Avacy CMP
Overview The WordPress Consent Solution Plugin is a powerful tool that empowers website owners to easily configure a Consent Management Platform (CMP) and preemptively block all trackers on their website. This plugin ensures compliance with privacy regulations by providing users with the ability to manage their consent preferences for tracking technologies. Features Consent Management Platform (CMP) User-Friendly Interface: The plugin offers an intuitive dashboard for configuring and customizing the Consent Management Platform to suit your website’s needs. Customizable Cookie Banners: Easily create and customize consent banners to inform users about the use of trackers on your website. Consent Logging: Keep track of user consent preferences and ensure compliance with privacy regulations. Tracker Preemptive Blocking Comprehensive Tracker Database: The plugin includes a regularly updated database of known trackers. It enables you to preemptively block these trackers, enhancing user privacy. The plugin preemptively blocks all the scripts that might contain a string in the src attribute or in the inner HTML that matches the strings you can configure on Avacy for each vendor. Avacy is a SaaS-based CMP that helps websites manage user consents efficiently and in compliance with data protection regulations. The platform offers customizable consent forms and integrates seamlessly with various web properties. Compatible with WP Consent API Avacy integrates out-of-the-box with the WP Consent API plugin. When WP Consent API is active, Avacy: registers itself as a compliant CMP (no admin action required); forces the optin consent type so other WP Consent API-aware plugins behave correctly by default; bridges the Avacy banner consent event to wp_set_consent, mapping Google Consent Mode flags to WP Consent API categories. The mapping applied when the user interacts with the banner is: WP Consent API category Granted when the user accepts… functional always allow preferences personalization_storage statistics analytics_storage statistics-anonymous analytics_storage marketing any of ad_storage, ad_user_data, ad_personalization The integration is dormant when WP Consent API is not installed, so it is safe to enable Avacy on any site. Usage Cookie Banners: Cookie banners will automatically appear on your site once configured. Users can manage their consent preferences through these banners. Tracker Control: Trackers are preemptively blocked based on a blacklist JSON file hosted on an AWS content delivery network. Every time a page in the website is loaded, Avacy checks if scripts injected in the current page have src attribute or the innerHTML property containing a string matching the patterns in the blacklist and, if so, overrides some attributes and blocks the script. Every script blocked this way will be launched only if user grants consent to the corresponding vendor and purposes by opting-in from the first layer or by selecting the vendor and its purposes from the second layer (the preference center). CDN Information The CDN used by Avacy is CloudFront, pointing to the following S3 bucket: https://avacy-cdn.s3.eu-central-1.amazonaws.com/ https://assets.avacy-cdn.com/ Integration Example Each custom vendor list can be reached using the following format: https://assets.avacy-cdn.com/config/{avacy_team_name}/{avacy_webspace_key}/custom-vendor-list.json; Explanation Base Url: The base URL for the configuration file is https://assets.avacy-cdn.com/config/. avacy_team_name: This option should be replaced with your specific tenant identifier. This is a unique identifier for your organization within Avacy. avacy_webspace_key: This option should be replaced with your specific webspace key. This is a unique identifier for your specific webspace within your tenant’s account. Example URL Assuming the following: Tenant ID: tenant123 Webspace Key: webspace456 The URL to access the custom vendor list would be: https://assets.avacy-cdn.com/config/tenant123/webspace456/custom-vendor-list.json Account Requirements To connect to and utilize Avacy’s services, you need an active Avacy account with valid credentials, which include: Tenant ID: Provided upon registration with Avacy. Webspace Key: Generated after creating a new web space on Avacy. Ensure you have these credentials available to correctly generate the URLs needed for integration. Avacy Consent Solution API The plugin provides an interface that allows connecting to your consent archive on Avacy. To do this, it’s necessary to generate a token from the Avacy platform and insert it into the Token field in the API token tab. This way, all the forms present on the page will be visible, and it will be possible to select various options, including: the ability to store consents given for that specific form in the consent archive; the fields to store for that form; a field to identify the user who has given the consent to be stored in the archive. Everytime a user submits his data from a contact form, Avacy will perform a POST request towards Avacy Consent API, using the previously generated token as authenticator. Under What Circumstances is Avacy Used? Avacy is utilized whenever users provide consent through forms or interactions on your WordPress site. The plugin sends this consent data to Avacy’s servers for storage and processing. Avacy Service Link For more information about Avacy and its features, visit Avacy’s website. Avacy Terms of Use and Privacy Policies Avacy uses 3rd party services as the Avacy REST API and AWS distributions to provide assets as the blacklist JSON file. Before integrating Avacy with this plugin, please review the Avacy Terms of use and Privacy Policy to understand how your data is handled and what