General & Consent
Consent Management Platform (CMP) basics, GDPR requirements, multi-domain control, and language switching.
What is a CMP? And why do I need one?
A Consent Management Platform (CMP) automates cookie and user consent collection on your website. It ensures compliance with privacy regulations such as GDPR, ePrivacy, and CCPA by informing visitors about tracking technologies, collecting verifiable consent, blocking scripts until opt-in, and maintaining an auditable trail.
Learn more in our guide on what cookie consent is.
Which cookies require consent under GDPR?
Non-essential cookies — such as those used for analytics, conversion tracking, marketing pixels, and personalization — require prior, explicit consent. Strictly necessary cookies (such as security tokens, shopping cart sessions, or load balancer states) do not require consent.
Do I need to classify and configure cookies individually?
No. QookieQloud™ automatically categorizes detected scripts and cookies into standard categories (Necessary, Analytics, Marketing, Functional), eliminating the need for complex manual maintenance.
Where can I manage cookies and consents for multiple domains?
Log in to your account at app.qookieqloud.com. From the central dashboard, you can view analytics, configure consent modes, customize banner designs, and export audit logs for all your registered domains in one place.
Are there special setups for digital agencies?
Yes! Web agencies and developers can manage multiple client websites and domains centrally through a QookieQloud Partner account, while packaging and pricing the solution directly to their clients. Check our Partner documentation for more details.
How do I register my domain with QookieQloud?
Adding a domain takes less than a minute. In your dashboard, click Domains → Add Domain, enter your root URL, choose your consent mode, and copy your embed snippet. You can also follow our domain setup guide.
Is the client agent easy to install on any website?
Yes! We offer official WordPress plugins, Statamic plugins, and a Shopify app. For other platforms, use our universal script installation by pasting this script inside your <head> tag:
<script src="https://cf-cdn.qookieqloud.com/consentLoader.js"></script>
What languages and locales are supported?
The Free plan includes one primary language of your choice. Standard and Premium plans include automatic language switching across 28+ European and global languages based on the visitor's browser settings.
What is a GDPR Data Subject Request (DSR)?
A Data Subject Request (DSR) is a formal request submitted by an individual to exercise their privacy rights under Chapter III of the GDPR:
- Article 15 (Right of Access): Requesting a copy and confirmation of all stored personal data and consent telemetry.
- Article 16 (Right to Rectification): Requesting the correction of inaccurate or incomplete personal records.
- Article 17 (Right to Erasure): Requesting the permanent and irreversible deletion of personal data ("Right to be Forgotten").
QookieQloud™ includes a built-in DSR mechanism directly inside the consent banner so visitors can submit requests seamlessly and website owners can resolve them in compliance with privacy regulations.
What is the difference between the Privacy Score under Cookies and the V3 Live Audit Score?
The two scores evaluate two complementary dimensions of privacy compliance:
- Privacy Score (under Cookies / Dashboard): Evaluates the quality and completeness of your static cookie inventory and declaration. It checks if there are unclassified cookies, unreviewed AI suggestions, or cookies lacking confirmed legal purposes.
- V3 Live Diagnostic Audit Score (Live Scanner & Public Report): Evaluates the runtime execution and browser behavior in real time. It tests whether trackers fire before consent, verifies Google Consent Mode v2 default signal timing, checks for Late Consent, and confirms that marketing tags halt upon consent rejection.
How do visitors submit a Privacy Rights / DSR request?
Visitors can submit privacy requests directly through the active consent widget at any time:
- The visitor opens the banner preferences and clicks the Privacy Rights tab (or clicks a link/button with
class="qookieqloud-dsr-panel"). - They select their request type: Erasure (Art. 17), Access (Art. 15), or Rectification (Art. 16).
- They enter their email address along with optional notes and submit the form.
- An automated receipt is immediately emailed to the visitor, while domain administrators receive an instant notification in their dashboard and via email.
Tip: You can add a link in your website footer or privacy policy with <a href="#" class="qookieqloud-dsr-panel">Privacy Rights (GDPR)</a> to open the form directly.
Note: The DSR tab is included in Premium plans and can be toggled on or off under Customize > Layout in the admin dashboard.
