FAZ Cookie Manager
Tired of cookie consent plugins that lock essential features behind paywalls, require cloud accounts, or send your visitors’ data to third-party servers? FAZ Cookie Manager is a WordPress plugin that helps you implement cookie consent and privacy workflows for international regulations — completely free, with no strings attached. No account to create. The plugin requires no cloud service connection. Basic features like consent logging and geo-targeting are included — no premium plan needed. Core consent features run on your own server, and you own all your data. Why FAZ Cookie Manager? Most cookie consent plugins follow the same pattern: a free version with crippled features, and a paid tier starting at $10-50/month that unlocks what you actually need (cookie scanning, consent logs, Google Consent Mode, IAB TCF). FAZ Cookie Manager breaks that model: Cookie scanner — scans your site directly from your browser. No external service, no API limits, no waiting. Finds the cookies a JavaScript scanner cannot see — cookies set by PHP before the page renders, including HttpOnly ones your browser hides from scripts, are captured from the server response itself: from pages, AJAX, REST calls and sub-resources, then replayed across the URLs the crawl actually visited. Those are exactly the cookies that get set before consent, so a declaration built without them is incomplete. Cookie Policy generator — a jurisdiction-aware policy page (GDPR / CCPA / LGPD / POPIA) built from your own company details and the scanner’s live cookie inventory, published with [faz_cookie_policy_complete]. Ships in en, it, fr, de, es, pt-BR, bg and cs, and every section can be rewritten per jurisdiction and language. Consent logging with CSV export — every consent is recorded locally in your database. Export anytime for audits. Google Consent Mode v2 — all 7 consent signals sent to Google tags. No premium required. IAB TCF v2.3 — full Transparency and Consent Framework API and UI. Operating as a recognised CMP needs your own registered IAB Europe CMP ID; without one the TCF interface stays inactive and no TC string is produced, so invalid signals are never broadcast to vendors. Script blocking — tag any script with data-faz-tag to hold it until its category is accepted. Geo-targeting and 180+ languages — serve the right banner per region and translate every string, or use a built-in translation. Guided setup wizard — a first-run wizard detects your environment (multilingual plugin, page cache, WooCommerce, existing consent data) and configures jurisdiction-appropriate defaults, explaining each choice in plain language. Existing sites are treated as already set up and are never nagged. A/B test your consent banner — run two or more existing banners with a persistent random split and read the accept rate per variant. Only active, independently compliant banners take part, so improving your wording can never quietly become a dark pattern. Off by default. Schrems II transfer disclosure — flag per cookie that a service sends personal data to a country without an EU adequacy decision, with the safeguard you rely on. Worded neutrally: it states the fact and your described safeguard, and never claims that safeguard is legally sufficient. Off by default. Age-appropriate consent (GDPR Art. 8) — an optional age-confirmation checkbox above the buttons. It gates only Accept, never Reject or withdraw, so the two keep equal weight. This is a self-declared affirmation and is not a substitute for the parental-consent verification Art. 8(2) requires. Off by default. Ad-blocker resilience — keeps the legally required notice visible when a cosmetic filter list hides elements whose class contains “cookie” or “consent”. A single deferred re-assert: no loop, no cookie wall. It protects a mandatory notice; it does not circumvent a privacy tool. Off by default. Editable “Do Not Sell” opt-out text — customise the title, description and toggle label of the CCPA / US State Laws opt-out popup, per language. E-commerce & payment friendly — a per-gateway opt-in (PayPal, Stripe, Square, Braintree, Klarna, Mollie, Amazon Pay) lets payment SDKs load before consent when you enable that gateway, so pre-consent blocking never breaks a payment button. Off by default; a real WooCommerce checkout/cart is exempt automatically. Cache & object-cache compatible — purges and bypasses FlyingPress, LiteSpeed, WP Rocket, W3 Total Cache and more on save, epoch-invalidates Redis / Memcached object caches, and keeps WPML, Polylang, TranslatePress and Weglot banners in the right language behind a full-page cache. Details in the