Marketing Use Cases - Cookies in Advertising
This guide explores how cookies are used in marketing and advertising, including pixel syncing, tracking, and audience building.
Common Marketing Scenarios
Scenario 1: Pixel Syncing
What It Is: Synchronizing user identifiers across different systems using tracking pixels.
How It Works:
- User visits advertiser's website
- Page loads tracking pixel from ad network
- Pixel request includes user ID from advertiser's cookie
- Ad network receives ID and syncs with their own cookie
- Both systems can now identify the same user
Example:
<!-- On advertiser site -->
<img src="https://tracker.adnetwork.com/sync?advertiser_id=user123" />
<!-- Ad network receives request -->
<!-- Sets cookie: Set-Cookie: ad_id=user123; Domain=adnetwork.com -->
Testing in Playground:
- Visit any playground domain
- Load pixel from another domain
- Check CloudWatch logs for pixel requests
- Observe cookie syncing behavior
Scenario 2: Conversion Tracking
What It Is: Tracking when users complete desired actions (purchases, sign-ups, etc.)
How It Works:
- User clicks ad and lands on site (tracking pixel fires)
- Ad network sets cookie with campaign ID
- User completes conversion
- Conversion pixel fires with same campaign ID
- Ad network attributes conversion to campaign
Cookie Flow:
Ad Click → Set Cookie: campaign=campaign123
Conversion → Send Cookie: campaign=campaign123 → Attribution
Testing in Playground:
- Set cookie with campaign ID on one domain
- Load pixel on another domain (simulating conversion)
- Verify cookie is sent with pixel request
Scenario 3: Retargeting
What It Is: Showing ads to users who previously visited your site.
How It Works:
- User visits advertiser site
- Tracking pixel sets cookie with user segment
- User visits other sites
- Ad network reads cookie and shows relevant ads
- User sees ads based on previous visit
Cookie Example:
Set-Cookie: segment=interested_buyer; Domain=adnetwork.com; SameSite=None; Secure; Max-Age=2592000
Testing: Use cross-domain pixel loading to simulate retargeting
Scenario 4: Audience Building
What It Is: Creating user segments based on behavior across multiple sites.
How It Works:
- Multiple sites use same ad network
- Ad network sets cookie on each site visit
- Cookie accumulates user behavior data
- Ad network builds audience profiles
- Profiles used for targeted advertising
Cookie Attributes:
Set-Cookie: audience_data={...}; Domain=adnetwork.com; SameSite=None; Secure; Max-Age=63072000
Pixel Tracking Implementation
Basic Pixel Tag
Simple Tracking:
<img src="https://tracker.com/pixel?event=page_view&page=home" />
With Cookie Sync:
<script>
var userId = getCookie('user_id');
var pixelUrl = 'https://tracker.com/pixel?user=' + userId + '&event=page_view';
</script>
<img src="<%= pixelUrl %>" />
Sequence Diagram - Basic Pixel Tracking:
(example.com) participant Tracker as Tracker Site
(tracker.com) participant Browser participant CloudWatch as CloudWatch Logs User->>Advertiser: Visit example.com/page Advertiser->>Browser: HTML with pixel tag Browser->>Browser: Parse HTML, detect
Cookie: (if any from tracker.com) Tracker->>Tracker: Log request details
(params, headers, IP) Tracker->>CloudWatch: Write log entry Tracker->>Browser: HTTP 200 OK
Content-Type: image/gif
1x1 transparent GIF Browser->>Browser: Render pixel (invisible)
Advanced Pixel (JavaScript Beacon)
More Reliable (handles failures):
function sendPixel(url) {
var img = new Image();
img.src = url;
// Also fires even if image fails to load
}
With Error Handling:
function trackEvent(event, data) {
var params = new URLSearchParams({
event: event,
...data,
cookie: document.cookie
});
var pixel = new Image();
pixel.onerror = function() {
// Fallback tracking
navigator.sendBeacon('/tracking', params.toString());
};
pixel.src = 'https://tracker.com/pixel?' + params.toString();
