Cross-Site Tracking and Your Kids: What Follows Them Around the Internet
Table of Contents

Cross-Site Tracking and Your Kids: What Follows Them Around the Internet

Third-party cookies, tracking pixels, and browser fingerprinting build detailed profiles of your child's online behavior. Here's what they are and how to reduce them.

Your son spent 45 minutes on a Minecraft strategy forum last Tuesday. He didn’t log in to anything. He didn’t enter his name or email. He just read articles. Three days later, on a completely different platform—a homework help site—he sees ads for Minecraft merchandise. On the school’s news aggregator app, more Minecraft ads. On YouTube, Minecraft channel recommendations from creators he’s never heard of.

This is cross-site tracking working exactly as designed. Your son’s reading behavior on the first site was observed, recorded, and shared with advertising networks that followed him everywhere he went afterward. He left a data trail without creating an account, entering any information, or being told it was happening.

Key Takeaways

  • Third-party cookies, tracking pixels, and browser fingerprinting all build behavioral profiles across multiple unrelated sites
  • Cookie consent popups rarely prevent tracking—they often exist to satisfy legal requirements while still allowing most tracking by default
  • Firefox with Enhanced Tracking Protection and privacy-focused browsers like Brave meaningfully reduce cross-site tracking
  • Children’s sites face additional restrictions under COPPA, but enforcement is inconsistent and workarounds are common
  • Browser fingerprinting is the most durable tracking method and cannot be blocked by cookie settings alone

How Cross-Site Tracking Actually Works

Most people understand cookies in a vague sense—they know websites “save cookies”—but the mechanism is worth understanding precisely because that understanding changes how you configure browsers.

First-party cookies are set by the website you’re actually visiting and are used for legitimate purposes: keeping you logged in, remembering your cart, saving your preferences. These are generally fine.

Third-party cookies are set by entities other than the website you’re visiting. When you load a page on Gaming-Site.com, that page may include content from an ad network, a social media share button, a video player, and an analytics service—each of which can set their own cookies. The ad network cookie records that you visited Gaming-Site.com. The next time you visit News-Site.com, if News-Site.com uses the same ad network, that network recognizes the same cookie and knows you went from Gaming-Site.com to News-Site.com.

Scale this across thousands of sites using the same few major ad networks (Google, Meta, and a handful of others dominate the market) and you have a comprehensive behavioral profile—built without any account registration, just browsing.

The consent management popups that appear on most websites exist primarily to satisfy legal requirements (GDPR in Europe, CCPA in California). What they typically don’t disclose clearly:

The default is tracking. On most implementations, the “Accept” button is visually prominent and the “Reject all” or “Manage preferences” option is buried or de-emphasized. The FTC has flagged this pattern as “dark pattern” design.

Rejecting doesn’t always work. Several audits by privacy researchers have found that even selecting “Reject all” on some implementations still sets tracking cookies due to implementation bugs or intentional non-compliance.

The vendor list is enormous. The “Manage preferences” view on many sites reveals 200-700 advertising vendors that the site wants to share data with. There’s no practical way to review these individually.

First-party tracking continues. The site itself collects and retains data about what you read, how long you stayed, and what you clicked—this isn’t covered by third-party cookie consent at all.

For children’s sites, the Children’s Online Privacy Protection Act (COPPA) provides some additional protection—our guide on kids’ online privacy and COPPA covers this in detail—but COPPA covers children under 13 and enforcement is inconsistent.

Even if you disable all cookies, trackers have a second method that doesn’t use cookies at all: browser fingerprinting.

Your browser reveals an enormous amount of information as part of normal operation: your operating system, browser version, screen resolution, installed fonts, timezone, language settings, hardware characteristics, and more. Each of these attributes is common; but combined, they create a profile that is statistically unique—or nearly so. The Electronic Frontier Foundation’s Panopticlick research found that 83% of browsers have a unique fingerprint.