FAQ. Microsoft UET/Clarity, revisit widget, accessibility — consent integration for Microsoft tags, a floating button so visitors can change their mind, and keyboard/screen-reader support throughout. Helps with these frameworks This plugin assists consent and privacy workflows. It does not itself create, provide, or guarantee legal compliance, and you remain responsible for the final configuration for your site and jurisdiction. GDPR (EU General Data Protection Regulation) — Opt-in consent, granular categories, right to withdraw CCPA / CPRA (California Consumer Privacy Act) — “Do Not Sell or Share” opt-out link ePrivacy Directive (EU Cookie Law) — Consent-based script blocking support Italian Garante Privacy — 6-month consent expiry setting and consent logging controls EDPB Guidelines — No scroll-as-consent, no pre-checked categories, equal button prominence options LGPD (Brazil General Data Protection Law) — Consent-based model POPIA (South Africa Protection of Personal Information Act) — Conservative consent-based preset under s.11(1)(a); other s.11(1)(b)-(f) justifications require separate assessment Try it Live Try FAZ Cookie Manager in WordPress Playground — no account, no install, runs entirely in your browser. How it works Install and activate — the cookie banner appears immediately with sensible defaults Scan your site to detect cookies automatically Customize the banner design, text, and colors to match your brand Enable Google Consent Mode or IAB TCF if you use advertising tools Monitor consent analytics on the dashboard Core banner functionality runs on your WordPress site. Optional update/download features may contact GitHub, IAB Europe, MaxMind, ipinfo.io (opt-in VPN detection), or the AMP CDN depending on which features you enable and use. Cookie Policy generator A dedicated Cookie Policy admin tab and the [faz_cookie_policy_complete] shortcode build a policy page from the cookies your site actually sets. Jurisdiction-aware — GDPR (EU/EEA/UK), CCPA/CPRA, LGPD or POPIA, each with the legal references and sections that framework requires. Auto-populated — the inventory renders live from the scanner, so a newly discovered cookie appears with its category, duration and description. Multilingual — en, it, fr, de, es, pt-BR, bg, cs; override per render with lang="it" or let the browser decide. Editable per jurisdiction and language — replace any section with your own Markdown, placeholders included; leave one empty and it keeps receiving reviewed updates. Your company data — name, address, DPO email, retention period. Never seeded from admin_email or blogname. Honest by default — a localised disclaimer states the templates are a starting point, not legal advice. The older [faz_cookie_policy] and [faz_cookie_table] shortcodes and the faz/cookie-table block are unchanged. Multi-banner geo-routing and multilingual content Two orthogonal features that combine freely: the visitor’s country decides which banner is served, the visitor’s browser language decides the translation shown inside it. Geo-routing picks a banner per country — typically a strict GDPR banner for the EU/EEA/UK and a CCPA opt-out banner for California — resolving the country from Cloudflare’s CF-IPCountry header (opt-in), then a server GeoIP module or extension, then the self-hosted MaxMind GeoLite2 database. All four are local to your server or your CDN edge; no visitor IP is sent to a third party for country resolution. When none of them is available the most-protective GDPR ruleset is applied to every visitor. Translations live inside each banner and are resolved client-side from navigator.languages, so a country-targeted banner still works behind a full-page cache. In practice that means two banner rows rather than eight: one EU banner holding English, Italian, German, French and Polish, one US banner holding English and Spanish. External Services Summary. This plugin is cloud-free: consent is stored on your own site and there is no vendor account, dashboard or telemetry. Below is the full outbound picture, one heading per item — the optional features that contact an external host (none run unless you enable them), the public REST endpoints this plugin exposes on your own domain, and a note on third-party domain strings that appear in the code as matching patterns and are never contacted. Each entry states its trigger, what leaves your server, and the provider’s terms. GitHub / Raw GitHubusercontent (Open Cookie Database) Used to refresh the built-in cookie definitions snapshot for the optional auto-categorize feature. Triggered when: you click the definitions update action in the Cookies screen. Data