Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA
This is Cookie Compliance for WordPress — the WordPress component of Cookie Compliance, the consent management platform by Hu-manity.co. (Previously published as “Compliance by Hu-manity.co”, and before that “Cookie Notice”.) One product: this plugin runs the consent banner on your WordPress site, and the Cookie Compliance dashboard is where you configure it, manage every domain you own, and keep your consent records. Cookie Compliance is a fully featured Consent Management Platform (CMP) that provides automated compliance features and enhanced design controls in a state-of-the-art web application. Cookie Compliance enables websites to take a proactive approach to data protection and consent laws. It is the first solution to offer Intentional Consent, a new consent framework that incorporates the latest guidelines from over 100+ countries, and emerging standards from leading international organizations like the IEEE and European Center for Digital Rights (noyb.eu). Cookie Compliance provides a beautiful, multi-level experience and includes new choices and controls for site visitors to better understand and engage in data privacy decisions. You can run this plugin two ways. In Banner Only mode it works on its own, with no account, and gives you the consent banner and its settings. In Connected mode — free or paid — you sign in to Cookie Compliance from inside WordPress and the plugin unlocks the platform features listed below: automatic script blocking, purpose categories, consent records, Google, Microsoft and Facebook consent modes, multilingual banners and multi-domain management. The two lists below say exactly which features belong to which mode. Our Cookie Compliance web application introduces a more ethical, proactive way to capture and manage consent. This early version of the emerging Intentional Consent framework is a result of Hu-manity.co’s ongoing work with top Fortune 500 companies, governments, and standards organizations, who believe that the imbalanced relationship between consumers and corporations is unsustainable when it comes to data privacy and consent online. We are making it available for all website owners and operators who share this belief and support our mission to eliminate the dark patterns in online consent. Matt Sinderbrand – Chief Platform Officer, Hu-manity.co Banner Only mode (this plugin on its own, no account) Cookie Compliance for WordPress provides a simple, customizable website banner to help your website comply with certain cookie consent requirements. Banner features: Customizable notice message Consent on click, scroll or close Multiple cookie expiry options Link to Privacy Policy page WordPress Privacy Policy page synchronization WPML and Polylang compatible SEO friendly Connected mode (this plugin + the Cookie Compliance dashboard) Signed in to Cookie Compliance, on a free or paid plan, you get access to the most up-to-date formatting guidelines and technical compliance requirements for over 100 countries and legal jurisdictions. Banner features: Intentional Consent provides 3 equal buttons to give site visitors the ability to accept none, some, or all cookies through packaged choices called Data Access Levels. Data Access Levels improve consent conversion and eliminate the dark pattern of deceptive, non-equal choices in the first layer. Complies with equal choice principle prescribed under GDPR and other data protection laws. Consent duration selector gives visitor control over how long their consent remains valid for your site. Enables your site to align with recent guidelines from EU Data Protection Authorities, which state that cookie consent should be valid for no longer than a period of 6 months. Cookie purpose categories make it easy for website visitors to customize their consent by category. Complies with affirmative, opt-in consent requirements prescribed under GDPR and other data protection laws. Consent metrics displays the visitor’s consent record and a list of blocked / allowed 3rd parties directly in the expanded level of the banner. Complies with latest guidance from EU Data Protection Authorities like CNIL (France) and ICO (UK). Customizable Privacy Paper provides helpful information to improve visitor comprehension and understanding of the data sharing risks and benefits. Allows you to summarize core components of your sites privacy notice and aligns with the informed principle prescribed by GDPR rules for valid consent capture. Configurable Privacy Contact allows you to provide contact information for a business’ data privacy admin, as well as helpful links to data subject request forms and other data privacy resources. Aligns with the informed principle prescribed by GDPR rules for valid consent capture. Cookie Compliance dashboard features: Consent analytics dashboard shows event data for number of visits and provides a “trust score” to help you track how site visitors are setting their consent. Make adjustments to your banner to improve your cookie acceptance rate and monitor progress via the consent activity graph. Default configurations for GDPR, CCPA and more help to remove dark patterns and allow for quick and easy deployment of the consent banner without