Fingerprinting is used to track users across sites without cookies and is particularly difficult to block because:

  • It doesn’t require any storage permission
  • It operates through normal browser function, not anything that can be blocked by cookie settings
  • Rotating IP addresses doesn’t defeat it—the browser characteristics remain consistent

For children, fingerprinting is particularly concerning because it persists even if a child clears cookies, uses a private browsing window, or thinks they’ve “gone incognito.”

Tracking MethodBlocked by Cookie SettingsBlocked by “Do Not Track”Blocked by VPNBest Mitigation
Third-party cookiesPartiallyNoNoBrowser privacy settings
Tracking pixelsNoNoNoTracker blockers (uBlock)
Browser fingerprintingNoNoNoPrivacy browser (Brave, Firefox)
First-party trackingNoNoNoCareful platform selection
Local storage trackingNoNoNoRegular clearing + extensions

Practical Browser Settings That Actually Reduce Tracking

Mozilla Firefox includes Enhanced Tracking Protection (ETP) by default, which blocks known third-party trackers, fingerprinting scripts, and cryptominers. For stronger protection:

  • Settings → Privacy & Security → Enhanced Tracking Protection → select Strict (blocks more trackers; occasionally breaks site functionality, but fixes are usually simple)
  • Enable DNS over HTTPS (Settings → Privacy & Security → scroll to DNS over HTTPS) to prevent ISP-level tracking of domains visited
  • Add uBlock Origin extension (free, open-source) for additional tracker and ad blocking

Firefox also offers Multi-Account Containers—an extension that separates browsing contexts so that a tracker on a gaming site can’t follow you to a homework site because they run in separate isolated containers. This is particularly useful for older teens who use multiple types of sites.

Chrome

Chrome has implemented third-party cookie blocking but the rollout has been inconsistent and the underlying model (Privacy Sandbox) has been criticized by privacy researchers as replacing cookies with a different tracking mechanism.

For Chrome users:

  • Settings → Privacy and Security → Cookies and other site data → Block third-party cookies
  • Add uBlock Origin extension
  • Consider switching to Firefox or Brave for a child’s primary browser

Brave Browser

Brave is a Chromium-based browser (compatible with Chrome extensions) with aggressive privacy defaults:

  • Blocks third-party cookies, ads, and trackers by default
  • Includes fingerprinting protection
  • Blocks bounce tracking (a technique that circumvents standard third-party cookie blocking)

Brave is the most privacy-protective mainstream browser without requiring technical configuration. It’s a reasonable default for teens and older children.

Privacy-Focused Options for Younger Children

For children under 13, consider browsers designed specifically for kids: Kiddle (Google-powered but with content filtering), or simply using a standard browser with strict parental controls and the settings above applied.

What COPPA Actually Covers (and What It Doesn’t)

The Children’s Online Privacy Protection Act requires websites and apps directed at children under 13—or websites that know they’re collecting data from children under 13—to obtain verifiable parental consent before collecting personal information.

What this means in practice:

  • Sites explicitly directed at young children (Club Penguin successors, kids’ entertainment sites) must comply
  • General-audience sites (YouTube, Google) that don’t verify age typically claim their service is “not directed at children under 13” and put the responsibility on parents
  • Many sites that children regularly use are not technically “directed at” children even when children are a significant portion of their actual audience

The FTC enforces COPPA and has levied significant fines ($170 million against YouTube/Google in 2019; $520 million against Epic/Fortnite in 2023) but cannot monitor every platform continuously.

Cross-site tracking is specifically addressed in COPPA regulations: third-party tracking and behavioral advertising involving children under 13 requires parental consent. But without age verification, this protection is often not applied in practice.

Having the Tracking Conversation With Kids

The concept of cross-site tracking is actually a useful teaching tool for something broader: the internet is not a neutral public space where you move invisibly. Your behavior is observed, recorded, and used by people you don’t know, on behalf of entities you’ve never heard of.