sent: your server IP address and standard HTTP request headers. Service URLs: * https://raw.githubusercontent.com/fabiodalez-dev/Open-Cookie-Database/master/open-cookie-database.json Terms of Service / Privacy Policy: * https://docs.github.com/en/site-policy/github-terms/github-terms-of-service * https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement IAB Europe / vendor-list.consensu.org Used to download the Global Vendor List and purpose translations for the optional IAB TCF feature. Triggered when: you manually update the vendor list, and weekly while IAB TCF is enabled. Data sent: your server IP address and standard HTTP request headers. Service URLs: * https://vendor-list.consensu.org/v3/vendor-list.json * https://vendor-list.consensu.org/v3/purposes-en.json Privacy Policy: * https://iabeurope.eu/privacy-policy/ MaxMind Used to download a GeoLite2 database for optional geo-targeting. You choose the edition in Settings → GeoIP Database: the smaller Country edition (default, country-level only) or the larger City edition (adds region/subdivision data for sub-national province/state routing such as Quebec Law 25). City is a much larger download; pick it only if you rely on region-level routing. Triggered when: you enter a MaxMind license key in Settings and start the database download. Data sent: your server IP address, the license key you provide, and standard HTTP request headers. Service URL: * https://download.maxmind.com/app/geoip_download Terms of Service / Privacy Policy: * https://www.maxmind.com/en/terms-of-use * https://www.maxmind.com/en/privacy-policy ipinfo.io (optional live VPN detection and admin preview) The live geo-ruleset runtime applies jurisdiction-specific consent defaults and mandatory controls. If an administrator explicitly enables ipinfo.io, the jurisdiction pipeline may use it to classify a visitor as VPN/proxy/Tor and apply the most-protective fallback; the Geo-routing admin preview uses the same detector. Leave this integration disabled to keep visitor geolocation entirely on trusted headers and the local GeoLite2 database. Triggered when: an administrator has configured an ipinfo API key, confirmed the transfer terms, and enabled the integration, then either a visitor-facing jurisdiction lookup or an admin preview runs the geo detector. Without that explicit opt-in, ipinfo is never called. Data sent: the visitor IP address or the IP entered/resolved for an admin preview, the configured API key, and standard HTTP request headers. The result is cached locally for 24 hours hash-keyed by IP. Service URL: * https://ipinfo.io/{ip}/privacy Terms of Service / Privacy Policy: * https://ipinfo.io/terms-of-service * https://ipinfo.io/privacy-policy * DPA (Data Processing Agreement) available on request: https://ipinfo.io/contact Plugin REST endpoint /faz/v1/banner (public) Serves the banner configuration to the visitor’s browser under Cache Compatibility Mode, so a full-page cache can store one visitor-invariant HTML document while the banner still resolves per request. Hosted by this WordPress install; no third-party host is involved. Triggered when: Cache Compatibility Mode is enabled and a visitor loads a page with no stored consent. Data sent: nothing about the visitor. The response carries banner text, categories and styling only. Service URL: * https://{your-site}/wp-json/faz/v1/banner Plugin REST endpoints /faz/v1/amp-consent/check and /update (public) Used by the plugin’s AMP banner to reconcile the AMP consent cache with the first-party FAZ consent cookie. Both are hosted by the same WordPress install. Requests must pass AMP CORS provenance checks — the publisher origin, or that publisher’s exact HTTPS Google AMP Cache origin with the matching __amp_source_origin. Arbitrary origins, another publisher’s cache subdomain, and requests without AMP provenance are rejected before consent can change. Sites on another registered AMP cache can add their own verified exact origin with the faz_amp_consent_allowed_cache_origin filter. Triggered when: an AMP page checks an existing decision, or the visitor saves AMP cookie preferences. Data sent: banner scope, consent state, per-category purpose choices, and the AMP-generated user ID that amp-consent includes. FAZ neither stores nor logs that ID, and does not derive its consent identifier from it. The update endpoint tries to synchronise the first-party cookie with SameSite=None; Secure; a browser that blocks third-party cookies may refuse it behind an AMP Cache, and the bridge then fails closed and asks again rather than claiming cross-origin parity it cannot guarantee. Service URLs: * https://{your-site}/wp-json/faz/v1/amp-consent/check * https://{your-site}/wp-json/faz/v1/amp-consent/update AMP Project CDN Used only on AMP pages when the AMP consent integration is active, to load the official amp-consent component required by AMP. Triggered when: an AMP page renders the AMP consent banner. Data sent: the visitor IP address and standard browser request data to the AMP CDN. Service URL: * https://cdn.ampproject.org/v0/amp-consent-0.1.js Documentation / Privacy: * https://amp.dev/documentation/components/amp-consent * https://policies.google.com/privacy Note on third-party domain strings inside the plugin codebase The source contains third-party domain names (js.stripe.com, connect.facebook.net, googletagmanager.com and others) purely as string patterns, for two purposes: Blocking detection — to recognise analytics, advertising and tracking scripts injected by the site’s other plugins, so they can be held until consent. This plugin loads none of them itself. Explicit exceptions — no whole third-party plugin is whitelisted and no profiling resource is: Google Fonts, Google Maps, OAuth endpoints and generic CDNs stay blocked until consent. The only defaults are four anti-abuse challenge endpoints (reCAPTCHA, its gstatic assets, Cloudflare Turnstile, hCaptcha), which gate a form the visitor is actively submitting and are therefore strictly necessary. An administrator can add a narrow audited exception in Settings, and can remove the CAPTCHA defaults too. Every outbound request documented above happens only when its feature is used. /faz/v1/banner is hosted by this plugin on the same site: no third-party call leaves the visitor’s browser. Cache Plugin Compatibility When multi-banner geo-routing is active, the rendered HTML can legitimately vary by visitor country. This plugin asks the page-cache layer to bypass caching on those requests by emitting: Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache X-LiteSpeed-Cache-Control: no-cache CDN-Cache-Control: no-store and Cloudflare-CDN-Cache-Control: no-store (banner REST endpoint only, so an edge that overrides the browser directive still refuses to store the country-dependent payload) Vary: CF-IPCountry (when the trust filter faz_trust_cf_ipcountry_header is enabled). It is emitted for symmetry but is inert on these responses: nothing is stored, so there is no cache key to vary. Vary only does work on the storable responses — the banner REST endpoint’s non-country-dependent answers, which are served public, max-age=300 and carry the same header. DONOTCACHEPAGE, …
Top keywords
- consent38×1.53%
- cookie28×1.13%
- banner25×1.01%
- amp20×0.81%
- https20×0.81%
- faz19×0.77%
- data17×0.69%
- cache16×0.65%
- visitor15×0.61%
- service13×0.52%
- policy12×0.48%
- privacy12×0.48%
SureCookie – GDPR Cookie Consent Banner, Cookie Scanner & Script Blocking
SureCookie is a WordPress cookie consent plugin that helps you scan cookies, display a customizable cookie banner, block non-essential scripts before consent, and store consent logs inside your WordPress database. It is built for site owners, E-commerce stores, agencies, bloggers, and WordPress professionals who want more than a basic cookie notice. SureCookie helps you understand what cookies and third-party services are running on your site, lets visitors manage their choices, and gives you a practical consent workflow without visitor-based pricing. 👉 Try the live demo of SureCookie. Not Just a Cookie Banner A cookie notice can tell visitors that your site uses cookies, but that alone does not manage consent. If analytics scripts, marketing pixels, video embeds, maps, or tag manager scripts run before visitors choose, the banner is only cosmetic. SureCookie connects the banner to the rest of the workflow: scan the site, review detected cookies, block non-essential scripts before consent, store consent logs locally, and keep your cookie policy easier to maintain. How SureCookie Works SureCookie follows a simple WordPress cookie consent workflow: Scan selected pages with the real browser cookie scanner. Review detected cookies, scripts, resources, and third-party domains. Organize cookies into consent categories such as Essential, Functional, Analytics, and Marketing. Enable script blocking so non-essential scripts wait for consent. Show the cookie consent banner and preference modal to visitors. Store consent logs locally in WordPress for review and export. Generate or connect a cookie policy page that reflects your cookie setup. This makes SureCookie more than a WordPress cookie banner. Many cookie plugins focus only on the visitor-facing notice, while SureCookie