What is QookieQloud's Zero-Retention security principle for DSRs?
Zero-Retention ensures that QookieQloud never retains sensitive personal data longer than strictly necessary to process the request:
- Requester email addresses and notes are temporarily encrypted purely to route notifications and match the consent log.
- The instant an administrator marks the request as Resolved in the dashboard, the requester's email address and submitted notes are permanently and irreversibly purged from QookieQloud servers.
- For erasure requests, the consent log is permanently anonymized as well.
This architecture eliminates lingering data liability and strictly aligns with GDPR's data minimization and storage limitation principles (Article 5.1.c & 5.1.e).
Can I disable the Privacy Rights (DSR) tab in the cookie banner?
Yes. For Premium customers, the DSR tab (Privacy Rights) is enabled by default, but it can be easily toggled off if your organization prefers a separate compliance channel:
- Log in to your admin dashboard and navigate to Domains.
- Select your domain and click Customize in the sidebar.
- In the Layout tab, scroll to the Data Subject Requests (DSR) card.
- Toggle the switch off and click Save.
The setting is encrypted and immediately updated on the live visitor banner without affecting your cookie consent tracking.
How do I handle Rectification requests (Article 16)?
While cookie consents are binary records, a Rectification request under GDPR Article 16 typically pertains to personal records held across your connected business systems (such as CRM databases, customer accounts, or newsletter lists):
- Navigate to
Domains > Consentsand click Resolve DSR on the pending request. - Review the requester's notes and correct the relevant records within your internal database.
- Add an optional explanation in the Response message to visitor text area.
- Click Complete. The visitor receives your response note in a formal completion email, and their contact information is automatically purged from QookieQloud.
How does Article 15 Data Access / Export work for visitors?
When a visitor requests a data export (Right of Access under GDPR Article 15), QookieQloud automates the reporting process entirely:
- QookieQloud retrieves the associated consent record and aggregates all relevant parameters: timestamp, unique consent ID, anonymized IP/country, user agent, and approved cookie categories.
- The moment an administrator resolves the request in the dashboard, a structured consent summary table is automatically compiled and embedded directly into the completion email sent to the visitor.
- You can also append supplementary notes or links regarding internal CRM customer records in the response field before completing the request.
What happens when an Erasure request (Article 17) is resolved?
When an administrator resolves an Erasure request (GDPR Article 17 / "Right to be Forgotten"):
- Purge internal systems: You verify that the user's customer records, profiles, or newsletter subscriptions have been deleted across your internal systems.
- Resolve in QookieQloud: Open the pending request in the admin dashboard and click Complete.
- Anonymize consent records: The visitor's consent telemetry in QookieQloud is immediately and irreversibly anonymized.
- Enforce Zero-Retention: The requester's email address and submitted notes are permanently purged from QookieQloud servers.
- Visitor notification: A final confirmation email is automatically delivered to the visitor certifying that their data has been erased.
Plans, Pricing & Quotas
Subpage count rules, billing, plan tiers, cookie scan frequency, and Google Consent Mode v2 modeling.
What counts as a subpage?
A subpage is any unique URL indexed and crawled by our cookie scanner on your verified domain (e.g. /about, /shop/product-1). Assets like images, CSS, and API endpoints are not counted as subpages.
Can I upgrade or scale my subpages later?
Yes. You can switch between Free, Standard, and Premium at any time. When using Premium, you can seamlessly scale between 100 and 5,000 subpages straight from your account dashboard with prorated billing.
Does QookieQloud slow down my website?
No. Our consent banner script is delivered via global edge CDN, weighing less than 15 KB gzipped. It loads asynchronously without blocking your page paint, keeping Core Web Vitals green.
How does Google Consent Mode v2 work?
QookieQloud has native built-in Consent Mode v2 support. When visitors give or deny consent, Google Analytics, Ads, and Tag Manager tags update their consent parameters automatically with zero custom coding required.
Are there special setups for digital agencies?
Yes! Web agencies and developers can manage multiple client websites and domains centrally through a QookieQloud Partner account, while packaging and pricing the solution directly to their clients. Check our Partner documentation for more details.
