Skip to content
Cookie banner

Ask once, and respect the answer

The script that measures your site also shows the banner and tells Google what the visitor decided. This page says what it does, what it stores and what changes by country.

How the banner asks

  • By default a window in the middle of the page. In init you can choose layout: bar, modal or corner.
  • Reject all sits on the first screen next to Accept all (showRejectOnFirstView, on by default).
  • The settings view has four categories: essential (always on), analytics, marketing and functional. All but essential start switched off.
  • Languages: English, Slovak, Czech, German, Polish, Hungarian, Dutch, French, Italian and Spanish. A language the banner does not have falls back to English.
  • The language is taken from language in init, then from the language saved for the project in the app, then from the visitor's browser.
  • The links to your cookie policy and privacy policy default to /cookie-policy and /privacy. If your pages have other addresses, set cookiePolicyUrl and privacyPolicyUrl.
  • On the Free plan the banner carries the Conseto mark. On paid plans it is shown too, unless you turn it off in the project's white-label settings.

What you can set

In the app, on the Cookie banner page: the theme (light, dark or automatic), the colour of the accept button, the language (automatic, Slovak, Czech, English or German) and the two policy links. Everything else you set in init. Where both say something, init wins.

HTML
<script src="https://www.conseto.io/dist/conseto.min.js"></script>
<script>
  Conseto.init({
    clientId: 'conseto_xxx_xxx',
    language: 'sk',
    theme: 'auto',
    accentColor: '#3B82F6',
    cookiePolicyUrl: '/cookies',
    privacyPolicyUrl: '/privacy'
  });
</script>

What it remembers

  • The decision is kept in the browser's local storage under cs_consent, together with the version of the banner policy. A decision made under an older version does not count, and the banner asks again.
  • The visitor can change the decision at any time: with the small button on the page (bottom right by default, reopenButtonPosition moves it), with an element of your own that has data-conseto="cookie-settings", or with Conseto.openCookieSettings().
  • Before the visitor decides, the script keeps the visitor's and the visit's identifiers in memory only. They are stored on the device after analytics consent.
  • The banner shown, the interaction and the decision itself are recorded even when the visitor refuses: a refusal that is not recorded cannot be proven. The Cookie banner page in the app shows how visitors decide, by category.
HTML
<a href="#" data-conseto="cookie-settings">Cookie settings</a>
JavaScript
Conseto.getConsent();
// { necessary: true, analytics: true, marketing: false, functional: false }

Conseto.updateConsent({ analytics: true, marketing: false });

Conseto.clearConsent(); // the banner asks again on the next page load
JavaScript
Conseto.showBanner();         // ask now, if no banner is open
Conseto.openCookieSettings(); // open the settings view
Conseto.hideBanner();         // close the banner
JavaScript
Conseto.init({
  clientId: 'conseto_xxx_xxx',
  onConsent: (consent) => {
    console.log(consent.analytics, consent.marketing);
  }
});

Google Consent Mode v2

The script sets the consent defaults before any Google tag runs, and updates them when the visitor decides.

  • Analytics consent sets analytics_storage. Marketing consent sets ad_storage, ad_user_data and ad_personalization. Functional consent sets functionality_storage and personalization_storage.
  • Where opt-in applies, everything starts as denied except security_storage, and the script waits 500 milliseconds for the banner's update (wait_for_update). ads_data_redaction is on.
  • Where opt-out applies (California, Virginia, Colorado), everything starts as granted until the visitor opts out.
  • GA4 and Google Tag Manager are loaded at once and follow Consent Mode. The Meta Pixel is not loaded until the visitor gives marketing consent.
  • url_passthrough is off. Switch it on with urlPassthrough: true only if you run Google Ads: it decorates internal links with a _gl parameter.
Set by the script
gtag('consent', 'default', {
  analytics_storage: 'denied',
  ad_storage: 'denied',
  ad_user_data: 'denied',
  ad_personalization: 'denied',
  functionality_storage: 'denied',
  personalization_storage: 'denied',
  security_storage: 'granted',
  wait_for_update: 500
});

What changes by country

The gateway decides from the visitor's country which regime applies, and the script follows it. If the country cannot be found, or the settings do not arrive within 5 seconds, the strict opt-in regime applies.

EU, EEA, United Kingdom, unknown
Opt-in. Nothing non-essential happens before the visitor accepts: events wait in memory, are sent after Accept and are dropped after Reject.
California
Opt-out, with a short view and a Do Not Sell My Info button (English, Spanish, French and German). Events are sent until the visitor opts out.
Virginia, Colorado
Opt-out for measurement: events are sent until the visitor refuses. The banner looks like the one in the EU.
Connecticut, Utah, Brazil, Canada
The same behaviour as in the EU.
Everywhere else
No consent law is detected for the visitor, so no banner is shown and measurement runs. This includes the rest of the United States and countries such as Switzerland, Australia and Japan.

What the script stores

Google and Meta set their own cookies on top of this. These are Conseto's own keys.

cs_consent
The decision and the banner policy version. Local storage.
cs_v
The visitor's identifier. Local storage, only after analytics consent.
cs_s
The current visit. Storage of the browser tab, only after analytics consent.
cs_utm
The campaign the visitor arrived from. Storage of the browser tab, only after analytics consent.
cs_admin
The flag of your own visits. Local storage and a cookie, only if you opened the link.
_gcl_aw, _fbp, _fbc
Cookies _gcl_aw, _fbp and _fbc: the click IDs of Google and Meta ads, for 90 days, only with marketing consent. Withdrawing the consent deletes them.

Read next

Checked against the code on 1 October 2026.

Missing something?

This is everything we document today, and each page says only what the script and the gateway do now. If you need a guide that is not here, tell us what you want to achieve.

Write to us