Cookie consent banner
The cookie banner that shows the right rules in every region.
Add one line to your site. ConsentCook holds the common trackers it knows until a visitor agrees, shows each of them a banner tuned to where they are — UK, the EEA, California — and keeps a signed record of every choice. Live in an afternoon, no legal degree required.
WordPress, Shopify, Wix, Squarespace & Tag Manager · Free plan, no card required
Before the click
What happens before a visitor chooses
Recording a choice is the easy half. The half that gets sites in trouble is what already ran by the time the banner appeared — so where a visitor has to agree first, ConsentCook holds the trackers it knows, keeps Google's tags denied, and then goes and checks your real site.
Common trackers are held
Where a visitor has to agree first, ConsentCook stops the trackers it knows — Google Analytics, Meta, Hotjar and the like — from loading until they do. You don't tag anything for this.
Google's tags start denied
Before your configuration has even loaded, ConsentCook sets Google Consent Mode to denied — so analytics and ads hold off on storing anything until the visitor says otherwise.
Anything else waits when you tag it
For a tracker we don't know, mark the script with the purpose it serves and ConsentCook keeps it inert until a visitor allows that purpose. The moment they do, it runs — no page reload.
Then we check your live site
Verifying a site crawls it the way a visitor arrives and tells you if anything non-essential fired before consent. You hear it from us, with the evidence, rather than from a regulator.
Pricing
Start free, scale when you grow
Clear monthly pricing in pounds — no setup fees, cancel whenever you like. Pick a plan and you're straight into setup; the Free plan needs no card.
Free
£0forever
For a single site finding its feet.
- 1 site
- 10,000 consent events / month
- 1 cookie scan / month
- Signed consent receipts
- Every region pack included
Standard
Popular£19per month
For growing teams running a handful of sites.
- 5 sites
- 250,000 consent events / month
- 12 cookie scans / month
- Staging environment to rehearse changes
- Everything in Free
Pro
£49per month
For agencies and larger estates.
- 25 sites
- 2 million consent events / month
- 120 cookie scans / month
- Everything in Standard
- Priority support
Consent, on the record
And every choice, provable later.
Each decision on that banner is sealed into a signed receipt — the exact banner and policy a visitor saw, captured the moment they chose. When an auditor asks you to prove consent, you hand over the record, not a promise.
Consent receipt
Signed- AnalyticsGranted
- MarketingDenied
- FunctionalGranted
- PersonalisationPending
sha256 4f9c2a1d8b…e2d1
signed 2026-06-26T09:41:22Z · cfg v8 · pol v3
Our own evidence
Check us before you trust us with yours
We ask you to keep proof for your visitors, so it would be odd not to keep it for you. Every one of these is public, and none of it needs a sales call.
Security controls
TLS everywhere, encryption at rest, tenant isolation, MFA and signed configurations — written down, with what's done and what isn't.
Read the controls →Data processing terms
Our DPA and Standard Contractual Clauses, public and readable before you sign up rather than after.
Read the DPA →Who else touches the data
Every subprocessor we use, what they do and where they do it. No surprises buried in an appendix.
See the list →Is it up right now?
A public status page for the API, the configuration CDN and the dashboard. Check it before you ask us.
Check service status →The difference
A banner shows a choice. We prove it happened.
Most cookie tools stop the moment a visitor clicks. ConsentCook keeps going — turning that click into a signed record you could still stand behind a year from now.
What you get
Everything consent, in one place
From the banner a visitor sees to the receipt your auditor asks for — handled, and kept in sync.
Banner builder
Design your consent banner in the dashboard and preview it live — no front-end work.
Learn more →Rules by region
One policy that adapts to UK GDPR, EU ePrivacy, CCPA and more.
Learn more →Cookie scanning
Find the cookies and trackers actually running on your site.
Learn more →Signed receipts
Every choice is stored as a tamper-evident receipt you can prove later.
Learn more →Deploy like code
Review a diff, publish a version, roll back if you need to.
Learn more →WordPress app
Connect your WordPress site and add the widget without editing a theme.
Learn more →Google Consent Mode
Analytics and ads respect consent the moment a visitor chooses.
Learn more →Consent reports
See how visitors respond — and open the record behind any number.
Learn more →Speaks their language
Show each visitor a banner in their own language, chosen automatically.
Learn more →The receipt
Anatomy of a receipt
Every choice becomes one signed record. Here is what gets written into it — and why each line is what turns a setting into proof.
Consent receipt
Signed- AnalyticsGranted
- MarketingDenied
- FunctionalGranted
- PersonalisationPending
sha256 4f9c2a1d8b…e2d1
signed 2026-06-26T09:41:22Z · cfg v8 · pol v3
rcpt_9f3a17c4Receipt IDOne record for one decision, addressable for the life of your retention window.subject: a1b2…7eAnonymous subject keyIdentifies the decision, never the person — no name, no email, no full IP.region: UK-ENGWhere they wereThe jurisdiction ConsentCook resolved, and the rules that set the choices on offer.cfg v8 · pol v3What they sawThe exact banner build and policy version on screen at the moment they chose.2026-06-26T09:41:22ZWhen it happenedAn ISO timestamp to the second, ready to line up against your own logs.sha256: 4f9c…e2The signatureChange one byte of the record and this no longer matches. That's what makes it proof.
