A video on your page is already setting cookies
Paste a YouTube video into a page and it starts tracking whoever opens it, before your cookie banner has finished appearing. The same goes for an embedded map, a Calendly booking widget, an Instagram post. Consentify holds all of them back until someone agrees, and you do not have to change anything to get it.
There is nothing to set up
Use the code the provider gives you, exactly as they wrote it. We recognise it on the page and take it from there. No special elements, no snippets to copy out of a dashboard, no list to keep up to date.
What we hold back
Ten services today, and the list grows without you doing anything. Each one waits for the kind of consent that actually fits it.
Waits for marketing consent
YouTube, Vimeo, Spotify, SoundCloud, Instagram, Facebook, X, Typeform
Waits for functional consent
Google Maps, Calendly
The split matters. Someone who turns down marketing can still find your office on a map and book a meeting with you.
What people see in the meantime
A small box where the video would be, in your banner's own colours, saying which service is hidden and why. One button takes them to your cookie settings, opened at that service with its cookies listed. The moment they accept, the real content appears in its place.
Your cookie declaration follows along
Add a video to a page months from now and nobody has to remember to update anything. The first person who opens that page is enough for it to appear in your declaration, cookies and all. We work this out from what visitors' browsers actually see, so we never crawl your website.
What we do not claim
We hold back the services we recognise. Paste an unusual tracking pixel straight into your HTML and it is not on our list, so it will load. The better answer for anything you can configure through us is that it never reaches your page at all.
How gated consent worksFor developers
The guard runs synchronously from the head and watches the document through a MutationObserver as it is parsed. A matching iframe has its src moved to a data attribute and removed before the browser fetches it. Loader scripts are taken out of the DOM and re-inserted on consent, and their widget containers are hidden so they do not leave an empty gap in the layout.
The placeholder lives in a shadow root, so your stylesheet cannot reach into it and its styles cannot leak onto your page. Colours come from your banner configuration, and CSS custom properties on the host let you override them from your own stylesheet if you want to.
Being honest about the limit: this is a race against the parser, and it is won in practice rather than guaranteed by the specification. It depends on our script being synchronous and in the head. Add async, or move it to the end of the body, and content may start loading before we can stop it. Elements inserted later by your own scripts are always caught.
Does any of this apply to your site?
Find out in ten seconds. The scan shows which trackers fire before your visitors have agreed to anything.
- Results in about 10 seconds
- No account needed
- Shareable report link
Find out what your site loads before consent
The scanner checks any address for trackers and embeds that fire too early. No signup, no install.
- 1 domain
- 5,000 pageviews/mo
- All integrations
- GDPR, CCPA and ePrivacy