replacements never took hold.

What's actually tracking your visitors right now?

Cookies are only part of it. See which trackers — cookies, pixels, tags and more — fire on your site, and which fire before consent, in about 10 seconds. No account.

Scan your site free →

The "cookieless" myth every vendor is selling

Because so much traffic already blocks cookies, an entire industry has grown up around "cookieless tracking" — server-side tracking, the Meta Conversions API, fingerprinting, first-party data pipelines. Vendors pitch these as the answer to cookie loss. Here's the part they leave out, and it's the most important thing in this guide: going cookieless does not make the consent problem go away.

Two facts make this concrete:

1Consent law is tech-neutralThe EU's ePrivacy rule (Article 5(3)) requires consent before storing or accessing information on a device, regardless of the technology — cookie, pixel, fingerprint or local storage. The GDPR and CCPA apply to the personal data, not the mechanism. As one analysis put it, the law "applies whether the cookie is first-party, third-party, server-side, or nonexistent." Swapping cookies for fingerprinting doesn't dodge consent; it just changes the tool.
2Server-side tracking mostly hides the tracking, not consents to itMoving trackers server-side (so data goes to your server first, then to vendors) is increasingly popular partly because it "vastly reduces the visible evidence" a plaintiff can gather from your site's front end. But in Smith v. Rack Room Shoes (N.D. Cal., January 2026) — the leading server-side case — the server-side setup helped dismiss some claims, yet the client-side wiretapping claims survived, and courts remain divided. Server-side isn't a consent solution; it's a way to make tracking harder to see. That's the opposite of what regulators and courts are rewarding.
The uncomfortable takeaway
A lot of "cookieless" advice quietly amounts to: keep tracking people, just in ways that are harder to detect. But the legal exposure follows the data and the consent, not the cookie. The durable position isn't to hide the tracking better — it's to make sure non-essential trackers, whatever their technology, wait for consent, and to be able to prove it. Visibility, not invisibility, is what holds up.

How to stop and remove trackers

A big share of these searches come from people who just want the trackers gone. Here's the honest, practical answer for both sides of the screen.

If you're a visitor

You can both delete existing tracking cookies and switch on protection against future tracking:

  • Chrome: Settings → Privacy and security → Third-party cookies (block them), and Clear browsing data → Cookies to remove stored ones.
  • Safari: "Prevent Cross-Site Tracking" is on by default; use Settings → Privacy → Manage Website Data to clear stored data.
  • Firefox: Enhanced Tracking Protection (Standard or Strict), plus Clear Data for cookies.
  • Edge: Tracking prevention (Balanced or Strict), and clear cookies in settings.

One honest caveat: deleting cookies removes what's already stored, but it doesn't stop future tracking — and it does nothing against fingerprinting or server-side tracking, which don't rely on cookies. That's why the browser tracking-protection settings matter more than repeatedly clearing cookies.

If you're a site owner (the part that actually matters)

Here's the pivot that reframes the whole topic: you can't rely on visitors deleting cookies, and you shouldn't want to. Privacy law puts the duty on you, not them. It expects your site to hold non-essential trackers until the visitor consents, to honor opt-out signals like Global Privacy Control, and to prove you did. Whether a visitor ever clears a cookie is irrelevant to your compliance — what matters is what your site fires, and when.

Several keywords ask this directly — "is IP tracking illegal," "is tracking IP address legal." The short answer is: tracking is generally legal when it's transparent and consented to, and illegal when it isn't. The nuances are worth getting right.

IP addresses and basic logging. Logging IP addresses for analytics or security is generally lawful with transparency (a privacy notice) and a lawful basis — under the GDPR, legitimate interest usually covers server logs and security, while marketing use leans toward consent. An IP address can itself be personal data under the GDPR. Simply looking up an IP is legal; the illegal uses are harassment, stalking, DDoS and swatting — not analytics. Reasonable retention (commonly around 90 days for server logs) is expected.

Consent before non-essential tracking. For non-essential trackers, the EU requires opt-in consent before they fire; US state laws require a working opt-out and honoring GPC. And this is where the US litigation wave lives: under California's Invasion of Privacy Act (CIPA), plaintiffs argue that trackers firing before consent are an unlawful interception, with statutory damages of $5,000 per violation under Cal. Penal Code §637.2. More than 800 CIPA claims were filed in 2025, and courts have held that a banner promising tracking is off while trackers fire anyway is a "representational failure" that can defeat a consent defense. For the full map of who must comply, the 2026 privacy laws overview and the IAPP's US State Privacy Legislation Tracker are the references to keep. This is general information, not legal advice.

What it means for your website

Pull the threads together and the site-owner takeaway is simple, even though the tracker landscape is messy. You don't need to memorize every mechanism. You need to know three things about your own site: what's tracking your visitors, whether it fires before they consent, and whether you can prove the answer.

That's harder than it sounds, because trackers hide. A pixel added through a tag manager and forgotten; a "cookieless" analytics tool that fingerprints instead; a server-side pipeline you can't see in the browser; a banner that says "off until you accept" while scripts load on page load anyway. The gap between what your consent banner claims and what your site actually does is exactly where enforcement and litigation live. Closing it isn't about picking the right tracker — it's about controlling the timing (nothing non-essential before consent) and keeping the receipts.

That's the job ConsentPixel — Privacy · Verified is built for: it scans what actually fires on your pages — cookies, pixels, tags and more — blocks non-essential third-party trackers until a visitor consents, honors Global Privacy Control, and logs each decision as evidence. It's the visibility-and-proof approach the "cookieless" pitches skip. You can see the whole platform on the consent management platform page, or start by seeing what's on your own site with the privacy scanner. This is information, not legal advice — but the one thing that holds up across every tracker type and every regime is the same: consent before it fires, provable after.