Get set up
Live in three steps
Most people have a verified site collecting receipts the same afternoon.
Add your site
Name the site you want to manage consent for and it gets its own key straight away. Paid plans also get a staging environment to rehearse changes in.
Verify the domain
Prove you control the domain with a DNS record or a hosted file. Receipts only carry weight once the domain is verified.
Publish the banner
Add one line to your site, build the banner, set your rules and publish — changes go live as a versioned deployment.
<script src="https://consentcook.com/loader.js"
data-site="cc_pub_2f5705a8fbbbc7e4bb0bb3e2bd34e9de"></script>Install your way
It goes where your site already lives
It's the same one line everywhere — these are just the directions to the box you paste it into. Pick your platform and we'll walk you through it after signup.
WordPress
- Recommended: download the ConsentCook WordPress app below. In WordPress, go to Plugins → Add New Plugin → Upload Plugin, choose the ZIP, then install and activate it.
- Open Settings → ConsentCook and press Connect ConsentCook. Sign in, choose this site, and allow the connection. The app adds the widget; keep styling it here in ConsentCook.
- Or install without the app: add the free “WPCode” plugin, open Code Snippets → Header & Footer, and paste the line above at the very top of Header before any existing code.
Shopify
- In your Shopify admin, go to Online Store → Themes.
- On your live theme, open the “…” menu and choose Edit code.
- In the file list on the left, open the “layout” folder and click “theme.liquid”.
- Paste the line directly after the opening <head> tag, above everything else in the file, then click Save.
Squarespace
- In Squarespace, go to Settings → Advanced → Code Injection.
- Paste the line at the very top of the “Header” box, before any code already there.
- Click Save.
Wix
- In your Wix dashboard, go to Settings → Custom Code.
- Click “+ Add Custom Code” and paste the line above.
- Choose “Head”, set it to load on all pages, and click Apply.
- If you have other custom code in the Head, move this one to the top of the list.
Tag Manager
- In Google Tag Manager, create a new Tag and choose “Custom HTML”.
- Paste the line above, then set the trigger to “Consent Initialization - All Pages”.
- Click Save, then Submit and Publish.
Any website
- Open the HTML for your site.
- Paste the line above just after the opening <head> tag, before any analytics or marketing tags.
- Save and publish your changes.
When it counts
“Show me the consent for this visitor.”
An auditor, a regulator's query, a visitor exercising their rights. With ConsentCook you don't reconstruct anything from memory — you look up the decision and hand over the record that was written the moment it happened.
- Look up the visitor's decision
- Read exactly what they saw and chose
- Export the signed, timestamped receipt
Consent receipt
Signed- AnalyticsGranted
- MarketingDenied
- FunctionalGranted
- PersonalisationPending
sha256 4f9c2a1d8b…e2d1
signed 2026-06-26T09:41:22Z · cfg v8 · pol v3
Kept honest
Proof you can keep, without the baggage
A record that stands up is only half the job. The other half is not hoarding anything you'd later have to defend holding on to.
An anonymous key, not a name
Receipts record a decision, not a person. No name, no email, and no full IP address by default — only what proves the choice was made.
You set how long it's kept
Choose a retention window per property. When it ends, deletion actually runs — it isn't a setting that quietly gets ignored.
Proof without the profile
Enough on file to stand up the consent if it's ever questioned, and nothing extra you'd then have to justify holding on to.
Questions
The things people ask first
Do I need a developer to set this up?
Usually not on WordPress: upload our ready-made app and connect your account. On other sites, someone adds a single line once; from there you build, style and publish from the dashboard.
How long does it take to go live?
An afternoon is plenty. Most people add a property, build a banner and see their first receipts land the same day.
Will it slow my site down?
No. The banner loads from a small script and your configuration is served pre-built, so visitors see the right banner straight away without waiting on a round trip.
What do you store about my visitors?
As little as possible. Receipts use an anonymous key rather than a name or email, and we don't keep full IP addresses by default. You set how long records are kept, and deletion actually runs when that window ends.
If someone questions our consent, can we prove it?
Yes — that's the whole point. Every choice is a signed receipt that records what the visitor saw and chose. When an auditor or a visitor asks, you have the record rather than a promise.
Does it work outside the UK and EU?
Yes. One policy adapts to where each visitor is — UK GDPR, EU GDPR and ePrivacy, California's CCPA and more — so you're covered wherever they land, with no duplicate set-ups.
Can the banner show in other languages?
Yes. The banner detects each visitor's browser language and shows itself in it, falling back to your default. Built-in translations of the standard copy come ready for German, French, Spanish, Italian and Polish, and you can review and adjust the wording for each.
ConsentCook runs on ConsentCook — the cookie banner on this page is ours, served from the same signed pipeline you'd put in front of your visitors.
Get consent right, and prove it.
Stand up your first site in minutes. The Free plan is enough to go live.