Internet Tracking, cookies and what follows you around
How web tracking works: cookies, pixels and fingerprints
The four mechanisms that follow you across sites, why deleting cookies stopped being enough, and the settings that actually reduce it.
The short answer
- Web tracking runs on four mechanisms: cookies, pixels and tags, device fingerprinting, and identity graphs keyed to your email address.
- Deleting cookies no longer does much, because three of the four mechanisms store nothing in your browser to delete.
- A tracking pixel reports on you by the simple act of being requested, and server side tagging moves that request off your device entirely, where nothing you install can block it.
- Fingerprinting measures your device rather than storing an identifier, so it survives private windows, new addresses and cleared history.
- The most durable identifier is the email address you type at checkout, scrambled into a stable string that links your phone, your laptop and your tablet to one profile.
- The best value settings are a browser with tracking protection on, one maintained content blocker, a reset advertising identifier, and a separate email address for shopping.
Four mechanisms do almost all of web tracking: cookies, pixels and tags, device fingerprinting, and identity graphs built from things you typed yourself. They are layered deliberately. Cookies were the original method and are the weakest now, so the industry moved its weight onto the other three, all of which survive a cleared cookie jar. That is the single most useful thing to understand. Deleting cookies used to be a real defense and today it is housekeeping, because the durable identifier is no longer stored in your browser at all. It is your email address, and a rough sketch of your device.
Cookies: first party, third party and the difference
A cookie is a short piece of text a site asks your browser to keep and send back on every later request to that same domain. That is all it is. It cannot read your files, and it carries no meaning on its own. The power comes from the value inside it, which is usually a random identifier that lets a server recognize the same browser again.
A first party cookie belongs to the domain in your address bar. It keeps you signed in, remembers your basket and your language. Break these and the web stops working, which is why blocking all cookies is bad advice.
A third party cookie belongs to a different domain that the page loaded something from: an ad slot, an analytics script, an embedded video or a share button. Because dozens of unrelated sites embed the same handful of companies, one identifier is seen by one company across all of them. That list of pages is the product.
Third party cookies are now blocked by default in several browsers, and the change was significant enough that the industry rebuilt around it. Trackers responded by moving into first party space: a script served from a subdomain of the site you are visiting looks first party to your browser, even when the data flows straight back to an outside company. If you want the legal side of who is allowed to set what, and what the banner is really asking, see what reject all actually does.
Pixels, tags and server side tracking
A tracking pixel is a request your browser makes to a measurement company while a page loads. Historically it was a transparent one pixel image, which is where the name comes from. Today it is usually a script, but the mechanism is unchanged: making the request is the report.
The request itself carries plenty without any cookie at all. The address of the page you are on, the page you came from, your network address, your browser and operating system version, your screen size and your time zone. Sites add events on top: viewed product, added to basket, started checkout, purchased, with the amount. This is how an ad is credited with a sale.
Two upgrades made this harder to see. Click identifiers are tags appended to a link when you follow it, so the destination knows which ad or email you came from even if nothing else survives the jump. They are visible in the address bar if you know where to look, which the anatomy of a URL explains. The bigger one is server side tagging: the site collects the event and its own server forwards it to the ad platform. Your browser only ever talks to the site you chose to visit, so a content blocker sees nothing to block, and neither does filtering at the DNS level. Nothing installed on your device can stop it.
Fingerprinting: recognizing the device itself
Fingerprinting stores nothing. It measures your device and uses the combination as a name. Screen dimensions, installed fonts, language, time zone, the exact way your graphics hardware draws a test image, the shape of your audio processing, the browser version down to the minor number. Each detail is boringly common. Fifty of them together are frequently unique, or rare enough to single you out in a crowd of millions.
Because there is nothing saved, there is nothing to clear. Private browsing does not help. Changing your network address does not help either, which is worth remembering when you read the marketing for a consumer VPN, since the address is only one signal among dozens.
The honest position on defending against it: you can reduce it, not defeat it. Browsers that fight fingerprinting do so by making many users look identical, reporting rounded screen sizes and a generic font list. That works only if you leave the defaults alone. Piling on unusual extensions and exotic settings makes you more distinctive, not less, which is the trap most privacy enthusiasts fall into.