The age-appropriate version of this conversation:

For kids 8–10: “Websites know what other websites you visited, kind of like if a store could see the bag from every store you’d been to that day. That’s how ads know what you’ve been looking at.”

For kids 11–13: Walk through a real example. Show them the “Manage preferences” page on a major site and count the vendor list together. Show them what browser fingerprinting is using coveryourtracks.eff.org (an EFF tool that shows what a site can learn about your browser). This usually lands.

For teens 14+: They’re often already aware that tracking exists but underestimate how comprehensive it is. The EFF’s full explanation of browser fingerprinting and how it works at the JavaScript level is appropriate for technically curious older teens.

Our article on digital literacy and cybersecurity basics provides the broader framework for making these individual concepts part of an ongoing conversation.

What to Watch For Over the Next 3 Months

Chrome’s third-party cookie blocking rollout continues to evolve. Alternative tracking techniques—particularly bounce tracking and CNAME cloaking—are increasing in response to cookie blocking. These techniques are more difficult to block with standard browser settings and may require updated content blocking extensions.

Several state privacy laws passed in 2024 and 2025 are now in effect or becoming effective, including Maryland’s Consumer Privacy Act and Minnesota’s Consumer Data Privacy Act. These laws have provisions specifically protective of children’s data. Awareness of your state’s current law is worth tracking.

Frequently Asked Questions

Does using a VPN protect my child from cross-site tracking?

A VPN hides your IP address from the sites you visit, which prevents IP-based location tracking. However, it does not block cookies, tracking pixels, or browser fingerprinting. For comprehensive tracking reduction, a VPN is useful but not sufficient alone—combine it with a privacy browser and tracker-blocking extensions.

Is private browsing or incognito mode enough to stop tracking?

No. Private browsing prevents the browser from saving your history locally and deletes cookies when the window is closed. It does not prevent websites from tracking you during the session through cookies, fingerprinting, or tracking pixels. It also doesn’t hide activity from your ISP or network administrator. It’s useful for keeping browsing history off the device, but not for preventing online tracking.

My child uses school-provided devices and browsers. Can I apply these settings?

School device settings are typically controlled by the school’s IT department. You can ask the school’s technology coordinator what privacy settings are applied to student browsers and whether additional protections like DNS filtering are in use. Some schools use enterprise-level filtering (like Cisco Umbrella or Securly) that provides strong tracker blocking as a side effect. Others don’t—it’s worth asking.

At what age should I start explaining tracking to my kids?

The basic concept—“websites remember what you do and tell other websites”—is understandable to children around age 8. The detailed mechanics can be introduced progressively. What matters is establishing early that online activity is not anonymous, so kids don’t develop a false sense of privacy that they’ll have to unlearn as teenagers.


About the author Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.


Sources

  1. Electronic Frontier Foundation. “Cover Your Tracks — Browser Fingerprinting.” coveryourtracks.eff.org.
  2. Federal Trade Commission. “FTC Imposes $170 Million Penalty on Google and YouTube for Violating Children’s Privacy Law.” ftc.gov, 2019.
  3. Federal Trade Commission. “FTC and DOJ Charge Fortnite Maker Epic Games.” ftc.gov, 2023.
  4. Federal Trade Commission. “Children’s Online Privacy Protection Act (COPPA).” ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa.
  5. Mozilla Foundation. “Enhanced Tracking Protection in Firefox.” support.mozilla.org.
  6. Electronic Frontier Foundation. “Why Ad Blocking Is Declining and What You Should Use Instead.” eff.org.
  7. Privacy Guides. “Browser Recommendations.” privacyguides.org.
Ricky Flores
Written by Ricky Flores

Founder of HiWave Makers and electrical engineer with 15+ years working on projects with Apple, Samsung, Texas Instruments, and other Fortune 500 companies. He writes about how kids learn to build, think, and create in a tech-driven world.