Can I cancel my subscription anytime?
Absolutely. There are no lock-in periods on monthly plans. You can cancel with one click from your billing portal, and your plan will remain active until the end of the paid billing period.
Shopify Integration
Shopify App Embeds, Customer Privacy API, Google Consent Mode v2, theme updates, and reopening settings.
Do I need to edit my theme's Liquid code?
No. QookieQloud is built as a native Shopify Theme App Extension for Online Store 2.0. You simply toggle the App Embed on in your Shopify Theme Editor. No code editing is required, and your theme files remain 100% clean and updateable.
How does QookieQloud integrate with Shopify's Customer Privacy API?
QookieQloud automatically connects with Shopify's native window.Shopify.customerPrivacy API. When a visitor accepts or rejects tracking, consent signals are instantly synchronized across Shopify analytics, marketing pixels, and installed store apps.
Does the Shopify app support Google Consent Mode v2?
Yes, out of the box. QookieQloud automatically pushes ad_storage, ad_user_data, ad_personalization, and analytics_storage updates to Google Consent Mode v2, preserving your conversion modeling in Google Analytics 4 and Google Ads while remaining GDPR compliant.
Will QookieQloud slow down my store or affect checkout performance?
Not at all. The embed script is ultra-lightweight (<12 KB), loads asynchronously from global edge networks, and has zero negative impact on your Core Web Vitals or checkout performance.
What happens if I change or update my Shopify theme?
Because QookieQloud uses Shopify App Embeds, none of your cookie classifications, regional rules, or audit history are stored in theme files. When you publish a new theme, simply toggle the QookieQloud app embed on in the Theme Editor.
How can customers reopen cookie preferences in my storefront?
By default, the floating Qookie Eyes icon automatically appears in the corner of your storefront once consent is saved, allowing visitors to click and reopen their preferences anytime. If you prefer a menu or text link (such as in your store footer), you can also add the custom attribute data-qookie-open-settings to any link or button, and customize icon visibility in your dashboard.
Statamic Addon
Official Statamic addon installation, multi-site domains, Antlers script blocking, SSG, and local dev environments.
How does local development (Herd, Valet, Docker) work?
Connect your local installation to a domain you manage in QookieQloud. HTTP is supported on localhost and 127.0.0.1; other origins require HTTPS. If local and production installations share a domain, their reported cookies and consent statistics are combined. Use a separate demo domain when you want to keep test data separate.
Do I have to insert code manually into my layout templates?
By default, the addon automatically injects the required script into your <head> via Laravel middleware, requiring zero template edits. If your theme requires custom script placement or bundling, you can turn off auto-injection in the Statamic Control Panel and use the {{ qookieqloud }} Antlers tag (or @qookieqloud in Blade) anywhere in your layout.
Can I hide the consent banner for logged-in editors and Live Preview?
Yes. Under the addon settings in the Statamic Control Panel, you can toggle "Bypass for authenticated users". This prevents the consent banner from popping up while you or your content editors are logged in, editing entries, or reviewing content in Statamic Live Preview.
How do I block tracking scripts in Antlers and Blade before consent?
QookieQloud automatically blocks scripts matching your cookie scan rules client-side. For explicit template control, change your script tag to type="text/plain" with data-qq-category="marketing" (or "analytics"). QookieQloud will execute the script automatically the moment the visitor grants consent.
Does QookieQloud support Statamic Static Site Generation (SSG)?
Yes. Because consent evaluation and script unblocking execute asynchronously client-side via edge CDN, static HTML files generated via php please ssg:generate (hosted on Netlify, Cloudflare Pages, Vercel, or AWS S3) work seamlessly without server runtime dependencies.
How does the addon handle Statamic Multi-Site and multilingual domains?
In multi-site installations, the addon automatically resolves the active Statamic site locale and renders the banner and preference center in the visitor's language. If your sites operate on separate country top-level domains (e.g. .se vs .com), you can assign individual compliance presets per site.
WordPress & WooCommerce
Official WordPress plugin setup, automatic API token verification, and compatibility with caching plugins.
How do I install the QookieQloud WordPress plugin?