Frequently asked questions

What is a tracking cookie?

A tracking cookie is a third-party cookie — one set by a domain other than the site you're visiting, usually an advertising or analytics network embedded in the page. Because the same network appears across thousands of sites, its cookie recognizes you as you move around the web and builds a profile for ad targeting. That cross-site following is what makes it a "tracking" cookie, as opposed to a first-party cookie that simply keeps you logged in or remembers your cart. First-party cookies are mostly benign and often essential; third-party tracking cookies are the ones privacy laws and browsers target.

How do I remove or stop tracking cookies?

You can do both. To remove stored cookies, use your browser's "clear browsing data" tool and choose cookies. To stop future tracking, turn on tracking protection: Chrome lets you block third-party cookies in Privacy and security settings; Safari's "Prevent Cross-Site Tracking" is on by default; Firefox has Enhanced Tracking Protection (Standard or Strict); Edge has Tracking prevention. One caveat: deleting cookies removes what's stored but doesn't stop future tracking, and it does nothing against fingerprinting or server-side tracking, which don't use cookies. Browser tracking-protection settings matter more than repeatedly clearing cookies.

What is cross-site tracking?

Cross-site tracking (also called cross-website tracking) is following a user across different websites to build a unified profile of their behavior, usually to target ads. It works when a third-party cookie or a device fingerprint set by an ad network embedded on one site recognizes the same person on other sites, stitching their activity together. The "Allow Cross-Website Tracking" setting in browsers like Safari controls this — turning it off (the default in Safari via "Prevent Cross-Site Tracking") blocks the stitching. On mobile, Apple's App Tracking Transparency prompt is the equivalent control for apps.

Does cookieless tracking still need consent?

Yes. Consent law is technology-neutral. The EU's ePrivacy rule requires consent before storing or accessing information on a device regardless of the method — cookie, pixel, fingerprint or local storage — and the GDPR and CCPA apply to the personal data, not the mechanism. So switching to cookieless techniques like fingerprinting or server-side tracking doesn't remove the consent obligation; it just changes the tool. Server-side tracking in particular mainly reduces the visible evidence of tracking rather than making it lawful — courts have allowed client-side wiretapping claims to proceed even where server-side tracking was used. This is general information, not legal advice.

Is it legal to track IP addresses?

Generally yes, when it's transparent and has a lawful basis. Logging IP addresses for analytics or security is lawful if you disclose it in a privacy notice and have a legal basis — under the GDPR, legitimate interest typically covers server logs and security, while marketing use leans toward consent. An IP address can be personal data under the GDPR, and reasonable retention limits (commonly around 90 days for server logs) apply. Simply looking up an IP address is legal; the illegal uses are things like harassment, stalking, DDoS attacks and swatting, not ordinary analytics. As always, disclosure and a lawful basis are the requirements.

Are third-party cookies going away?

Not uniformly. Safari, Firefox and Brave block third-party cookies by default, so roughly 28–33% of web traffic is already cookieless. But Chrome — with about two-thirds of the market — reversed its plan to remove third-party cookies in 2025 and kept them, then shut down the core Privacy Sandbox APIs that were meant to replace them. So third-party cookies remain widely functional in Chrome while being blocked elsewhere. The practical result is a mixed environment: you can't rely on cookies working for all visitors, but they haven't disappeared either — and the consent obligations apply regardless of which technology you use.

The bottom line

"Tracking cookies" is a useful starting point but a misleading finish line. Third-party cookies are one way sites follow visitors across the web — but pixels, tags, fingerprinting, session replay and server-side data flows track people too, and several of them shrug off cookie deletion entirely. In 2026, a third of traffic is already cookieless, Chrome kept its cookies while its replacements died, and "going cookieless" mostly moves tracking somewhere harder to see.

Through all of it, one principle stays constant and technology-neutral: non-essential tracking needs consent before it fires, whatever the mechanism. For a visitor, that means using tracking protection, not just clearing cookies. For a site owner, it means the duty is yours — see what your site actually does, gate the trackers, and keep proof.

And that's not a legal question you have to guess at. It's a technical fact about your site you can check in about ten seconds.

See every tracker on your site — not just the cookies

ConsentPixel — Privacy · Verified scans what actually fires on your pages, blocks non-essential trackers before consent, honors GPC, and logs it as proof. Start with a free scan, then a 14-day trial.

Scan your site free →
No account needed for the scan · then a 14-day free trial, no credit card required
CP

The ConsentPixel Team

Privacy & Consent Compliance

ConsentPixel — Privacy · Verified is a consent platform delivered as a single JavaScript pixel: it scans what fires on your live pages, blocks third-party trackers of every kind until affirmative consent, honors opt-out and Global Privacy Control signals, and logs each decision as immutable evidence. This article is educational and not legal advice; facts reflect publicly reported information as of September 2026.

Information, not legal advice. This article explains website tracking technologies and related rules for general educational purposes and does not constitute legal advice or create an attorney–client relationship. Browser behavior, tracking technologies, and the law described here are evolving; details reflect publicly reported information as of September 2026 and may change, including Chrome's cookie plans, the status of Privacy Sandbox, and CIPA case law such as Smith v. Rack Room Shoes. How the GDPR, ePrivacy rules, CCPA, US state laws, and CIPA apply to your site depends on your specific facts and visitors. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. Consult qualified counsel for your situation. ConsentPixel — Privacy · Verified is not a law firm and does not by itself make any website compliant with any law.

Scroll to Top