}
Sequence Diagram - Cookie Sync via Pixel:
(shop.example.com) participant Tracker as Tracker
(tracker.adnetwork.com) participant Browser participant CloudWatch as CloudWatch Logs User->>Advertiser: Visit shop.example.com Advertiser->>Browser: HTML page Browser->>Browser: Store advertiser cookies
(first-party) Note over Browser: JavaScript executes Browser->>Browser: Read cookie: user_id=abc123
(from shop.example.com) Browser->>Tracker: GET /pixel?adv_user=abc123&event=purchase
Cookie: (tracker cookies if SameSite allows) Tracker->>Tracker: Extract adv_user from query params Tracker->>Tracker: Match with own user database Tracker->>Browser: Set-Cookie: tracker_id=xyz789
Domain=tracker.adnetwork.com
SameSite=None
Secure Tracker->>CloudWatch: Log sync event
{adv_user: abc123, tracker_id: xyz789} Tracker->>Browser: HTTP 200 OK
1x1 GIF Note over Browser,Tracker: Cookie sync complete
Both systems can identify same user
Cookie Syncing Mechanisms
Server-Side Cookie Sync
Flow:
- Advertiser redirects to sync endpoint
- Sync endpoint reads advertiser cookie
- Sync endpoint sets ad network cookie
- User redirected back to advertiser
Example:
User → advertiser.com → tracker.com/sync?adv_id=123 → tracker.com sets cookie → back to advertiser.com
Sequence Diagram:
(advertiser.com) participant Tracker as Tracker
(tracker.com) participant Browser User->>Advertiser: Visit advertiser.com/page Advertiser->>Browser: Set-Cookie: adv_id=user123
Domain=advertiser.com Browser->>Browser: Store advertiser cookie Advertiser->>Browser: Redirect: 302 Found
Location: tracker.com/sync?adv_id=user123 Browser->>Tracker: GET /sync?adv_id=user123
Cookie: (advertiser cookie if same-site) Tracker->>Tracker: Read adv_id from URL params Tracker->>Tracker: Match adv_id with own user DB Tracker->>Browser: Set-Cookie: tracker_id=xyz456
Domain=tracker.com
SameSite=None
Secure Tracker->>Browser: Redirect: 302 Found
Location: advertiser.com/continue Browser->>Advertiser: GET /continue
Cookie: adv_id=user123 Note over Browser,Advertiser: Cookie sync complete
Both systems have user identifiers
Client-Side Cookie Sync
Flow:
- Advertiser page loads pixel
- Pixel request includes advertiser cookie value
- Ad network reads cookie from request
- Ad network sets their own cookie
Example:
<img src="https://tracker.com/sync?adv_user=abc123" />
<!-- Tracker reads adv_user, sets own cookie -->
Sequence Diagram:
(advertiser.com) participant Tracker as Tracker
(tracker.com) participant Browser User->>Advertiser: Visit advertiser.com/page Advertiser->>Browser: HTML with pixel: tracker.com/pixel?adv_user=abc123 Browser->>Browser: Execute JavaScript
Read cookie: adv_user=abc123 Browser->>Tracker: GET /pixel?adv_user=abc123
Cookie: (tracker cookies if any) Tracker->>Tracker: Extract adv_user from query params Tracker->>Tracker: Match with user database Tracker->>Browser: Set-Cookie: tracker_id=xyz789
Domain=tracker.com
SameSite=None
Secure Tracker->>Browser: HTTP 200 OK
1x1 GIF Note over Browser,Tracker: Cookie sync complete
Future requests include both cookies
Testing Pixel Syncing in Playground
Test 1: Basic Pixel Request
Procedure:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
user_id=test123 - Load pixel:
<img src="https://cookie-playground.pun7o.click/pixel?user=test123"> - Check CloudWatch logs
- Verify cookie value in logs
Test 2: Cross-Domain Pixel Sync
Procedure:
- Visit
https://cookie-playground.pun7o.click - Set cookie with user identifier
- Visit
https://site-a.cookie-playground.pun7o.click - Load pixel from parent domain
- Check if cookie is sent with pixel request
- Verify in CloudWatch logs
Test 3: Query Parameter Passing
Procedure:
- Load pixel with query parameters:
<img src="https://cookie-playground.pun7o.click/pixel?event=purchase&value=99.99&user=user123" /> - Check CloudWatch logs for parameters