Identity graphs: the email address as the real key
This is what replaced the third party cookie, and most people have never heard of it. When you buy something, sign up for a newsletter or log into a site, you hand over an email address or a phone number. The site scrambles it into a fixed string with a hash function and sends that to its ad and measurement partners. Anyone else holding the same email address produces the same string, so two companies can confirm they are dealing with the same person without ever exchanging the address in readable form.
Build that across thousands of retailers, publishers and apps and you get an identity graph: one profile that links your work laptop, your home laptop, your phone and your tablet, because you have used the same address on all of them. It does not care about cookies, private windows or a new phone. Hashing is often described as anonymizing, and it is not: the string is stable and reversible in practice for any address someone already holds.
Phones add their own key, an advertising identifier the operating system gives to apps. It is resettable and it can be switched off, which is one of the few settings on this page with an immediate effect. If you want to know what a company holds about you and how to make it stop, your rights over your own data are the practical route, particularly in the UK and EU where objecting to profiling is a defined right.
What your browser can and cannot block
| Mechanism | Blocked by browser defenses | Survives clearing cookies | What actually reduces it |
|---|---|---|---|
| Third party cookies | Yes, by default in several browsers | No | Nothing more needed |
| First party trackers on a subdomain | Partly, by blocklist | Usually yes | A maintained content blocker |
| Pixels and click identifiers | Partly | Yes | A blocker, plus stripping link tags |
| Server side tagging | No | Yes | Only the law and the site's own choices |
| Fingerprinting | Partly, by making users look alike | Yes | A default browser configuration |
| Hashed email and phone matching | No | Yes | Giving a different address, or none |
Read the bottom two rows twice. They are the reason a privacy setup built entirely out of browser settings feels thorough and misses most of the modern pipeline. A content blocker is still worth running, because it removes a large share of the first four rows at once, but choose one that is actively maintained and understand that it reads every page you open, which is exactly the permission that makes browser extensions risky when the maintainer changes hands.
A routine that is worth the effort
Ranked by result per minute spent.
- Use a browser with tracking protection on by default, or turn the strict setting on in the one you have. This handles the easy mechanisms permanently and needs doing once.
- Install one content blocker. One. Several do not stack usefully and each extra one is another extension reading every page.
- On your phone, reset the advertising identifier and turn off app tracking permission. Then look in the settings of the two or three large accounts you actually use and turn off ad personalization there.
- Use a second email address, or per site aliases, for shopping and newsletters. This is the only move that touches identity graphs, and it is the one most people skip.
- Keep a separate browser profile for the accounts you stay signed into, and browse everything else in the other one. Being logged in is what welds your activity to a named person.
- Once a year, ask two or three companies for a copy of your data and, if you want, close accounts you no longer use properly instead of abandoning them.
What you should not expect is invisibility. The realistic goal is to be a poorer, noisier signal: fewer linked identifiers, less purchase history attached to a name, less of your life reconstructable by a company you have never dealt with. That is achievable in an afternoon, and it holds up.
Common questions
Does private browsing stop tracking?
Only partly. A private window throws away cookies and history when you close it, which breaks the weakest kind of tracking. It does nothing about fingerprinting, nothing about server side measurement, and nothing at all once you sign in or type your email address, because that identifies you directly no matter what window you used.
Do I still need to clear my cookies?
Occasionally, and mostly for other reasons. Clearing cookies signs you out everywhere and can fix a site that is behaving oddly. As a privacy measure it resets one identifier while leaving your device fingerprint and every hashed email match untouched. A browser that blocks third party cookies by default is worth far more than clearing them by hand.
What is the difference between a cookie and a pixel?
A cookie is stored on your device and sent back to the domain that set it. A pixel is not stored anywhere: it is a request your browser makes to a measurement company while the page loads, and the details attached to that request are the data. A pixel works even when every cookie is blocked, which is why sites rely on it.
Can a website see my real name?
Not from tracking alone. What it starts with is an identifier, a device sketch and a history of pages. A name appears the moment you sign in, buy something, or enter an email address anywhere in a network that shares matched identifiers. That is normally how an anonymous profile becomes a named one, not clever detective work on the browser side.
Do ad blockers stop all of it?
No, though a maintained blocker removes a good share. It cuts third party requests, many pixels and many first party tracking scripts. It cannot touch anything collected by the site and forwarded from its own servers, and it cannot undo an email address you handed over. Treat it as one useful layer rather than a complete answer.