responsibilities you have as a user of their service. We welcome your feedback and suggestions to improve the functionality of the plugin. Disclosure of Third-Party Service Usage Our plugin utilizes third-party services to enhance its functionality. Below, we detail the specific circumstances under which these services are used, along with links to the respective service providers, their terms of use, and privacy policies. Services Utilized Amazon Web Services (AWS) is a leading cloud platform offering a wide range of services, including computing power, storage, and networking, as well as advanced technologies like machine learning and IoT. AWS is designed for flexibility, scalability, and service reliability. AWS CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to users globally with low latency and high transfer speeds. The URLs https://jumpgroup.avacy-cdn.com and https://assets.avacy-cdn.com are custom domains provided to access the AWS CloudFront service. Each asset is fetched from these URLs. Script Enqueuing Script enqueuing involves dynamically adding the main JavaScript core in order to display the cookie banner on your page. This method ensures that scripts are loaded only when needed, reducing page load times and improving performance. Configuration Fetching CMP configuration fetching is used to dynamically load the latest CMP configuration settings and vendor lists from a remote server. This process ensures that the plugin operates with the most current data, improving security, compatibility, and functionality. Service Provider Information Service URL: Amazon Web Services Privacy Policy: AWS Privacy Policy Terms of Use: AWS Terms of Use Legal Protection For your protection and to ensure transparency, we disclose the reliance on third-party services within our plugin. The URLs above provide detailed information on the terms of use and privacy policies of AWS. Users are encouraged to review these documents to understand the terms and conditions under which these third-party services operate. By using our plugin, you acknowledge and agree to these terms and conditions. If you have any questions or concerns, please refer to the provided links or contact us directly for more information. License This WordPress Consent Solution Plugin is licensed under the GNU General Public License v2.0 or later.
Top keywords
- avacy33×2.63%
- consent30×2.39%
- api10×0.80%
- services10×0.80%
- user10×0.80%
- aws9×0.72%
- privacy9×0.72%
- service9×0.72%
- terms8×0.64%
- wp8×0.64%
- avacy-cdn7×0.56%
- com7×0.56%
Terms & Conditions Consent Log
WordPress stores consent as a yes. Nothing about when, from where, or which version of your terms was on screen. The day somebody disputes it, that yes is worth very little. Terms & Conditions Consent Log fills the gap on any acceptance checkbox of your site: WooCommerce checkout (classic and blocks), Contact Form 7, WPForms, Gravity Forms, Fluent Forms, comments, login and registration, or a stand-alone shortcode or block. Every accepted consent writes a row to a dedicated indexed table with the timestamp, the IP, the user agent, the document version in force and the exact text shown, sealed with a SHA-256 hash so any later change is detectable. Exactly what Article 7.1 of the GDPR requires you to be able to demonstrate. Filter, search, export to CSV, integrate with the native WordPress Privacy Tools and open a printable A4 certificate for any record, one click to save it as PDF. Works with or without WooCommerce The admin menu lives under Users → Consent log on every install, with or without WooCommerce. The WooCommerce-specific bits (checkout capture for both the classic and the block checkout, order metabox, “Consent” column on the orders list, optional consent line in the order emails) load only when WooCommerce is active; everything else (Records, Settings, CSV export, PDF certificate, Privacy Tools integration) works the same way on any WordPress site. Sources of consent WooCommerce classic checkout (auto when WC is active): captures the native terms checkbox. Stored as terms_and_privacy. WooCommerce block checkout (auto when WC is active): captures purchases made through the block checkout, which is what WooCommerce builds for new stores since version 8.3 and which the classic hooks never see. Stores the exact wording of the Terms and Conditions block. Recorded as terms_and_privacy when that block requires a checkbox, or as terms_notice when it only shows the informational paragraph WooCommerce ships by default, so acceptance by conduct is never logged as explicit consent. An opt-in toggle adds a required checkbox of the plugin’s own, validated server-side, for evidence that does not depend on browser-side validation. On by default. Contact Form 7 (auto): detects [acceptance] fields automatically and the first email field of the form. Stored as cf7_form_{ID}, one type per form. No snippets required. On by default; turn off in Settings if it does not apply. WPForms (auto): detects GDPR Agreement fields automatically and the first email field of the form. Stored as wpforms_form_{ID}, one type per form. Works with WPForms Lite and Pro. No snippets required. On by default; turn off in Settings if it does not apply. Gravity Forms (auto): detects Consent fields automatically and the first email field of the form. Stored as gravityforms_form_{ID}, one type per form. No snippets required. On by default; turn off in Settings if it does not apply. Fluent Forms (auto): detects GDPR Agreement and Terms & Conditions fields automatically and the first email field of the form. Stored as fluentforms_form_{ID}, one type per form. Works with Fluent Forms Lite and Pro. No snippets required. On by default; turn off in Settings if it does not