any guesswork. Customize the design of any default configuration to match the look and feel of your site. Automatic script blocking blocks all non-essential cookie scripts and iFrames by default and complies with valid consent rules under GDPR and other data protection laws; in order to be compliant, your site must record visitor consent before setting or sending cookies. Google Consent Mode v2 ensures that your website can still gather valuable insights and perform effectively while respecting users’ privacy preferences by dynamically adjusting the behavior of Google services (ad_storage, analytics_storage, ad_user_data, ad_personalization) according to user consent. Facebook Consent Mode allows your website to measure the impact of your ads on Facebook, track website activities and conversions and automatically deliver ads to Facebook if the user has agreed to. Consent record storage automatically stores a record of each consent and makes these records available for export. Complies with proof-of-consent requirements prescribed under GDPR and other data protection laws. Multilingual support automatically translates all banner text strings and allows you to provide custom translations for every text field to ensure visitors get a consistent consent experience. Multidomain management allows you to manage additional Free or Professional domains under a single account and enables you to customize banner configuration and design for each domain independently. Cookie Compliance proactive approach: For all businesses, the resources required to stay ahead of the latest regulations increases with the passage of each new law. With enforcement of compliance violations increasing daily, we believe it is critical for us as a trusted consent vendor to do everything in our power to help you stay ahead of these laws and remove the risk to your business Cookie Compliance covers all current and upcoming regulations: GDPR (EU) ePrivacy Directive (EU) ePrivacy Regulation (EU) PECR (UK) LGPD (Brazil) PIPEDA (Canada) PDPB (India) CCPA (California, US) VCDPA (Virginia, US) Colorado Privacy Act (US) CPRA (California, US) Cookie Compliance incorporates all recent formatting guidance: European Data Protection Supervisor (EDPS) ICO (United Kingdom) CNIL (France) GPDP (Italy) BfDl (Germany) AEPD (Spain) European Center for Digital Rights (noyb.eu) Cookie Compliance targets dark patterns Dark Patterns are user interface (UI) techniques that push site visitors to make decisions (such as agreeing to the installation of cookies on their devices) that they might not otherwise make. The most common Dark Pattern is the lack of an equal “reject all” button on the first layer of the consent notice. Dark Patterns are explicitly banned under GDPR and other data protection laws. As a part of our proactive approach, Cookie Compliance is configured by default to prevent Dark Patterns through our unique Intentional Consent design. Privacy Cookie Compliance for WordPress is a Consent Management Platform client. Depending on how you use it, the plugin may send data to Hu-manity.co services on your behalf. This section describes what data leaves your WordPress server and when. It is kept up to date as the plugin evolves; material changes are noted in the changelog. Plugin-only mode (Banner Only) If you install the plugin and choose “Banner Only” in the Welcome screen — or never open the Welcome screen at all — the plugin operates entirely on your WordPress site. No account is created and the plugin does not initiate calls to Hu-manity.co services. Connected mode (Free or Professional) If you create a Cookie Compliance account from the Welcome screen (or log into an existing one), the plugin connects your site to the Hu-manity.co platform. While connected, the plugin sends data over HTTPS to Hu-manity.co’s platform services (hosted under *-api.hu-manity.co) for the following purposes: Account sign-up and sign-in, and registering your site as an application. Fetching and updating your banner configuration. Fetching consent analytics and individual consent records shown in the Audit Trail. Processing subscription payments (Professional plans only). The data sent depends on the feature you are using and typically includes: Account-identifying data such as the email address and password used for sign-up or sign-in. Site-identifying data such as your site’s URL, title, description, and language. Application credentials (App ID and Secret Key) issued to your site at registration, included with subsequent platform requests. Subscription and billing data for Professional plans, such as the selected plan identifier and a one-time payment token described below. Integration telemetry such as the plugin version, the admin interface and language you use, which of the plugin’s own options are switched on, basic diagnostics about how it is running, and which of the caching or JavaScript-optimisation plugins it needs to stay compatible with are active on your site, and whether a Google, Meta or Microsoft tracking plugin is active, sent as HTTP headers so we can understand integration adoption and support the plugin. Operational metadata such as the timestamp and locale of a request, as is normal for HTTPS API calls. As the plugin