Let's talk
← Back to all articles First-Party Data & Attribution 9 October 2026 ⏱ 15 min read

Server-Side Google Tag Manager (sGTM): Shielding Cookies from Safari ITP

How Safari ITP cuts the lifespan of JavaScript cookies to as little as 24 hours, and the engineering architecture that uses sGTM on your own cloud to issue legitimate Set-Cookie headers.

RM
Random Performance Engineering Paid traffic & server-side tracking specialists
9 October 2026
TECHNICAL DIAGNOSIS · OPERATIONS > BRL 100K/MONTH 15 min read

Operating scenario: Companies with sales cycles longer than 7 days lose campaign attribution on Safari and other WebKit-based browsers, recording qualified buyers as direct traffic.

Technical root cause: WebKit's Intelligent Tracking Prevention (ITP) discards cookies written in the browser via document.cookie after 7 days (or 24 hours if the link carries click parameters such as fbclid and gclid).

Engineering guideline: Deploying sGTM on your own cloud under the company's root domain (example: dados.empresa.com.br), writing cookies through the HTTP Set-Cookie header with HttpOnly and Secure directives.

How Safari ITP and WebKit Limit Attribution in Long Sales Cycles

WebKit, the engine behind the Safari browser on iOS, iPadOS and macOS, implements Intelligent Tracking Prevention (ITP). The technology was built with the stated goal of protecting consumer privacy, but it introduced deep challenges for digital marketing measurement engineering.

ITP applies severe restrictions to cookies written in the browser through JavaScript calls (document.cookie):

  • 7-Day Default Limit: Any persistent cookie created through client-side JavaScript has its lifespan capped at 7 days.
  • Sharp Cut to 24 Hours: If the user reaches the site through a link carrying tracking query parameters (such as fbclid, gclid, ttclid or msclkid), and the source domain has been classified by WebKit as a cross-site tracker, the cookie's validity drops to just 24 hours.

In operations that sell high-ticket products, postgraduate courses, corporate B2B services or real estate, the decision journey rarely ends on the same day. When the lead comes back to buy 10 days after the first click, the original cookie is already gone. The analytics system credits the transaction to the Direct Traffic channel, hiding the real effectiveness of the ad campaign.

The Fix: Server-Side GTM on Your Own Cloud

The data engineering answer to this block is to move the act of writing the cookie from the user's browser to the application server. Server-Side Google Tag Manager (sGTM) makes this infrastructure possible.

When you set up the server container under a subdomain of the corporate website's root domain (for example, coletor.empresa.com.br for a site at empresa.com.br), you establish a genuine First-Party Context.

How Issuance Works Over the HTTP Protocol:

Instead of running local scripts that call document.cookie, the browser tag sends a network ping to the sGTM subdomain. The server processes the request and responds with the Set-Cookie HTTP header. By browser standards, cookies delivered through a first-party network response are not subject to the forced shortening applied by ITP.

Technical Anatomy of the First-Party Set-Cookie Header

Below is an example of a network header configured on the server to shield session and conversion identifiers:

HTTP/2 200 OK
Content-Type: application/json
Set-Cookie: _fbp=fb.1.1726752000.987654321; Domain=.empresa.com.br; Path=/; Max-Age=31536000; Secure; HttpOnly; SameSite=Lax
Set-Cookie: _ga=GA1.1.849201928.1726752000; Domain=.empresa.com.br; Path=/; Max-Age=31536000; Secure; SameSite=Lax
Set-Cookie: _rand_uid=usr_c918f0a2; Domain=.empresa.com.br; Path=/; Max-Age=63072000; Secure; HttpOnly; SameSite=Strict

A look at each security directive applied:

  • Domain=.empresa.com.br: Makes the identifier available across all of the brand's subdomains (store, checkout, blog).
  • Max-Age=31536000: Sets a persistent validity of 1 year, which lets you follow complete commercial nurturing cycles.
  • Secure: Requires traffic to travel only over TLS/HTTPS encryption.
  • HttpOnly: Stops malicious third-party scripts from reading the cookie value through JavaScript, which strengthens compliance with information security guidelines.
  • SameSite=Lax: Protects the user against CSRF (Cross-Site Request Forgery) attacks while still sending the identifier on legitimate navigation.

DNS Delegation: CNAME vs Dedicated A/AAAA Records

WebKit updated ITP to inspect CNAME records (a technique known as CNAME Cloaking). If the dados.empresa.com.br subdomain points via CNAME to an unrelated external service, Safari may apply preventive limits.

The engineering recommendation for large operations is to provision a load balancer with a dedicated IP address (A and AAAA records) pointing directly to instances on Google Cloud Platform or AWS, keeping ownership of the network block within the organisation's own infrastructure.

Conventional Client-Side Tracking
  • Cookies created via document.cookie
  • Maximum retention of 24h to 7 days on Safari
  • Frequently blocked by DNS ad blockers and extensions
  • Distorted attribution in long cycles
Dedicated Server-Side Infrastructure (sGTM)
  • Cookies issued through the HTTP Set-Cookie header
  • Continuous retention of up to 1 to 2 years
  • Network traffic invisible to conventional blockers
  • Intact attribution of returning visitors back to the ad auction

Frequently Asked Questions about sGTM and ITP Protection

Does sGTM replace the traditional browser GTM?

sGTM works together with the web container. The browser container collects the user's events and sends a single data stream to the server. The server, in turn, distributes that information to Meta, Google Analytics, Google Ads and your CRM.

What does it cost to host sGTM on Google Cloud Platform?

For operations with medium to high traffic, a high-availability setup with 3 Cloud Run instances typically has an operating cost between 40 and 120 US dollars a month, a figure more than offset by the media efficiency it preserves on budgets above BRL 100k/month.

Is this architecture compliant with LGPD?

sGTM improves regulatory compliance. Because all data flows through your server first before reaching third-party platforms, the company can sanitize sensitive data, apply IP anonymization and honor user consent before any external call fires.

Want to shield your operation's data from Safari ITP?

Random Marketing's technical team implements high-availability sGTM containers integrated with the ad platforms.

I want to hire Random Marketing for my company ↗
TECHNICAL RIGOR & PRIMARY SOURCES

Official documentation & engineering references

Architecture guidelines, API specifications and official technical documentation consulted to support this dossier:

Indexing keywords: #sgtm server-side #google tag manager server #safari itp #first-party cookies #httponly cookies #first-party data infrastructure