Add a single line to your site and get a cookie banner that covers GDPR and CCPA. $5/mo. That's it.
<head>
<script src="cookieflag.com/api/banner/abc123" defer />
</head>Why it matters
If your website uses cookies — analytics, ads, embedded videos — regulations like GDPR and CCPA require you to get visitor consent before those cookies load. Most small sites aren't compliant.
If anyone from Europe visits your site, GDPR applies — regardless of where your business is based.
California's privacy law gives visitors the right to opt out of data collection. That includes cookies.
Regulators issue fines, and platforms like Google Ads require proof of consent to serve ads in the EU.
How it works
Pick your colors and text. Make it match your site.
Grab the script tag we generate for you.
Add it to your site's <head>. The banner handles the rest.
Works with any platform
If it has a <head> tag, CookieFlag works with it.
Features
Covers EU and US privacy requirements. No legal expertise needed.
Analytics, ads, and third-party scripts stay off until your visitor opts in.
Won't slow down your site or hurt your Core Web Vitals.
When privacy laws change, the banner updates automatically.
Signals consent status to Google Analytics and Ads automatically. Required for EU ad personalization.
Visitors choose what they allow — necessary, analytics, or marketing. Full control, no all-or-nothing.
How we compare
Most consent tools are built for enterprise compliance teams. CookieFlag is built for people who just need a banner that works.
| Typical consent tool | CookieFlag | |
|---|---|---|
| Setup time | 30+ minutes of configuration | 2 minutes — paste one script tag |
| Pricing | $10–50/mo, per-pageview tiers | $5/mo flat |
| Script size | 50–200KB | Under 15KB |
| Blocks trackers before consent | Sometimes | Always |
| Customizable design | Limited unless you pay more | Colors, text, and position included |
| Google Consent Mode v2 | Paid add-on or enterprise only | Built in |
| Contracts | Annual plans, cancellation fees | Cancel anytime, no contracts |
Is it right for you?
Pricing
Month-to-month. Cancel in two clicks. We don't do contracts.
Everything included. No tiers, no upsells.
FAQ
If your site sets any non-essential cookies — Google Analytics, Facebook Pixel, embedded YouTube videos, ad scripts — then yes. GDPR requires consent before those cookies load for EU visitors, and CCPA gives California visitors the right to opt out.
CCPA still applies if any visitors are from California. And many US states are passing their own privacy laws. A cookie banner now saves you from scrambling later.
GDPR (EU) requires opt-in consent — cookies can't load until the visitor agrees. CCPA (California) requires opt-out — you can load cookies but must let visitors say no. CookieFlag handles both models automatically.
No. The script is under 15KB, loads asynchronously, and blocks third-party cookies from loading until consent is given — which actually makes your initial page load faster.
CookieFlag groups cookies into categories (necessary, analytics, marketing) so visitors can choose. You don't need to maintain a manual cookie inventory.
Yes. CookieFlag includes Google Consent Mode v2, which signals your visitor's consent choices to Google automatically. Just place the CookieFlag script tag before your Google tags — no extra configuration needed.
Yes. No contracts, no commitments. Cancel from your Stripe billing portal and your banner stops serving at the end of the billing period.