evolves, additional non-personal fields of the same categories listed above may be sent to support new features. Material changes are noted in the changelog. Payments (Professional plans only) Payment card details are collected by Braintree’s hosted-fields SDK running in your browser and are tokenized there. The plugin and Hu-manity.co servers do not receive raw card data. A one-time, non-replayable Braintree token is sent to Hu-manity.co’s platform to create the subscription. Deactivation feedback If you deactivate the plugin and fill in the optional deactivation feedback form, the reason you select, any free-text comment you type, and your site URL are sent once to Hu-manity.co so we can improve the product. Submitting the form is optional; clicking “Skip” sends nothing. This applies to both Plugin-only and Connected modes. The banner shown to your site visitors The consent banner shown to your site visitors is served from cdn.hu-manity.co/hu-banner.min.js. When a visitor interacts with the banner, the banner script (running in the visitor’s browser, not the plugin) communicates directly with Hu-manity.co services to record the consent decision — this is what makes consent records available to you in the Audit Trail. This data flow is between the visitor’s browser and Hu-manity.co and does not pass through your WordPress server. Because these requests originate in the visitor’s browser, the visitor’s IP address is visible to Hu-manity.co as part of standard HTTPS network handling. Local state set by the plugin The plugin stores operational state in three places. None of this is transmitted to Hu-manity.co: On your WordPress server (options and transients) — for example, a welcome-modal dismissal timestamp (cookie_notice_welcome_dismissed) and short-lived caches of API tokens and configuration. In the admin user’s browser (localStorage) — for example, first-run setup flags such as cn_setup_wizard_complete_* and cn_has_platform_config_*. In visitor browsers (a short-lived hu-form cookie, 5 minutes) — set when forms with consent integration are submitted. Used locally by the form-consent flow. As the plugin evolves, additional keys may be stored in any of these locations. They remain local state on your site or in the user’s browser — not data sent to Hu-manity.co. Material changes to this pattern would be noted in the changelog. Data the plugin does not send The plugin does not transmit visitor IP addresses, cookies, page URLs, or page content as data fields. IP addresses are, as with any HTTPS request, visible to the receiving server as part of standard network handling. The plugin does not transmit the content of your posts, pages, users, or WordPress database. The plugin does not send data to third parties other than Hu-manity.co and, for Professional plan payments, Braintree (a PayPal service). Service providers Hu-manity.co / Cookie Compliance — primary service provider. Terms of Service: https://cookie-compliance.co/terms-of-service/ Privacy contact: https://cookie-compliance.co/documentation/privacy-contact/ Braintree (a PayPal service) — processes Professional plan signups initiated from the plugin (not invoked for Banner Only or Free). When you manage your subscription from the Cookie Compliance web application, additional payment gateway providers may process your billing information. Hu-manity.co’s email subscription service — receives your account email address and name to manage newsletter and operational email preferences. You can unsubscribe at any time via the email footer or by deleting your account. Account and consent data is processed in the European Union (AWS Ireland region). Hu-manity.co’s public marketing websites (hu-manity.co, cookie-compliance.co) are hosted separately in the United States. How long we retain your data Plugin-side caches on your WordPress server (API tokens, subscription data, configuration) are short-lived, with TTLs typically up to 24 hours. The visitor hu-form cookie expires after 5 minutes. On the Hu-manity.co platform, account information and consent records are retained as long as your Cookie Compliance account is active, and are removed when the account is deleted or via an erasure request. What rights you have over your data Stop further sends. Deactivate the plugin from the Plugins screen — no further plugin-initiated API calls will be made. Export consent records. Site owners can export cookie-consent and privacy-consent logs as CSV from the Cookie Compliance web application. Delete your account and all associated data. The Cookie Compliance web application has an account-deletion flow. Triggering it cancels active subscriptions, deletes your apps and banner configuration, removes your consent records from the platform, and nullifies free-text personal data before deleting the account. Erasure of visitor data (GDPR Article 17 / CCPA Delete). To request erasure of a specific visitor’s records (by email, session ID, IP, or consent ID), contact Hu-manity.co via the privacy contact page above. Hu-manity.co processes the request and erases the matching records from its storage systems within 30 days, in line with GDPR Article 12. Manage consent (visitors). Site visitors can adjust their consent at any time through the consent banner.