focuses on what happens before and after it: cookie detection, script blocking, consent records, and policy support. Free Features Included The WordPress.org version of SureCookie includes the core consent workflow: Cookie consent banner: Show a clean banner or notice for visitors. Preference modal: Let visitors review and manage cookie categories. Accept, Accept All, Decline, and Preferences buttons: Control the button text and order. Real browser cookie scanner: Scan selected pages using a browser-based scanning service. Cookie categories: Use Essential, Functional, Analytics, Marketing, and Uncategorized categories. See managing cookie categories. Custom cookies: Add and manage cookies manually when needed. Script blocking: Block non-essential scripts before consent is given. Resource blocking: Manage scripts, iframes, embeds, and objects found during scans. Consent logs: Store visitor choices inside your WordPress database. Consent log filters: Search and filter logs by action, country, IP, and session ID. Consent PDF export: Export individual consent records for documentation. Consent retention settings: Control how long consent logs are kept. Monthly automatic scanning: Schedule recurring scans on the free plan. Scan history and change detection: See what changed between scans, including newly detected cookies and domains. Rule-based category suggestions: Get suggested categories for newly detected cookies. Cookie policy page: Generate a page with dynamic cookie tables. Re-consent controls: Add a Cookie Preferences link through a shortcode or menu item. Re-request consent: Ask all visitors to review choices again when needed. Google Consent Mode support: Send consent states to supported Google services. WP Consent API support: Share consent state with compatible WordPress plugins. Multilingual support: Work with WPML and Polylang for banner and admin text. RTL support: Display frontend cookie policy content correctly for RTL languages. MCP and WordPress Abilities support: Enable AI assistant access to SureCookie management actions when supported. No visitor-based limits: SureCookie does not charge by traffic or monthly visitors. Free vs Pro Clarity Everything listed above is in the free plugin. Advanced workflows are reserved for SureCookie Pro: weekly automatic scans, email scan digests, auto-apply behavior, compliance guard workflows, geographic targeting (which applies CCPA-style opt-out rules per region), and consent forwarding. Compare on the features page or see plans and pricing. Real Browser Cookie Scanner SureCookie uses a browser-based scanning service at https://library.surecookie.com/ to inspect selected pages. See how the cookie scanner works. Instead of only reading static HTML, the scanner loads your pages in a real browser environment. This helps detect cookies and resources that appear after page load, through tag managers, or through third-party scripts. The scanner can help identify: Analytics, marketing, advertising, functional, and preference cookies WooCommerce and WordPress session cookies Third-party domains and resources Tag manager loaded and dynamically injected scripts Monthly Automatic Scanning When enabled, SureCookie runs scheduled monthly scans through WP-Cron. The scan uses the same scanner engine, respects the configured scan scope, and records the latest scan history. Full setup is in the automatic scheduled scanning guide. The scan history can show: Newly detected cookies Removed cookies Recategorized cookies Newly detected third-party domains Whether the scan was manual or automatic The last scan date and cookie count Script Blocking Before Consent SureCookie can block non-essential scripts before the visitor gives consent. When blocking is enabled, SureCookie processes the frontend HTML and converts matching resources so they do not execute until the relevant cookie category is allowed. It can handle scripts as well as embedded content such as iframes, embeds, and objects. This matters because a banner alone does not stop tracking. SureCookie is designed to connect consent choices with technical enforcement. The script blocker also includes safeguards so it skips admin pages, REST requests, AJAX requests, feeds, JSON responses, XML responses, and scanner bypass requests. The resource and script blocking guide covers how scripts, iframes and embeds are matched. Customizable Banner and Preferences SureCookie gives you control over the visitor-facing consent experience. You can customize: Banner message and description Rich text banner content Accept, Accept All, Decline, and Preferences button labels Button order Banner