apply. WordPress comments (auto): logs the native wp-comment-cookies-consent checkbox (introduced in WP 4.9.6) when the visitor opts in. Stored as comment_consent. On by default; turn off in Settings if your site uses Disqus, Jetpack or another third-party comments system. Note that this native checkbox is a cookie preference, not consent to store the commenter’s data. Privacy consent on comments and WooCommerce reviews (opt-in): adds a required privacy checkbox to the comment form, blocks the submission server-side if it is left unticked, and stores the acceptance as comment_privacy. This is the Article 7.1 consent to processing the name and email a commenter hands over, as opposed to the cookie preference above. WooCommerce product reviews share the comment form, so they are covered by the same option. Off by default. Membership, course and custom sign-up forms (opt-in): captures accounts created outside the standard WordPress and WooCommerce forms, such as those from MemberPress, LearnDash, Ultimate Member or Paid Memberships Pro, and multisite sign-ups. Stored as user_register. Accounts created from the admin Users screen are never recorded. Off by default. WordPress login and registration (auto): captures successful logins and registrations through wp-login.php when a consent checkbox is ticked on the form. Stored as wp_login and wp_register. Registration is on by default; login is off by default (a normal login form has no consent checkbox, so login only matters for re-consent flows). The “Remember me” checkbox is excluded by design (ePrivacy / cookie preference, not GDPR consent). WooCommerce login and registration (auto when WC is active): same idea for the My Account page. Stored as wc_login and wc_register. Registration is on by default; login is off by default, like the WordPress rows above. An opt-in toggle can inject the consent checkbox into the WC register form, since WooCommerce does not ship one natively. [tccl_consent_box] shortcode and Gutenberg block: drop a self-contained consent checkbox in any page, post or widget area as a stand-alone block. Submission posts to a REST endpoint and writes a record. Always available. For anything else (Elementor Forms, Forminator, custom flows), call tccl_save_consent() from the appropriate hook. Why a dedicated table Storing thousands of consent records in wp_postmeta is wasteful and slow. The plugin uses its own indexed table and exposes a public function (tccl_save_consent) that you can call from anywhere to log additional consents in the same place. Main features Records timestamp UTC, IP, user agent, document version, source URL and full consent text per acceptance. Custom database table with the right indexes (no wp_postmeta bloat). Tamper-evident: each record is sealed with a SHA-256 hash. Any later change to the stored text is detected and reported as TAMPERED in the records list. Printable A4 certificate per record, with a built-in “Print / Save as PDF” button — the browser exports the certificate to PDF natively, no external library bundled. Native Privacy Tools integration: Tools > Export Personal Data and Tools > Erase Personal Data both include consent records (erasure anonymises rather than deletes — the record itself is the lawful basis to keep it). WooCommerce checkout texts are optional — leave them empty and the WooCommerce native text is shown to the customer and stored verbatim. Automatic version bump when the text changes (suggests MAJOR.MINOR-YYYY-MM-DD). Optional opt-out of IP and/or user agent tracking. Configurable retention with a one-click anonymise button (records kept; PII scrubbed). Configurable access by role: grant the consent log to extra roles (for example a DPO) from Settings → Access, without making them administrators. One record per ticked box: a form with a required privacy checkbox and an optional marketing one produces two separate records, so the optional consent is evidenced on its own instead of being swallowed by the required one. Per-form consent wording: the WordPress login, WordPress registration, WooCommerce login and WooCommerce registration forms can each store their own text, falling back to a site-wide default. Live partial-match filters (email, order, date range, type, full-text search inside the accepted text) + filtered CSV export with UTF-8 BOM (opens cleanly in Excel). (When WooCommerce is active) Order metabox with the consent summary, integrity badge and outdated-version indicator. “Consent” column on the orders list (legacy and HPOS) with a quick visual status. Optional consent line in the New order email (admin) and the order confirmation email (customer) — both off by default. Optional delete_data_on_uninstall setting (off by default) — uninstalling does not destroy consent evidence unless you explicitly opt in. HPOS (custom order tables) compatible. Public tccl_save_consent() function to log consents from anywhere. Translation ready All strings use the terms-conditions-consent-log text domain. Translations are managed through translate.wordpress.org. Support Need private support or custom development? Do you need one-on-one help, priority troubleshooting, or a custom feature, integration, or tweak built specifically for your site? I offer private support and custom development. Just contact me and tell me what you need. Need help or have suggestions? Official website WordPress support forum YouTube channel Documentation and tutorials Love the plugin? Please leave us a 5-star review and help spread the word! About AyudaWP.com We are specialists in WordPress security, SEO, AI and performance optimization plugins. We create tools that solve real problems for WordPress site owners while maintaining the highest coding standards and accessibility requirements.