Cookie consent banner

The cookie banner that shows the right rules in every region.

Add one line to your site. ConsentCook holds the common trackers it knows until a visitor agrees, shows each of them a banner tuned to where they are — UK, the EEA, California — and keeps a signed record of every choice. Live in an afternoon, no legal degree required.

WordPress, Shopify, Wix, Squarespace & Tag Manager · Free plan, no card required

Before the click

What happens before a visitor chooses

Recording a choice is the easy half. The half that gets sites in trouble is what already ran by the time the banner appeared — so where a visitor has to agree first, ConsentCook holds the trackers it knows, keeps Google's tags denied, and then goes and checks your real site.

Common trackers are held

Where a visitor has to agree first, ConsentCook stops the trackers it knows — Google Analytics, Meta, Hotjar and the like — from loading until they do. You don't tag anything for this.

Google's tags start denied

Before your configuration has even loaded, ConsentCook sets Google Consent Mode to denied — so analytics and ads hold off on storing anything until the visitor says otherwise.

Anything else waits when you tag it

For a tracker we don't know, mark the script with the purpose it serves and ConsentCook keeps it inert until a visitor allows that purpose. The moment they do, it runs — no page reload.

Then we check your live site

Verifying a site crawls it the way a visitor arrives and tells you if anything non-essential fired before consent. You hear it from us, with the evidence, rather than from a regulator.

Pricing

Start free, scale when you grow

Clear monthly pricing in pounds — no setup fees, cancel whenever you like. Pick a plan and you're straight into setup; the Free plan needs no card.

Free

£0forever

For a single site finding its feet.

  • 1 site
  • 10,000 consent events / month
  • 1 cookie scan / month
  • Signed consent receipts
  • Every region pack included
Get started

Pro

£49per month

For agencies and larger estates.

  • 25 sites
  • 2 million consent events / month
  • 120 cookie scans / month
  • Everything in Standard
  • Priority support
Get started

Compare plans in full →

Consent, on the record

And every choice, provable later.

Each decision on that banner is sealed into a signed receipt — the exact banner and policy a visitor saw, captured the moment they chose. When an auditor asks you to prove consent, you hand over the record, not a promise.

See what's in a receipt →

CoversUK GDPREU GDPRePrivacy / PECRCCPAGoogle Consent Mode v2

The difference

A banner shows a choice. We prove it happened.

Most cookie tools stop the moment a visitor clicks. ConsentCook keeps going — turning that click into a signed record you could still stand behind a year from now.

When a visitor chooses…A banner aloneConsentCook
Shows the right banner for each visitor's regionTable stakes — every banner does this much.
Captures the choice the visitor madeUsually only in the visitor's own browser, where it can be cleared.
Signs the record so it can't be edited after the factEach receipt is signed and tamper-evident the moment it's written.
Stamps the exact banner and policy version they sawConfiguration and policy versions travel on every receipt.
Hands you the proof when an auditor or visitor asksLook up the decision and export the record — not a promise, the record.

The receipt

Anatomy of a receipt

Every choice becomes one signed record. Here is what gets written into it — and why each line is what turns a setting into proof.

  1. rcpt_9f3a17c4Receipt IDOne record for one decision, addressable for the life of your retention window.
  2. subject: a1b2…7eAnonymous subject keyIdentifies the decision, never the person — no name, no email, no full IP.
  3. region: UK-ENGWhere they wereThe jurisdiction ConsentCook resolved, and the rules that set the choices on offer.
  4. cfg v8 · pol v3What they sawThe exact banner build and policy version on screen at the moment they chose.
  5. 2026-06-26T09:41:22ZWhen it happenedAn ISO timestamp to the second, ready to line up against your own logs.
  6. sha256: 4f9c…e2The signatureChange one byte of the record and this no longer matches. That's what makes it proof.

Get set up

Live in three steps

Most people have a verified site collecting receipts the same afternoon.

STEP 01

Add your site

Name the site you want to manage consent for and it gets its own key straight away. Paid plans also get a staging environment to rehearse changes in.

STEP 02

Verify the domain

Prove you control the domain with a DNS record or a hosted file. Receipts only carry weight once the domain is verified.

