PerformanceOctober 22, 202510 min

Cookieless marketing 2026: how to work without third-party cookies

What has changed with the abandonment of third-party cookies: how 40-60% of mobile conversions fall out of attribution, and what to do about it. Server-side tracking, first-party data, MMM.

Article cover:Cookieless marketing 2026: how to work without third-party cookies

The advertising account shows ROAS 4.2× - and in the CRM there are 40% fewer closed transactions than the pixel “sees”. Sound familiar? This is not a configuration error. This is the cookieless reality of 2025-2026, which most teams live in without realizing it.

I've been working with performance tracking since 2017. After iOS 14.5, I had three projects where the gap between desk ROAS and actual sales reached 55%. Not because the campaigns were bad - it’s just that the attribution broke down, and no one noticed it in time. Since then, on every new project, the first thing I do is compare my account data with the CRM. In 7 out of 10 cases the gap is more than 30%.

The main misconception about cookieless is that they think it’s about the future. It’s more correct to think that it’s already broken. You have it right now.

1. What happened: chronology of cookie refusal

It all didn’t start with Google Chrome, as is commonly believed. Safari blocked third-party cookies back in 2017 through Intelligent Tracking Prevention (ITP). Firefox - in 2019. By 2021, before Apple rolled out ATT (App Tracking Transparency) in iOS 14.5, mobile tracking was already operating with serious losses on ~35% of devices.

April 2021 - iOS 14.5 and ATT. Users began choosing “do not track” 80-85% of the time. IDFA - the device identifier on which all Meta/Facebook mobile attribution was based - dropped from ~70% coverage to 25-30%. The Meta account stopped “seeing” most of the conversions in iOS applications and the mobile browser.

With Chrome the situation lasted longer. Google has moved the date several times: first to 2022, then to 2023, then to 2024. As a result, by October 2025, Chrome had not completely disabled third-party cookies, but the Privacy Sandbox API (Topics, Protected Audience) had actually become the standard for new browser integrations. At the same time, mobile Chrome on iOS works through the WebKit engine - and ITP has already blocked everything there.

Bottom line: even without the "official" end of cookies, attribution is broken on mobile devices for MTA models already now.

2. How much data are you already losing (and don't know it)

Specific figures from practice: on projects with a budget of 500k-3M ₽/month, where I conducted a tracking audit in 2024-2025, the gap between “desk” conversions and real sales in CRM looked like this:

ChannelVisible conversions (office)Real sales (CRM)Attribution losses
Meta (iOS mobile)100%42-58%42-58%
Meta (desktop)100%75-85%15-25%
VKontakte (mobile)100%60-70%30-40%
Yandex Direct100%80-90%10-20%
Telegram Ads100%50-65%35-50%

Why Yandex is better than others? Because Yandex Metrica works through a first-party domain, and Crypta uses its own identification through Yandex-ID. But this does not mean that Metrica does not lose data - it simply loses less.

The most painful situation is when the dashboard algorithm is trained on “visible” conversions. If a pixel sees only 50% of purchases, it is optimized for an incomplete sample. It's called cookieless bias: The algorithm thinks that iOS users are not buying and stops showing them ads. In reality, they are buying - the pixel just doesn’t know.

3. Answer 1: server-side tracking (CAPI)

Server-side tracking - this is when conversion data is sent not from the user’s browser, but from your server directly to the advertising platform API. The browser (and its blocking) is completely bypassed.

For Meta this is called Conversions API (CAPI). For VKontakte - VK Ads API. For Yandex - offline conversions via the Metrica API. The mechanics are similar everywhere: the user performed the target action → your backend records the event → via the API notifies the advertising platform with hashed user data (email, phone, IP).

What does the implementation of CAPI give in practice - from my experience on three e-com projects in 2024-2025:

  • Visible conversions in the Meta account increased by 28-41% without changing the budget
  • Event Match Quality (EMQ) - a metric for the quality of matching events - increased from 4-5 to 7-8 out of 10
  • The algorithm stopped being “afraid” of the iOS audience and began to work normally on mobile
  • CPL for the iOS segment decreased by an average of 22% in the first 60 days after implementation

How to implement: the easiest way is through GTM Server-Side. You deploy a GTM server on Google Cloud Run or Stape.io (~5-15$/month), configure a CAPI tag, and specify an endpoint. This will take 4-8 hours for an average developer. The alternative is direct integration into the backend via the Meta Conversions API - more reliable, but requires backend development.

An important nuance: CAPI does not replace the client pixel - they work together. The pixel catches sessions, CAPI confirms conversions. Deduplication between them is configured via event_id.

4. Answer 2: first-party data infrastructure

First-party data — data that the user himself transferred to your company: email, phone, purchase history, behavior on the site. They belong to you, do not depend on platforms and do not disappear with any changes in browsers.