Top keywords
- consent57×2.37%
- data39×1.62%
- cookie34×1.41%
- co29×1.20%
- compliance28×1.16%
- hu-manity26×1.08%
- hu-manity co26×1.08%
- cookie compliance24×1.00%
- banner22×0.91%
- site21×0.87%
- account14×0.58%
- privacy14×0.58%
FAZ Cookie Manager
Tired of cookie consent plugins that lock essential features behind paywalls, require cloud accounts, or send your visitors’ data to third-party servers? FAZ Cookie Manager is a WordPress plugin that helps you implement cookie consent and privacy workflows for international regulations — completely free, with no strings attached. No account to create. The plugin requires no cloud service connection. Basic features like consent logging and geo-targeting are included — no premium plan needed. Core consent features run on your own server, and you own all your data. Why FAZ Cookie Manager? Most cookie consent plugins follow the same pattern: a free version with crippled features, and a paid tier starting at $10-50/month that unlocks what you actually need (cookie scanning, consent logs, Google Consent Mode, IAB TCF). FAZ Cookie Manager breaks that model: Cookie scanner — scans your site directly from your browser. No external service, no API limits, no waiting. Finds the cookies a JavaScript scanner cannot see — cookies set by PHP before the page renders, including HttpOnly ones your browser hides from scripts, are captured from the server response itself: from pages, AJAX, REST calls and sub-resources, then replayed across the URLs the crawl actually visited. Those are exactly the cookies that get set before consent, so a declaration built without them is incomplete. Cookie Policy generator — a jurisdiction-aware policy page (GDPR / CCPA / LGPD / POPIA) built from your own company details and the scanner’s live cookie inventory, published with [faz_cookie_policy_complete]. Ships in en, it, fr, de, es, pt-BR, bg and cs, and every section can be rewritten per jurisdiction and language. Consent logging with CSV export — every consent is recorded locally in your database. Export anytime for audits. Google Consent Mode v2 — all 7 consent signals sent to Google tags. No premium required. IAB TCF v2.3 — full Transparency and Consent Framework API and UI. Operating as a recognised CMP needs your own registered IAB Europe CMP ID; without one the TCF interface stays inactive and no TC string is produced, so invalid signals are never broadcast to vendors. Script blocking — tag any script with data-faz-tag to hold it until its category is accepted. Geo-targeting and 180+ languages — serve the right banner per region and translate every string, or use a built-in translation. Guided setup wizard — a first-run wizard detects your environment (multilingual plugin, page cache, WooCommerce, existing consent data) and configures jurisdiction-appropriate defaults, explaining each choice in plain language. Existing sites are treated as already set up and are never nagged. A/B test your consent banner — run two or more existing banners with a persistent random split and read the accept rate per variant. Only active, independently compliant banners take part, so improving your wording can never quietly become a dark pattern. Off by default. Schrems II transfer disclosure — flag per cookie that a service sends personal data to a country without an EU adequacy decision, with the safeguard you rely on. Worded neutrally: it states the fact and your described safeguard, and never claims that safeguard is legally sufficient. Off by default. Age-appropriate consent (GDPR Art. 8) — an optional age-confirmation checkbox above the buttons. It gates only Accept, never Reject or withdraw, so the two keep equal weight. This is a self-declared affirmation and is not a substitute for the parental-consent verification Art. 8(2) requires. Off by default. Ad-blocker resilience — keeps the legally required notice visible when a cosmetic filter list hides elements whose class contains “cookie” or “consent”. A single deferred re-assert: no loop, no cookie wall. It protects a mandatory notice; it does not circumvent a privacy tool. Off by default. Editable “Do Not Sell” opt-out text — customise the title, description