position and width Banner logo Banner animation Background overlay Preference modal heading and description Cookie category labels and descriptions Custom CSS Visitors can accept all cookies, decline non-essential cookies, or open the preferences modal and choose specific categories. See customizing banner content and banner layout for every option, and custom CSS for banner styling if you need finer control. Consent Logs Stored Locally SureCookie stores consent records inside your WordPress database. This is different from many SaaS consent management platforms where consent records live on an external platform. With SureCookie, your consent logs stay on your WordPress site and can be reviewed from the admin area. Consent logs can include: User session ID Consent action, such as accepted, declined, or partially accepted Cookie category preferences Masked IP address Timestamp Country Admins can view, search, filter, delete, and export logs from WordPress. SureCookie also includes retention settings so you can control how long logs are kept. See understanding consent logs and exporting consent logs to PDF or CSV. Cookie Policy Page and Generator SureCookie includes a cookie policy generator that can create a Cookie Policy page for your website. The generated page uses native WordPress blocks and includes a dynamic shortcode that displays cookie tables grouped by category and provider. The cookie policy content can include: Cookie categories Cookie names Purpose or description Duration Domain Last updated timestamp A table of contents when multiple categories are available You can edit the generated policy page in the WordPress editor and keep the dynamic cookie table connected to your scanned and manually added cookies. Walkthrough: how to generate a cookie policy page. Re-Consent and Re-Request Consent Visitors should be able to change their choices later. SureCookie includes a re-consent shortcode: [surecookie_reconsent_button] You can use it to add a Cookie Preferences button on your site. SureCookie can also add a virtual Cookie Preferences item to a selected WordPress navigation menu. Admins can also re-request consent from all visitors. This is useful after updating your cookie policy, adding new tracking tools, changing categories, or making a major consent workflow change. See the re-consent guide. Google Consent Mode When enabled, SureCookie sends consent states for supported Google services and updates them when visitors change their preferences. Setup steps: setting up Google Consent Mode v2. It maps SureCookie categories to Google consent signals, detects Google services from enqueued scripts or the page HTML, and hides block toggles that Google Consent Mode already manages. WP Consent API SureCookie reads its consent cookie and syncs the visitor’s consent state so compatible WordPress plugins can check consent using the standardized WP Consent API flow. Default category mapping includes: Essential to functional Functional to preferences Analytics to statistics Marketing to marketing Developers can customize mappings through filters. Multilingual and RTL Support SureCookie includes multilingual compatibility for WPML and Polylang. It can register and translate banner text, button labels, preference modal text, category labels, and related frontend strings. It also includes RTL support for cookie policy layouts. MCP and WordPress Abilities When enabled, AI assistants and compatible tools can use structured SureCookie abilities to manage settings, cookie categories, consent logs, cookie management, and site scanner actions. Scanner start actions still require care because they contact an external scanning service. Who Should Use SureCookie? SureCookie is a good fit for: WordPress site owners and agencies who need a cookie consent banner across client sites E-commerce stores and publishers using analytics, ads, pixels, embeds, or marketing tools Businesses running tag managers, heatmaps, video embeds, maps, forms, or CRM and conversion tracking Developers who want a WordPress-native consent workflow with hooks and APIs, and consent logs kept inside WordPress Important Legal Note SureCookie provides technical tools for cookie scanning, script blocking, consent collection, consent logging, and cookie policy management. No WordPress plugin can guarantee legal compliance on its own. Privacy and cookie requirements depend on your website, visitors, region, policies, data processing practices, and legal obligations. For legal advice, consult a qualified legal professional. External Services SureCookie uses external services for cookie scanning, site verification, and