# Cookie Consent

> Ask visitors before anything tracks them, add a cookie banner with AI, choose what waits for which consent, and keep a log of every choice as proof.

Source: https://knowledge.estage.com/project-settings/cookie-consent/
Part of the ESTAGE knowledge base (https://knowledge.estage.com). Full corpus: https://knowledge.estage.com/llms-full.txt

---
The **Cookie Consent** tab is where your site asks visitors before tracking them — and keeps a
record of what each one chose. If your visitors are in the EU or UK, this is required: tracking
cookies need the visitor's consent first.

Changes reach the published site the next time you publish.

## Ask before tracking

Turn on **Ask before tracking**. From then on:

- **Google tags** (Tag Manager, GA4) run in **Consent Mode v2** with everything denied until the
  visitor accepts — no cookies, only anonymous pings.
- **Meta, TikTok and LinkedIn** don't load at all before marketing consent.
- **Affiliate referrals** from order-form links are recorded only after marketing consent.
- **Funnel visits** are recorded only after analytics consent.
- **Code Injection** waits for the category you give it (see [below](#code-injection-when-to-load)).
- **Every choice** is kept in the [consent log](#consent-log).

:::caution
While the switch is off, your [Pixels & Tracking](/project-settings/marketing-tags/) tags and
funnel analytics run for every visitor without asking — and a banner that stores its own choice
isn't seen by any of them.
:::

**Hold Google tags until consent** is a stricter option. Off, GTM and GA4 load at once in
Consent Mode. On, they don't load at all until the visitor allows Analytics (GA4) or Analytics or
Marketing (GTM) — stricter, but Google's own reports recover less.

## The cookie banner

The switch decides what waits; the site still needs a banner that asks. If your site has none,
press **Add with AI** — the builder opens with the request ready to send, and the AI builds a
banner in your site's style that always matches the switch:

- **Accept all**, **Reject non-essential** and **Manage preferences**, side by side.
- Preferences with **Strictly necessary** always on and one switch per category, all off by default.
- A **Cookie settings** link in the footer and a small cookie button in the corner, so visitors
  can change their mind or **withdraw consent** later.
- The visitor's **consent ID** with a copy button — the ID they quote to you to ask what was
  recorded about their choice.

Once your site has a banner, the card shows **Added** and the file it lives in. To change it, ask
the AI in the builder.

Ask the AI for the banner rather than adding your own: a banner that stores the choice in its own
cookie gates nothing — the tags and the log never see it — so the builder won't write one, and
cookie-consent tools from third parties aren't needed.

## What waits for which consent

| Category | What waits for it |
| --- | --- |
| **Strictly necessary** | Nothing — always on |
| **Functional** | Embedded YouTube, Vimeo, Google Maps, Calendly, Typeform, Spotify, SoundCloud, Loom and Wistia; code you file under Functional |
| **Analytics** | GA4 and GTM (fully, with *Hold Google tags*), funnel analytics, code you file under Analytics |
| **Marketing** | Meta, TikTok, LinkedIn, affiliate referrals, Facebook / Instagram / X / TikTok post embeds, code you file under Marketing |

The **Functional** switch appears on the banner only when your site needs it — when it embeds
videos, maps or booking widgets, or you file code under Functional. Until the visitor allows it,
each embed shows an **Allow and load** box that allows just that category.

:::note
A banner built before October 2026 doesn't have a Functional switch. Ask the AI to update it —
until then, only *Accept all* loads Functional content.
:::

### Code Injection: when to load

In [Code Injection](/project-settings/code-injection/), **When to load this code** files your own
snippets under a category:

- **Always** — code that neither tracks nor remembers visitors: site verification, fonts.
- **After Functional consent** — chat widgets, embedded players, maps.
- **After Analytics consent** — Hotjar, Microsoft Clarity, other analytics or heatmaps.
- **After Marketing consent** — ad pixels and retargeting tags not set up in Pixels & Tracking.

Filing code under a category changes what your site asks for, so its visitors are asked again.

## Cookie policy

Pick the **Page** your banner links to — your cookie policy, or your privacy policy if cookies are
explained there — or **Other link…** for a policy hosted elsewhere. Give it a **Version** (for
example `2026-09-30`) and change the version whenever the policy's text changes: every recorded
choice notes which version the visitor saw.

## Consent log

The **Consent log** keeps every choice made in the banner for five years, as proof that consent
was given. It stores no IP address or browser details — each visitor is a random consent ID.

- **Accepted all**, **Rejected all**, **Chose some** and **Withdrew** — the last 30 days and all time.
- **Find a visitor by consent ID** shows that visitor's history and whether every record is
  exactly as it was written.
- Each row shows the date, consent ID, decision, what was allowed, the page, and — on hover — the
  policy version and whether the choice came from the banner or Cookie settings.
- **Export CSV** downloads the log, or one visitor's history when you've looked them up.

When a visitor asks what you recorded about them, ask for the consent ID shown in their Cookie
settings and look it up here.

## Good to know

- Recording starts once the site is published with the switch on.
- Closing the banner without choosing records nothing, and everything stays off.
- The tab isn't shown for mobile-app projects.
- It's under the same permission as Pixels & Tracking.