and toggle label of the CCPA / US State Laws opt-out popup, per language. E-commerce & payment friendly — a per-gateway opt-in (PayPal, Stripe, Square, Braintree, Klarna, Mollie, Amazon Pay) lets payment SDKs load before consent when you enable that gateway, so pre-consent blocking never breaks a payment button. Off by default; a real WooCommerce checkout/cart is exempt automatically. Cache & object-cache compatible — purges and bypasses FlyingPress, LiteSpeed, WP Rocket, W3 Total Cache and more on save, epoch-invalidates Redis / Memcached object caches, and keeps WPML, Polylang, TranslatePress and Weglot banners in the right language behind a full-page cache. Details in the FAQ. Microsoft UET/Clarity, revisit widget, accessibility — consent integration for Microsoft tags, a floating button so visitors can change their mind, and keyboard/screen-reader support throughout. Helps with these frameworks This plugin assists consent and privacy workflows. It does not itself create, provide, or guarantee legal compliance, and you remain responsible for the final configuration for your site and jurisdiction. GDPR (EU General Data Protection Regulation) — Opt-in consent, granular categories, right to withdraw CCPA / CPRA (California Consumer Privacy Act) — “Do Not Sell or Share” opt-out link ePrivacy Directive (EU Cookie Law) — Consent-based script blocking support Italian Garante Privacy — 6-month consent expiry setting and consent logging controls EDPB Guidelines — No scroll-as-consent, no pre-checked categories, equal button prominence options LGPD (Brazil General Data Protection Law) — Consent-based model POPIA (South Africa Protection of Personal Information Act) — Conservative consent-based preset under s.11(1)(a); other s.11(1)(b)-(f) justifications require separate assessment Try it Live Try FAZ Cookie Manager in WordPress Playground — no account, no install, runs entirely in your browser. How it works Install and activate — the cookie banner appears immediately with sensible defaults Scan your site to detect cookies automatically Customize the banner design, text, and colors to match your brand Enable Google Consent Mode or IAB TCF if you use advertising tools Monitor consent analytics on the dashboard Core banner functionality runs on your WordPress site. Optional update/download features may contact GitHub, IAB Europe, MaxMind, ipinfo.io (opt-in VPN detection), or the AMP CDN depending on which features you enable and use. Cookie Policy generator A dedicated Cookie Policy admin tab and the [faz_cookie_policy_complete] shortcode build a policy page from the cookies your site actually sets. Jurisdiction-aware — GDPR (EU/EEA/UK), CCPA/CPRA, LGPD or POPIA, each with the legal references and sections that framework requires. Auto-populated — the inventory renders live from the scanner, so a newly discovered cookie appears with its category, duration and description. Multilingual — en, it, fr, de, es, pt-BR, bg, cs; override per render with lang="it" or let the browser decide. Editable per jurisdiction and language — replace any section with your own Markdown, placeholders included; leave one empty and it keeps receiving reviewed updates. Your company data — name, address, DPO email, retention period. Never seeded from admin_email or blogname. Honest by default — a localised disclaimer states the templates are a starting point, not legal advice. The older [faz_cookie_policy] and [faz_cookie_table] shortcodes and the faz/cookie-table block are unchanged. Multi-banner geo-routing and multilingual content Two orthogonal features that combine freely: the visitor’s country decides which banner is served, the visitor’s browser language decides the translation shown inside it. Geo-routing picks a banner per country — typically a strict GDPR banner for the EU/EEA/UK and a CCPA opt-out banner for California — resolving the country from Cloudflare’s CF-IPCountry header (opt-in), then a server GeoIP module or extension, then the self-hosted MaxMind GeoLite2 database. All four are local to your server or your CDN edge; no visitor IP is sent to a third party for country resolution. When none of them is available the most-protective