STEP 03

Publish the banner

Add one line to your site, build the banner, set your rules and publish — changes go live as a versioned deployment.

index.htmlOne line — that's the install
<script src="https://consentcook.com/loader.js"
        data-site="cc_pub_2f5705a8fbbbc7e4bb0bb3e2bd34e9de"></script>

Install your way

It goes where your site already lives

It's the same one line everywhere — these are just the directions to the box you paste it into. Pick your platform and we'll walk you through it after signup.

WordPress

  1. Recommended: download the ConsentCook WordPress app below. In WordPress, go to Plugins → Add New Plugin → Upload Plugin, choose the ZIP, then install and activate it.
  2. Open Settings → ConsentCook and press Connect ConsentCook. Sign in, choose this site, and allow the connection. The app adds the widget; keep styling it here in ConsentCook.
  3. Or install without the app: add the free “WPCode” plugin, open Code Snippets → Header & Footer, and paste the line above at the very top of Header before any existing code.

Shopify

  1. In your Shopify admin, go to Online Store → Themes.
  2. On your live theme, open the “…” menu and choose Edit code.
  3. In the file list on the left, open the “layout” folder and click “theme.liquid”.
  4. Paste the line directly after the opening <head> tag, above everything else in the file, then click Save.

Squarespace

  1. In Squarespace, go to Settings → Advanced → Code Injection.
  2. Paste the line at the very top of the “Header” box, before any code already there.
  3. Click Save.

Wix

  1. In your Wix dashboard, go to Settings → Custom Code.
  2. Click “+ Add Custom Code” and paste the line above.
  3. Choose “Head”, set it to load on all pages, and click Apply.
  4. If you have other custom code in the Head, move this one to the top of the list.

Tag Manager

  1. In Google Tag Manager, create a new Tag and choose “Custom HTML”.
  2. Paste the line above, then set the trigger to “Consent Initialization - All Pages”.
  3. Click Save, then Submit and Publish.

Any website

  1. Open the HTML for your site.
  2. Paste the line above just after the opening <head> tag, before any analytics or marketing tags.
  3. Save and publish your changes.

When it counts

“Show me the consent for this visitor.”

An auditor, a regulator's query, a visitor exercising their rights. With ConsentCook you don't reconstruct anything from memory — you look up the decision and hand over the record that was written the moment it happened.

  • Look up the visitor's decision
  • Read exactly what they saw and chose
  • Export the signed, timestamped receipt

Kept honest

Proof you can keep, without the baggage

A record that stands up is only half the job. The other half is not hoarding anything you'd later have to defend holding on to.

An anonymous key, not a name

Receipts record a decision, not a person. No name, no email, and no full IP address by default — only what proves the choice was made.

You set how long it's kept

Choose a retention window per property. When it ends, deletion actually runs — it isn't a setting that quietly gets ignored.

Proof without the profile

Enough on file to stand up the consent if it's ever questioned, and nothing extra you'd then have to justify holding on to.

Questions

The things people ask first

Do I need a developer to set this up?

Usually not on WordPress: upload our ready-made app and connect your account. On other sites, someone adds a single line once; from there you build, style and publish from the dashboard.

How long does it take to go live?

An afternoon is plenty. Most people add a property, build a banner and see their first receipts land the same day.

Will it slow my site down?

No. The banner loads from a small script and your configuration is served pre-built, so visitors see the right banner straight away without waiting on a round trip.

What do you store about my visitors?

As little as possible. Receipts use an anonymous key rather than a name or email, and we don't keep full IP addresses by default. You set how long records are kept, and deletion actually runs when that window ends.

If someone questions our consent, can we prove it?

Yes — that's the whole point. Every choice is a signed receipt that records what the visitor saw and chose. When an auditor or a visitor asks, you have the record rather than a promise.

Does it work outside the UK and EU?

Yes. One policy adapts to where each visitor is — UK GDPR, EU GDPR and ePrivacy, California's CCPA and more — so you're covered wherever they land, with no duplicate set-ups.

Can the banner show in other languages?

Yes. The banner detects each visitor's browser language and shows itself in it, falling back to your default. Built-in translations of the standard copy come ready for German, French, Spanish, Italian and Polish, and you can review and adjust the wording for each.

ConsentCook runs on ConsentCook — the cookie banner on this page is ours, served from the same signed pipeline you'd put in front of your visitors.

Get consent right, and prove it.

Stand up your first site in minutes. The Free plan is enough to go live.

ConsentCook — Cookie consent you can prove