geolocation. Cookie Scanning SureCookie connects to https://library.surecookie.com/ to provide real browser-based cookie scanning and smart categorization. When you run a scan, SureCookie sends the selected page URLs to the scanning service. A browser-based scanner visits those pages and detects cookies, scripts, resources, and third-party domains. Scanner Registration and Authentication Before the first scan, SureCookie performs a one-time registration handshake with library.surecookie.com/api/register. The request sends: Site URL WordPress admin email SureCookie version A temporary installation nonce (one-time, random) The scanning service verifies the site through a temporary REST endpoint, then returns site-specific credentials and a verification token. These credentials are stored locally in a non-autoloaded WordPress option and are used for authenticated scan requests. Consent IP Logs and Region Detection For consent logging and country detection, visitor IP addresses may be processed through MaxMind-backed region detection through SureCookie’s service. This helps SureCookie record the country in the consent log. IP addresses are masked before being stored in your WordPress database. MaxMind attribution: https://www.maxmind.com Service URLs SureCookie scanning and geolocation service: https://library.surecookie.com/ SureCookie privacy policy: https://surecookie.com/privacy-policy/ MaxMind: https://www.maxmind.com Data Stored Locally SureCookie stores plugin settings and consent data in your WordPress database. This can include: Banner and preference modal settings Cookie categories Custom cookies Scanned cookies Scanned resources Scan history Consent logs Cookie policy page ID Automatic scan settings Scanner credentials Consent logs and scan results can be viewed, exported, or deleted from the WordPress admin. Privacy and Data Processing SureCookie processes data through its API service at library.surecookie.com for cookie scanning, scanner authentication, and region-aware consent logging. Here is what happens and why. What We Send to SureCookie Services During the one-time scanner registration and site verification flow, SureCookie sends the site URL, the WordPress administrator email, the SureCookie version, and a temporary installation nonce. The scanning service uses these to verify your site and issue credentials, then returns a verification token that SureCookie exposes at a temporary REST endpoint for domain verification. After registration, scan requests use site-specific credentials stored locally in WordPress and do not resend the admin email. When a scan runs, SureCookie sends selected page URLs to the scanning service so a real browser can detect cookies, scripts, resources, and third-party domains. What Is Processed and Why Cookie scanning: Selected page URLs are scanned in a real browser environment to detect cookies, scripts, resources, and third-party domains. Cookie categorization: Detected cookie details, such as names, domains, and durations, are used to help categorize cookies. Region detection: Visitor IP addresses may be processed through MaxMind-backed region detection to determine country-level location for consent logs. IP addresses are masked before being stored in your WordPress database. Consent records: Consent choices, timestamps, category preferences, and session details are logged locally in your WordPress database. Where Data Lives Consent logs, scan results, settings, and scanner credentials are stored in your WordPress database. Data sent to library.surecookie.com for scanning and geolocation may be temporarily processed for those features. SureCookie does not sell this data or use it for advertising. Data Retention and Control Consent logs and scan results can be viewed, exported, or deleted from your WordPress admin. Consent log retention periods are configurable in plugin settings. Scanner credentials are stored locally in a non-autoloaded WordPress option. Security API communication uses HTTPS. Scan requests use authenticated site credentials after the registration flow. Site credentials are used to sign later scan requests. Because visitor data and selected page URLs can be processed through SureCookie services, you should mention this in your site’s privacy policy where appropriate. Full details: https://surecookie.com/privacy-policy/ For questions about data processing, visit https://surecookie.com/support/. Useful Links SureCookie Website Documentation Support Forum Privacy Policy Live Demo About Brainstorm Force SureCookie is built by Brainstorm Force, the team behind Astra and other widely used WordPress products.