Install and activate WP Consent API and QookieQloud. Use the connection flow below if your plugin and account have v2 access. In the v2 plugin, open QookieQloud in WordPress and click Connect. Sign in in the popup, select a domain you manage or add one, and approve. The public and private API keys are saved automatically; no keys to copy. Existing v1 installations keep their current banner until you explicitly connect to v2. After connecting, changing banner settings or disconnecting, clear your page and CDN caches.
Is QookieQloud compatible with WooCommerce and caching plugins?
Yes. QookieQloud works flawlessly with WooCommerce, WP Rocket, LiteSpeed Cache, and W3 Total Cache without requiring cache-busting workarounds.
Custom JS & Headless
Universal script embed, Google Tag Manager integration, headless single-page applications, and programmatic JS APIs.
Where do I place the QookieQloud script tag?
Paste the script snippet <script src="https://cf-cdn.qookieqloud.com/consentLoader.js"></script> inside the <head> tag of your HTML template, website builder (such as Webflow, Framer, Squarespace), or tag manager. Once loaded on your domain, QookieQloud immediately begins managing banner display and tag interception.
How can visitors reopen the consent settings modal?
By default, the floating Qookie Eyes icon automatically appears in the corner of your website, allowing visitors to reopen and adjust their preferences anytime. You can also trigger the modal from any text link or button using the data-qookie-open-settings attribute, or programmatically invoke window.QookieConsent.open().
Does QookieQloud support Custom JS, Google Tag Manager, React, and headless sites?
Yes. QookieQloud works with Custom JS, Google Tag Manager, React, and headless sites. For new installations, use API v2 with a public Site Key and the v2 script. API v1 can remain enabled while you migrate and verify v2. After v2 is working, disable API v1 in Customize → Connection because that is the safer production configuration. The Site Key alone is not enough: the v2 script must be installed on the website.
How do I generate a public Site Key for API v2?
Sign in at app.qookieqloud.com and open the domain that should use the banner. Go to Customize → Connection and choose Generate new Site Key. Confirm the dialog, then copy the key into the v2 script shown in step 2 of the Custom JS page. The Site Key is public and scoped to the domain. It only becomes active once the script is installed on the website.
How do I resolve late consent signals and Google Tag Gateway (GTG) warnings?
If Google Tag Assistant or your debug console flags a "late consent" warning, follow these troubleshooting steps:
- Verify Google Tag Gateway (GTG) adoption: Check if your website routes Google tags through a CDN edge integration or server-side Google Tag Gateway (GTG).
- If GTG is adopted: Ensure that global consent default commands are dispatched prior to edge routing so tags receive default states immediately.
- If using standard Google Tag Manager: Verify that your QookieQloud GTM tag is configured to fire on the Consent Initialization - All Pages trigger so consent defaults are established before any other tags execute.
How do I integrate API v2 into a web app?
API v2 works with React, Vue, Next.js, Nuxt, Astro, and other client-rendered web apps. Add the v2 script to the app’s global HTML head, such as index.html or a layout file loaded on every page. The Site Key may be included in client-side code: it is public and scoped to the registered domain. Never put a private server key in the browser. Example: <script src="https://cf-cdn.qookieqloud.com/v2/consentLoader.js" data-site-key="qq_pk_..." defer></script>. Verify that the script loads on the correct domain, then disable API v1 under Customize → Connection.
Accessibility & WCAG
WCAG 2.1 Level AA certified agent, keyboard navigation, screen reader accessibility, and Live Contrast Validator.
Is the QookieQloud™ agent WCAG 2.1 AA compliant?
Yes. The QookieQloud™ agent has been rigorously audited and certified compliant with WCAG 2.1 Level AA standards. It supports full keyboard navigation, screen readers, focus traps, and high-contrast color modes. Read more in our WCAG compliance guide.
How does the Live WCAG Validator work when customizing colors?
Our built-in Live WCAG Validator tests your background and text color contrast ratios in real time. If a color combination falls below the required 4.5:1 ratio, the validator flags it instantly so you can maintain accessibility standards.
Still have questions?
Can’t find the answer you’re looking for? Our engineers and compliance team are ready to assist you.