Analytics and Tracking

Cookie

Also called HTTP cookie, browser cookie

A small piece of text a browser stores for a website and returns automatically on later requests.

Quick facts: Cookie

Category
Analytics and Tracking
Also called
HTTP cookie, browser cookie
Level
Beginner
Affects
Logins and baskets, analytics accuracy, advertising, consent obligations
Where to see it
Browser developer tools storage panel, Google Tag Manager, your consent banner settings
In this article4
  1. How a cookie works
  2. Why cookies matter
  3. Common mistakes with cookies
  4. What to do about them

A website asks the browser to remember a short piece of text — a name, a value and an expiry date. The browser stores it and hands it back automatically every time it makes a request to that site. That is the whole mechanism. Nothing is installed, nothing runs, and a cookie cannot read files on the device or watch what happens in another application.

What varies is who set it and how long it lasts. A cookie set by the site in the address bar is a first-party cookie; one set by another domain whose script is embedded in the page is a third-party cookie. One that vanishes when the browser closes is a session cookie; one with a future expiry date is a persistent cookie. Those two distinctions, source and lifetime, decide almost everything else about how a cookie behaves.

Why cookies matter

Without them the web forgets you between clicks. A shopping basket empties when you open a product page, a login has to be repeated on every screen, and a language preference never sticks. Those are the cookies nobody argues about, because the site simply will not function without them.

The contested ones are the cookies that exist for measurement and advertising: the identifier that lets analytics recognise a returning visitor as the same person, the value that ties a purchase back to the ad that produced it. They are useful, they are not necessary for the page to load, and that difference is exactly what the law hangs on. It is also why browsers have been steadily shortening how long some cookies survive.

Common mistakes with cookies

The first is a cookie policy written from a template that lists cookies the site does not set and omits the ones it does. That is worse than no policy at all, because it is a documented, checkable inaccuracy. Audit what your site actually stores rather than copying a competitor.

The second is assuming a cookie equals a person. It identifies a browser on one device. The same customer on a phone and a laptop is two cookies, and a shared office computer can be several people behind one. The third is loading advertising and analytics cookies before anyone has agreed to them, then showing a banner that pretends to ask.

What to do about them

Open your own site in a private window, look at the storage panel in the browser’s developer tools, and list what appears before you touch anything and after you accept a banner. Most owners are surprised, usually by a plugin or an embedded video player nobody remembered adding.

Then sort that list into cookies the site needs to work and cookies that exist for marketing, block the second group until consent is given, and make the cookie table in your policy match the list exactly. If you run tags through Google Tag Manager, that is where the blocking is easiest to enforce, because every tag sits in one place instead of being scattered through the theme.

Do and do not

Do

  • Audit what your site really stores before writing a policy
  • Separate necessary cookies from marketing cookies
  • Hold marketing cookies until consent is given

Do not

  • Copy a cookie table from another website
  • Treat one cookie as one customer
  • Fire advertising tags before the banner is answered

Questions people ask about this

Are cookies dangerous?

A cookie is stored text, not a program, so it cannot infect a device or read your files. The risk is a privacy one: identifiers stored across many sites can build a profile of browsing behaviour. That is why browsers restrict cookies set by other domains and why consent rules apply to marketing cookies rather than to the ones a site needs to function.

Which cookies need consent?

Anything that is not strictly necessary for the service the visitor asked for. A login session, a shopping basket and a security token are necessary. Analytics, advertising and personalisation cookies are not, so they should stay switched off until the visitor agrees. The safest test is simple: would the page still work correctly without it?

What happens to my data if visitors block cookies?

Reporting gets thinner rather than disappearing. Returning visitors look like new ones, sessions fragment, and conversions become harder to connect to the click that caused them. Plan for it by watching totals and trends instead of individual journeys, and by comparing platform reports against something you can count directly, such as enquiries received.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.