GDPR ruleset is applied to every visitor. Translations live inside each banner and are resolved client-side from navigator.languages, so a country-targeted banner still works behind a full-page cache. In practice that means two banner rows rather than eight: one EU banner holding English, Italian, German, French and Polish, one US banner holding English and Spanish. External Services Summary. This plugin is cloud-free: consent is stored on your own site and there is no vendor account, dashboard or telemetry. Below is the full outbound picture, one heading per item — the optional features that contact an external host (none run unless you enable them), the public REST endpoints this plugin exposes on your own domain, and a note on third-party domain strings that appear in the code as matching patterns and are never contacted. Each entry states its trigger, what leaves your server, and the provider’s terms. GitHub / Raw GitHubusercontent (Open Cookie Database) Used to refresh the built-in cookie definitions snapshot for the optional auto-categorize feature. Triggered when: you click the definitions update action in the Cookies screen. Data sent: your server IP address and standard HTTP request headers. Service URLs: * https://raw.githubusercontent.com/fabiodalez-dev/Open-Cookie-Database/master/open-cookie-database.json Terms of Service / Privacy Policy: * https://docs.github.com/en/site-policy/github-terms/github-terms-of-service * https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement IAB Europe / vendor-list.consensu.org Used to download the Global Vendor List and purpose translations for the optional IAB TCF feature. Triggered when: you manually update the vendor list, and weekly while IAB TCF is enabled. Data sent: your server IP address and standard HTTP request headers. Service URLs: * https://vendor-list.consensu.org/v3/vendor-list.json * https://vendor-list.consensu.org/v3/purposes-en.json Privacy Policy: * https://iabeurope.eu/privacy-policy/ MaxMind Used to download a GeoLite2 database for optional geo-targeting. You choose the edition in Settings → GeoIP Database: the smaller Country edition (default, country-level only) or the larger City edition (adds region/subdivision data for sub-national province/state routing such as Quebec Law 25). City is a much larger download; pick it only if you rely on region-level routing. Triggered when: you enter a MaxMind license key in Settings and start the database download. Data sent: your server IP address, the license key you provide, and standard HTTP request headers. Service URL: * https://download.maxmind.com/app/geoip_download Terms of Service / Privacy Policy: * https://www.maxmind.com/en/terms-of-use * https://www.maxmind.com/en/privacy-policy ipinfo.io (optional live VPN detection and admin preview) The live geo-ruleset runtime applies jurisdiction-specific consent defaults and mandatory controls. If an administrator explicitly enables ipinfo.io, the jurisdiction pipeline may use it to classify a visitor as VPN/proxy/Tor and apply the most-protective fallback; the Geo-routing admin preview uses the same detector. Leave this integration disabled to keep visitor geolocation entirely on trusted headers and the local GeoLite2 database. Triggered when: an administrator has configured an ipinfo API key, confirmed the transfer terms, and enabled the integration, then either a visitor-facing jurisdiction lookup or an admin preview runs the geo detector. Without that explicit opt-in, ipinfo is never called. Data sent: the visitor IP address or the IP entered/resolved for an admin preview, the configured API key, and standard HTTP request headers. The result is cached locally for 24 hours hash-keyed by IP. Service URL: * https://ipinfo.io/{ip}/privacy Terms of Service / Privacy Policy: * https://ipinfo.io/terms-of-service * https://ipinfo.io/privacy-policy * DPA (Data Processing Agreement) available on request: https://ipinfo.io/contact Plugin REST endpoint /faz/v1/banner (public) Serves the banner configuration to the visitor’s browser under Cache Compatibility Mode, so a full-page cache can store one visitor-invariant HTML document while the banner still