Server-Side Google Tag Manager (sGTM): Shielding Cookies from Safari ITP
How Safari ITP cuts the lifespan of JavaScript cookies to as little as 24 hours, and the engineering architecture that uses sGTM on your own cloud to issue legitimate Set-Cookie headers.
Operating scenario: Companies with sales cycles longer than 7 days lose campaign attribution on Safari and other WebKit-based browsers, recording qualified buyers as direct traffic.
Technical root cause: WebKit's Intelligent Tracking Prevention (ITP) discards cookies written in the browser via document.cookie after 7 days (or 24 hours if the link carries click parameters such as fbclid and gclid).
Engineering guideline: Deploying sGTM on your own cloud under the company's root domain (example: dados.empresa.com.br), writing cookies through the HTTP Set-Cookie header with HttpOnly and Secure directives.
How Safari ITP and WebKit Limit Attribution in Long Sales Cycles
WebKit, the engine behind the Safari browser on iOS, iPadOS and macOS, implements Intelligent Tracking Prevention (ITP). The technology was built with the stated goal of protecting consumer privacy, but it introduced deep challenges for digital marketing measurement engineering.
ITP applies severe restrictions to cookies written in the browser through JavaScript calls (document.cookie):
- 7-Day Default Limit: Any persistent cookie created through client-side JavaScript has its lifespan capped at 7 days.
- Sharp Cut to 24 Hours: If the user reaches the site through a link carrying tracking query parameters (such as
fbclid,gclid,ttclidormsclkid), and the source domain has been classified by WebKit as a cross-site tracker, the cookie's validity drops to just 24 hours.
In operations that sell high-ticket products, postgraduate courses, corporate B2B services or real estate, the decision journey rarely ends on the same day. When the lead comes back to buy 10 days after the first click, the original cookie is already gone. The analytics system credits the transaction to the Direct Traffic channel, hiding the real effectiveness of the ad campaign.
The Fix: Server-Side GTM on Your Own Cloud
The data engineering answer to this block is to move the act of writing the cookie from the user's browser to the application server. Server-Side Google Tag Manager (sGTM) makes this infrastructure possible.
When you set up the server container under a subdomain of the corporate website's root domain (for example, coletor.empresa.com.br for a site at empresa.com.br), you establish a genuine First-Party Context.
How Issuance Works Over the HTTP Protocol:
Instead of running local scripts that call document.cookie, the browser tag sends a network ping to the sGTM subdomain. The server processes the request and responds with the Set-Cookie HTTP header. By browser standards, cookies delivered through a first-party network response are not subject to the forced shortening applied by ITP.
Technical Anatomy of the First-Party Set-Cookie Header
Below is an example of a network header configured on the server to shield session and conversion identifiers:
HTTP/2 200 OK
Content-Type: application/json
Set-Cookie: _fbp=fb.1.1726752000.987654321; Domain=.empresa.com.br; Path=/; Max-Age=31536000; Secure; HttpOnly; SameSite=Lax
Set-Cookie: _ga=GA1.1.849201928.1726752000; Domain=.empresa.com.br; Path=/; Max-Age=31536000; Secure; SameSite=Lax
Set-Cookie: _rand_uid=usr_c918f0a2; Domain=.empresa.com.br; Path=/; Max-Age=63072000; Secure; HttpOnly; SameSite=Strict
A look at each security directive applied:
Domain=.empresa.com.br:Makes the identifier available across all of the brand's subdomains (store, checkout, blog).Max-Age=31536000:Sets a persistent validity of 1 year, which lets you follow complete commercial nurturing cycles.Secure:Requires traffic to travel only over TLS/HTTPS encryption.HttpOnly:Stops malicious third-party scripts from reading the cookie value through JavaScript, which strengthens compliance with information security guidelines.SameSite=Lax:Protects the user against CSRF (Cross-Site Request Forgery) attacks while still sending the identifier on legitimate navigation.
DNS Delegation: CNAME vs Dedicated A/AAAA Records
WebKit updated ITP to inspect CNAME records (a technique known as CNAME Cloaking). If the dados.empresa.com.br subdomain points via CNAME to an unrelated external service, Safari may apply preventive limits.
The engineering recommendation for large operations is to provision a load balancer with a dedicated IP address (A and AAAA records) pointing directly to instances on Google Cloud Platform or AWS, keeping ownership of the network block within the organization's own infrastructure.
Conventional Client-Side Tracking
- Cookies created via document.cookie
- Maximum retention of 24h to 7 days on Safari
- Frequently blocked by DNS ad blockers and extensions
- Distorted attribution in long cycles
Dedicated Server-Side Infrastructure (sGTM)
- Cookies issued through the HTTP Set-Cookie header
- Continuous retention of up to 1 to 2 years
- Network traffic invisible to conventional blockers
- Intact attribution of returning visitors back to the ad auction
Frequently Asked Questions about sGTM and ITP Protection
Does sGTM replace the traditional browser GTM?
sGTM works together with the web container. The browser container collects the user's events and sends a single data stream to the server. The server, in turn, distributes that information to Meta, Google Analytics, Google Ads and your CRM.
What does it cost to host sGTM on Google Cloud Platform?
For operations with medium to high traffic, a high-availability setup with 3 Cloud Run instances typically has an operating cost between 40 and 120 US dollars a month, a figure more than offset by the media efficiency it preserves on budgets above BRL 100k/month.
Is this architecture compliant with LGPD?
sGTM improves regulatory compliance. Because all data flows through your server first before reaching third-party platforms, the company can sanitize sensitive data, apply IP anonymization and honor user consent before any external call fires.
Want to shield your operation's data from Safari ITP?
Random Marketing's technical team implements high-availability sGTM containers integrated with the ad platforms.
I want to hire Random Marketing for my company ↗Official documentation & engineering references
Architecture guidelines, API specifications and official technical documentation consulted to support this dossier: