Practice · August 2025 · 7 min

First-party data people actually agree to

First-Party Signal Lab exists because “we collect it ourselves” became a slogan, not a discipline.

Notebook with figures beside a calculator

A waitlist that asks for name, email, phone, company size, job title, and “anything else we should know,” then writes every answer into a CRM and a user property, is not a first-party strategy. It is a surplus of personal data with a nicer hostname.

Purpose before field

Consent-based tracking analytics applies to forms as much as to pixels. If the purpose is “tell me when the cohort opens,” you need a way to send that email. You do not need a phone number. If you later want to qualify leads, that is a second purpose and a second ask — after the person has joined, not buried in the same submit.

In the Lab we strike fields until the remaining ones can be read aloud next to the purpose sentence. It feels severe. Learners usually keep three.

Storage is part of the agreement

If you say the address is for cohort notices and then sync it to a lookalike tool, you have changed the purpose. First-party collection does not license downstream advertising. Put the sync behind a separate, refused-by-default control, or do not do it.

Identifiers you invent

First-party cookies that remember a banner choice are often essential to honouring reject. First-party cookies that stitch browsing for advertising are not. The hostname does not decide the category. The purpose does. We see teams relabel the same stitching cookie after a rebrand and call the problem solved. It is not.

If you want help cutting a form and a first-party event list down to what people actually accept, ask about the Lab on the contact page.

← Journal