resolves per request. Hosted by this WordPress install; no third-party host is involved. Triggered when: Cache Compatibility Mode is enabled and a visitor loads a page with no stored consent. Data sent: nothing about the visitor. The response carries banner text, categories and styling only. Service URL: * https://{your-site}/wp-json/faz/v1/banner Plugin REST endpoints /faz/v1/amp-consent/check and /update (public) Used by the plugin’s AMP banner to reconcile the AMP consent cache with the first-party FAZ consent cookie. Both are hosted by the same WordPress install. Requests must pass AMP CORS provenance checks — the publisher origin, or that publisher’s exact HTTPS Google AMP Cache origin with the matching __amp_source_origin. Arbitrary origins, another publisher’s cache subdomain, and requests without AMP provenance are rejected before consent can change. Sites on another registered AMP cache can add their own verified exact origin with the faz_amp_consent_allowed_cache_origin filter. Triggered when: an AMP page checks an existing decision, or the visitor saves AMP cookie preferences. Data sent: banner scope, consent state, per-category purpose choices, and the AMP-generated user ID that amp-consent includes. FAZ neither stores nor logs that ID, and does not derive its consent identifier from it. The update endpoint tries to synchronise the first-party cookie with SameSite=None; Secure; a browser that blocks third-party cookies may refuse it behind an AMP Cache, and the bridge then fails closed and asks again rather than claiming cross-origin parity it cannot guarantee. Service URLs: * https://{your-site}/wp-json/faz/v1/amp-consent/check * https://{your-site}/wp-json/faz/v1/amp-consent/update AMP Project CDN Used only on AMP pages when the AMP consent integration is active, to load the official amp-consent component required by AMP. Triggered when: an AMP page renders the AMP consent banner. Data sent: the visitor IP address and standard browser request data to the AMP CDN. Service URL: * https://cdn.ampproject.org/v0/amp-consent-0.1.js Documentation / Privacy: * https://amp.dev/documentation/components/amp-consent * https://policies.google.com/privacy Note on third-party domain strings inside the plugin codebase The source contains third-party domain names (js.stripe.com, connect.facebook.net, googletagmanager.com and others) purely as string patterns, for two purposes: Blocking detection — to recognise analytics, advertising and tracking scripts injected by the site’s other plugins, so they can be held until consent. This plugin loads none of them itself. Explicit exceptions — no whole third-party plugin is whitelisted and no profiling resource is: Google Fonts, Google Maps, OAuth endpoints and generic CDNs stay blocked until consent. The only defaults are four anti-abuse challenge endpoints (reCAPTCHA, its gstatic assets, Cloudflare Turnstile, hCaptcha), which gate a form the visitor is actively submitting and are therefore strictly necessary. An administrator can add a narrow audited exception in Settings, and can remove the CAPTCHA defaults too. Every outbound request documented above happens only when its feature is used. /faz/v1/banner is hosted by this plugin on the same site: no third-party call leaves the visitor’s browser. Cache Plugin Compatibility When multi-banner geo-routing is active, the rendered HTML can legitimately vary by visitor country. This plugin asks the page-cache layer to bypass caching on those requests by emitting: Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache X-LiteSpeed-Cache-Control: no-cache CDN-Cache-Control: no-store and Cloudflare-CDN-Cache-Control: no-store (banner REST endpoint only, so an edge that overrides the browser directive still refuses to store the country-dependent payload) Vary: CF-IPCountry (when the trust filter faz_trust_cf_ipcountry_header is enabled). It is emitted for symmetry but is inert on these responses: nothing is stored, so there is no cache key to vary. Vary only does work on the storable responses — the banner REST endpoint’s non-country-dependent answers, which are served public, max-age=300 and carry the same header. DONOTCACHEPAGE, …