Safari 27 tightens the screws on client-side tracking
by Edward

Apple's latest browser update strips even more tracking parameters, reclassifies popular analytics tools as fingerprinters, and starts blocking at the network layer. This further strengthens the case for server-side tracking.
Every year Apple tightens Safari's privacy rules. And every year marketers rediscover that another chunk of their attribution is lost. Safari 27, shipping with iOS 27, is the sharpest turn yet, because it changes not just what Safari blocks but where it blocks it.
What Safari 27 changes for tracking
Four shifts matter for anyone measuring marketing.
- Link Tracking Protection is spreading. Safari already strips some click identifiers from shared URLs. Version 27 adds more platforms: Threads'
xmt, YouTube'ssi, and X'stwclid,cnandcxt. Today this mostly applies in private browsing, but Apple has widened the net with every release - so we can expect this to be applied to all browsing at some point. - More tools count as fingerprinting. Safari's Advanced Fingerprinting Protection now classifies LinkedIn Insight Tag, Tealium, Segment and others as fingerprinting utilities. Once a tool lands on that list, Safari restricts its access to URL parameters, click IDs, referrer data, cookies and local storage. And if your CDP is classified this way, every tag you deploy through it inherits the same restrictions.
- Blocking moved down a layer. Safari now enforces part of its tracking protection at the network transport layer, checking the destination IP address rather than only the script or domain. That reaches tactics that used to slip past domain-based rules.
- Over-the-wire updates. Apple can push new privacy rules without shipping a new version of Safari. The list of blocked parameters and classified tools can grow at any time.
At a glance, here is what moved between the two releases — and what didn't:
| Behaviour | iOS 26 | iOS 27 |
|---|---|---|
Tracking script 'lifetime' ID (ajs_anonymous_id, _shopify_y) | Capped to 7 days | Capped to 7 days |
| Cookie set via a custom tracking domain | Capped to 7 days | Capped to 7 days |
| Link parameters stripped | Meta + Google click IDs (e.g. fbclid) | Adds YouTube si, X twclid / cn / cxt |
| Tools classified as fingerprinting | Known trackers | Adds LinkedIn Insight Tag, Tealium, Segment. Not Littledata. |
| A classified script's access to referrer, click IDs, URL parameters | Unrestricted for these tools | Restricted once classified |
| Where blocking happens | Script and domain level | Adds the network layer (destination IP) |
Why this breaks attribution
When a link parameter is stripped, the click that drove a sale arrives with no source attached, so paid traffic gets logged as direct or organic.
When a tool is reclassified, its pixel loses the identifiers it needs to match a visit to a customer.
When blocking happens at the network layer, moving your tracking to a subdomain on your own domain no longer guarantees the request gets through.
The result is familiar. Returning shoppers look like new visitors. A customer who clicks your Meta ad on mobile, then buys on desktop, is counted as two people. Ad platforms receive weaker signals, match quality drops, and your reported cost per acquisition drifts away from reality.
What this means if you use Segment
If you collect Shopify data through Segment, this update lands directly on you, because Segment's analytics.js is now on Apple's fingerprinting list.
Segment mints an anonymous ID (ajs_anonymous_id) and stores it in the browser. That storage was already capped — Safari deletes script-written cookies and local storage after seven days. Safari 27 adds a second squeeze: as a classified tool, the Segment script now has restricted access to referrer data, click IDs and storage, and some of its requests can be stopped at the network layer.
In practice, on the iPhone that means:
- Inbound signal thins out. The script sees less about where a visit came from, so more paid traffic lands as direct or organic — on top of the click IDs Safari now strips from links before the page even loads.
- Collection itself can be blocked. In private browsing and stricter modes, a classified script can be stopped from loading or from reaching its endpoint, not just limited in what it stores.
The loss is real but specific: it hits the shopper who leaves and returns later, and the one who clicks on mobile and buys on desktop. That is the customer worth the most and the one the browser can no longer hold onto.
The "first-party cookie" fix stopped working years ago
The standard answer to all of this has been a "first-party" tracking domain. Point a subdomain like data.yourstore.com at your vendor's servers with a CNAME record, set cookies from there, and — the pitch goes — Safari treats them as first-party and leaves them alone.
Apple closed that in stages. Safari 14, back in 2020, began capping cookies from CNAME-cloaked subdomains to seven days. Safari 16.4, in early 2023, went further and detects the mismatch by IP address, so even an A-record pointing at a third party gets the same seven-day cap.
The subdomain workaround has been dead for three years.
So when a vendor sells a custom-domain cookie as the cure for the "cookie apocalypse," look closely at what you'd actually get: a cookie Safari resets after a week. For your iPhone attribution, that is no change at all.
What Persistent ID does differently
We built Persistent ID precisely because those short-lived tricks were already failing. PersistentID does not try to smuggle a longer-lived cookie past the browser, and it does not depend on a CNAME domain.
It resolves identity server-side, binding each session to keys the browser never holds — your Shopify customer ID, email, and order data. There is nothing for Safari to cap, because nothing depends on browser storage surviving.
Apple restricts what scripts and cookies can do in the browser. It has no say over identity you resolve on your own servers from your own commerce data.
Why you need Littledata more than ever
Why not accept the gap? Because the shopper hasn't disappeared - only the browser's memory of them has. The moment they log in, enter an email, or check out, they can be reconnected to everything they did before.
Persistent ID stitches the anonymous session to the known customer server-side, then feeds the complete identity back to the tools that need it: Meta's Event Match Quality improves, and Klaviyo abandonment flows reach roughly 30% more shoppers by matching anonymous cart activity to known profiles.
The honest truth: a shopper who returns after seven days and never identifies is gone, for us and for every other Shopify tracking solution — no cookie, custom domain, or fingerprint recovers them on Safari.
Anyone claiming otherwise is running on out-dated information.
The takeaway
iOS 27 doesn't end tracking. It ends a decade of workarounds that pretended the browser could be tricked into remembering.
The cookie was never going to survive; your commerce data always would. Anchor identity there, server-side, and Apple's next release becomes something you read about rather than something you feel in your numbers.