Three required elements of first-party infrastructure:

  • Form of capture with explicit consent — at every key step of the funnel. Not “subscribe to the newsletter”, but a specific offer: discount, checklist, demo. Conversion to filling out a form is 2-4% versus 0.5-1% without an offer - a difference of 3-4x the volume of the database per year.
  • CRM with full profile - not just a lead storage, but a system where each contact is associated with a source, history of interactions and purchases. Without this, “first-party data” is just a list of emails without context.
  • Offline conversions back to your account — closed transactions from CRM must be returned to advertising platforms. This closes the loop: the algorithm learns from real customers, not from those the pixel sees.

One of the cases from 2024: EdTech project, 800k ₽/month budget. Before the introduction of offline conversions, the VKontakte algorithm was optimized for the “application” - leads went for 180 ₽, but 3-4% were converted into payment. After we started transferring “payment” through offline conversions, the algorithm was rebuilt in 4 weeks. Leads grew to 340 ₽, but 9-11% were converted into payment. CAC decreased by approximately 35%.

5. Answer 3: MMM for channel estimation without tracking

Marketing Mix Modeling (MMM) is a statistical method that calculates the contribution of each channel to sales without tracking users. Works with aggregated data: how much was spent in each channel, how many sales received, taking into account seasonality and external factors.

MMM is not a new technology. It has been used by large FMCG companies since the 1980s. But the cookieless crisis made it relevant for medium-sized businesses - because attribution models (MTA) break down, but you still need to understand the real impact of the channels.

A simplified scheme: you take weekly data for 12-18 months - expenses for each channel, number of sales or revenue, seasonal flags (holidays, promotions). You build a linear regression or a Bayesian model. The output is coefficients showing how many sales each channel “explains,” all other things being equal.

The downside of MMM is the lag. The model works on historical data and does not tell you “this channel is not working today.” For operational decisions, a different methodology is needed. Therefore, MMM is a strategic tool (once a quarter), and not a replacement for daily monitoring of offices.

6. Yandex Crypta and Russian solutions

For projects with a focus on the Russian market, the situation is somewhat better than for international ones: Yandex Metrica uses first-party cookies through a js counter on your domain - they are not blocked by ITP as aggressively as third-party ones. Plus Crypta is a system for probabilistic identification of users within the Yandex ecosystem.

Crypta is still a closed technology: it is only available inside Yandex.Audience and Direct; identifiers cannot be exported outside. But for Direct attribution it gives +15-25% to visible conversions compared to pure pixel tracking - this is noticeable.

Practically: if your main channel is Yandex Direct, the priority is to set up offline conversions through the Metrica API. It’s free, done in 1 day, gives +15-20% to the visibility of conversions and teaches bidding strategies normally.

VKontakte released VK Ads Pixel Server-Side in 2024 - this is an analogue of Meta CAPI, integrated via GTM. It works worse than CAPI (Event Match Rate is lower due to a smaller base of identifiers), but better than nothing. On test projects it gave +18-25% to visible conversions.

7. Prioritization: where to start with a budget of up to 100k ₽/month

There is no universal answer, but there is a practical matrix. The cost of implementation is the developer's time plus infrastructure. The effect is an increase in visible conversions.

Budget/monthStep 1 (do now)Step 2 (after 1-2 months)Step 3 (every block)
Up to 100k ₽Offline conversions from CRM to Direct and VK via CSV downloadLead magnet + email database (Unisender / SendPulse)GTM Server-Side on Stape.io (~5$/month)
100k-500k ₽GTM Server-Side + CAPI for Meta / S2S for VKCRM with automatic transfer of offline conversionsFirst MMM on Excel based on historical data
500k-2M ₽Full S2S stack (Meta CAPI + VK S2S + Direct API)CDP or dataLayer with single user profileMMM via Robyn (Meta open-source) or Meridian (Google)
Over 2M ₽S2S + CDP + cross-channel deduplicationMMM + incrementality testing (geo-experiments)Own data warehouse + automatic MMM pipeline

With a budget of up to 100k ₽/month, there is no need to build a “full cookieless stack”. Three things need to be done: offline conversions to accounts, basic email/phone collection, and manually compare account data with CRM at least once a quarter. This is enough for the algorithm to be trained on real customers, and not on phantom “pixel” conversions.

8. What to do right now

Cookieless is not hype and not a “problem of the future.” This is already a broken attribution for most teams who continue to make budget decisions based on data that cannot be trusted. Algorithms learn from what the pixel sees—and the pixel sees 40-60% of mobile conversions.

Three actions for this week: compare conversions from your account with closed transactions in CRM over the past 30 days. If the gap is more than 20%, you have a problem. If more than 40% is a critical situation, and the first thing you need is server-side tracking. If there is nothing to compare with (no CRM or no data on closed transactions), the problem is even deeper, and you need to start with first-party data infrastructure.

Related topics: ROAS/ROMI calculator, KPI dashboard template, performance channels in Russia 2026.

If you want to analyze your specific situation, write to Telegram or through form. Starting consultation - 0 ₽.

More on the topic