- Verify all parameters logged correctly
Privacy and Compliance
GDPR Considerations
Requirements:
- Obtain user consent before setting tracking cookies
- Disclose cookie usage
- Provide opt-out mechanisms
- Allow cookie deletion
Implementation:
- Cookie consent banner
- Consent management platform (CMP)
- Honor user preferences
CCPA Considerations
Requirements:
- Disclose data collection
- Provide opt-out mechanism
- Honor "Do Not Sell" requests
Implementation:
- Privacy policy disclosure
- Opt-out mechanism
- Cookie management
Browser Restrictions
Current State:
- Third-party cookies being phased out
- SameSite policies enforced
- Enhanced privacy features
Alternatives:
- First-party data collection
- Server-side tracking
- Privacy-preserving APIs
- Contextual advertising
Real-World Examples
Example 1: E-commerce Retargeting
Scenario: User browses products but doesn't purchase
Cookie Flow:
- User visits
shop.example.com - Sets cookie:
viewed_products=item1,item2,item3 - User leaves without purchase
- Later visits
news.example.com - Ad network reads cookie
- Shows ads for viewed products
Example 2: Lead Generation
Scenario: User downloads whitepaper
Cookie Flow:
- User visits
company.com - Downloads whitepaper (form submission)
- Sets cookie:
lead_type=whitepaper_download - User visits partner sites
- Cookie indicates qualified lead
- Shows relevant B2B ads
Example 3: Attribution Tracking
Scenario: Track which ad led to conversion
Cookie Flow:
- User clicks ad:
adnetwork.com/click?campaign=summer_sale - Sets cookie:
campaign=summer_sale; source=google - User lands on
retailer.com - User makes purchase
- Conversion pixel fires with campaign cookie
- Attribution:
summer_salecampaign → conversion
Testing Scenarios in Playground
Scenario A: Simple Page View Tracking
- Visit playground domain
- Set cookie:
visitor_id=abc123 - Load pixel:
https://cookie-playground.pun7o.click/pixel?event=page_view - Check CloudWatch logs
- Verify visitor ID in logs
Scenario B: Cross-Domain Tracking
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
segment=high_value - Visit
https://cookie-playground.pun7o.click - Load pixel from subdomain A
- Verify cookie behavior across domains
Scenario C: Cookie Sync Simulation
- Visit domain A
- Set cookie:
advertiser_id=user456 - Load sync pixel:
https://domain-b/pixel?sync=1&id=user456 - Check if domain B receives and can use the ID
- Simulate cookie matching
Future of Marketing Cookies
Declining Third-Party Cookies
Why:
- Privacy concerns
- Browser restrictions
- Regulations (GDPR, CCPA)
Impact:
- Reduced cross-site tracking
- Need for alternatives
- Shift to first-party data
Alternatives
- First-Party Data: Collect data directly on your site
- Server-Side Tracking: Track via server logs
- Privacy Sandbox: Browser APIs (Topics API, FLEDGE)
- Contextual Advertising: Target based on content, not user
- Federated Identity: Login-based (e.g., Google, Facebook)
Migration Strategies
Short Term:
- Maximize first-party cookies
- Server-side cookie syncing
- Reduced reliance on third-party cookies
Long Term:
- Privacy Sandbox APIs
- Contextual targeting
- First-party data focus
Best Practices
- Transparency: Disclose cookie usage clearly
- Consent: Obtain proper user consent
- Minimization: Collect only needed data
- Security: Use Secure and HttpOnly flags
- Expiration: Set appropriate cookie lifetimes
- Testing: Test cookie behavior across scenarios
- Compliance: Follow privacy regulations
Related Topics
- First-Party vs Third-Party - Cookie classification
- Cross-Domain Behavior - Cross-domain scenarios
- HTTP Headers - Set-Cookie header details
- Using the Playground - Testing procedures
Next Steps
- Test pixel syncing in the playground
- Review HTTP Inspection to understand request/response details
- Learn about Browser Behaviors for privacy features