Skip to main content

The cookie banner and your privacy policy

Switching on the consent banner, what it gates, and editing the privacy policy page behind it.

If your website uses analytics, visitors in a lot of places are entitled to be asked first. The cookie banner does that, and it comes with a privacy policy page so the banner has something real to link to.

Both live on your website's Plugins page, beside the analytics plugins the banner gates.

Switching the banner on

One switch. When you turn it on:

  • A small notice appears at the bottom of every page on your website. Visitors can accept all optional services, reject all non-essential services, or choose individual categories.
  • Your privacy policy page becomes live at /privacy-policy, and the banner links to it.
  • Connected Analytics, Marketing, and Functional services wait for the matching choice.

The banner is a plain notice with no third-party code in it, and it remembers each visitor's category choices in their own browser so they are only asked once. A choice expires after about a year, at which point the banner asks again.

Turning the banner off hides the banner and the privacy policy page together, and connected services run normally again. Your policy text is kept — switching off and on again never loses your edits.

The privacy policy

The first time you switch the banner on, a policy is written for you. It is a plain-language starting point, already filled in with your business name and address. It lists each connected service by name and the category that controls it.

It is a starting point, not legal advice. Read it, and edit anything that does not describe what your business actually does. The editor below the switch is where you do that, and Restore the suggested policy puts the generated version back if an edit goes wrong.

The policy is your own HTML, so you can structure it with headings, paragraphs, lists, emphasis, and links. Anything else — scripts, embedded frames, forms, styling — is stripped when you save. This is a page visitors read, not somewhere to run code.

What each category controls

  • Analytics helps the website owner understand visits and improve the site. Google Analytics and Google Tag Manager use this category.
  • Marketing covers advertising, social media, and other marketing services.
  • Functional covers optional experiences such as maps, video players, and live feeds.

Scripts and external frames in those categories are placed on the page inert. They receive no visitor data until the category is allowed. Essential first-party website features do not need permission and remain available.

An optional player, map, or feed can also show a placeholder that names its provider. The visitor can load just that content without changing the choices saved for the rest of the website. Google Tag Manager's no-JavaScript fallback is skipped while the banner is on, because a visitor without JavaScript has no way to give permission.

Visitors who accepted the original analytics-only banner keep that choice after this update: Analytics remains allowed, while Marketing and Functional remain off until chosen.

When it takes effect

Immediately, on your dev site and your live site. The banner and the policy page are added as pages are served, so there is nothing to republish after changing either.

Next