CookieBoxs – GDPR/CCPA Cookie Consent & Google Consent Mode v2
CookieBoxs is a cookie consent plugin for WordPress that helps site owners manage visitor consent preferences and configure consent-aware integrations. Free features include: Google Consent Mode v2 support Automatic script blocker and cookie cleaner 25+ built-in integrations Content blockers for embedded media and maps 40 interface languages Region presets Consent logging in WordPress Floating settings badge Self-hosted plugin files Optional PRO features include two-phase Cookie Scanner (server + browser-based detection), geo-targeting, additional templates, cookie declaration, consent analytics, tamper-proof consent records with CSV export and printable certificates, A/B testing of banner variants, granular per-service consent, a live banner design editor, branding options, and custom CSS. Documentation: cookieboxs.com Source Code All JavaScript and CSS files included in this plugin are human-readable and not minified or compiled. No build tools (npm, webpack, composer) are required to work with this plugin’s source code. All plugin-authored JavaScript and CSS is written directly and included as-is. Third-party libraries and embed snippets: assets/js/chart.min.js — Chart.js library (MIT License). Source code and unminified version available at: https://github.com/chartjs/Chart.js assets/js/cookieboxs-consent-mode.js — Contains standard third-party integration embed snippets (e.g., Google Tag Manager, Meta Pixel, TikTok Pixel, Microsoft Clarity, Hotjar, LiveChat, Intercom, etc.). These are the official JavaScript snippets provided by each service for website embedding, written in their standard compact form. Each snippet includes a source URL comment pointing to the official documentation. A full list of source URLs is also available in the file header comments. The surrounding plugin logic (consent state management, Google Consent Mode v2 setup, custom script injection) is authored by this plugin and is fully human-readable. Official documentation URLs for all embedded third-party snippets: Google Tag Manager: https://developers.google.com/tag-platform/tag-manager/web Meta Pixel: https://developers.facebook.com/docs/meta-pixel/get-started TikTok Pixel: https://ads.tiktok.com/help/article/get-started-pixel Microsoft Clarity: https://learn.microsoft.com/en-us/clarity/setup-and-installation/clarity-setup Hotjar: https://help.hotjar.com/hc/en-us/articles/115011639927 Heap Analytics: https://developers.heap.io/docs/web Mixpanel: https://docs.mixpanel.com/docs/tracking-methods/sdks/javascript PostHog: https://posthog.com/docs/libraries/js LinkedIn Insight Tag: https://learn.microsoft.com/en-us/linkedin/marketing/integrations/ads-reporting/insight-tag Pinterest Tag: https://help.pinterest.com/en/business/article/install-the-pinterest-tag Snapchat Pixel: https://businesshelp.snapchat.com/s/article/snap-pixel-about Twitter/X Pixel: https://business.x.com/en/help/campaign-measurement-and-analytics/conversion-tracking-for-websites Microsoft Advertising UET: https://help.ads.microsoft.com/apex/index/3/en/56682 LiveChat: https://developers.livechat.com/docs/getting-started/installing-livechat Crisp: https://docs.crisp.chat/guides/chatbox-sdks/web-sdk/ Tawk.to: https://help.tawk.to/article/adding-a-tawk-to-widget-to-your-website Intercom: https://developers.intercom.com/installing-intercom/web/installation Yandex Metrica: https://yandex.com/support/metrica/code/counter-initialize.html Matomo: https://developer.matomo.org/guides/tracking-javascript-guide Privacy Policy CookieBoxs does not send visitor consent records to the plugin author’s servers. Consent records are stored in the WordPress database. Optional third-party integrations that you configure, such as analytics, advertising, chat, or embedded media services, connect directly from the visitor’s browser to those third-party providers after the relevant consent conditions are met. Admin-only connections used for plugin news, optional deactivation feedback, or optional license validation are described below. External Services This plugin uses external services only for user-configured integrations. Third-party integrations are optional, disabled by default, and only activated when the site administrator enables and configures them. The plugin does not offload any of its own assets (JavaScript, CSS, images) to external servers — all plugin files are included locally. Plugin services VisionSolutions API – plugin news and updates: used in the admin area only; sends plugin version, WordPress version, and site language when an administrator opens the settings page. Provider: VisionSolutions, https://visionsolutions.pl Terms of use: https://visionsolutions.pl/regulamin/ Privacy policy: https://visionsolutions.pl/polityka-prywatnosci/ VisionSolutions API – deactivation feedback (optional): sends selected reason, optional comment, site URL, WordPress version, and PHP version only if an administrator submits feedback during deactivation. Provider: VisionSolutions Terms of use: https://visionsolutions.pl/regulamin/ Privacy policy: https://visionsolutions.pl/polityka-prywatnosci/ VisionSolutions API – PRO license validation (optional): sends license key, site domain, and plugin version on activation and periodic validation. Provider: VisionSolutions Terms of use: https://visionsolutions.pl/regulamin/ Privacy policy: https://visionsolutions.pl/polityka-prywatnosci/ ipapi.co geolocation API (optional, PRO): used only when geo-targeting is enabled and fallback geolocation is needed; sends visitor IP address. Provider: ipapi Terms of use: https://ipapi.co/terms/ Privacy policy: https://ipapi.co/privacy/ Cookie Scanner (admin-initiated, PRO): two-phase scan. Phase 1 (server): sends requests from your server to your own website pages to detect cookies and tracking scripts from HTML. Phase 2 (browser): loads the scanned page in a hidden iframe within the administrator’s browser to detect cookies set by JavaScript (e.g. pixels loaded via Google Tag Manager). All scanning happens locally — no external provider is contacted. Optional integrations (services) These are third-party services that the site administrator can optionally enable. When enabled, the plugin loads the official embed snippet provided by each service, which connects the visitor’s browser directly to that service provider. These are service integrations, not offloaded plugin assets. Each integration is disabled by default and only activates when the administrator provides their account ID. Google Tag Manager – tag management service; may load on page view and use Consent Mode signals. Loaded from: www.googletagmanager.com. Provider: Google LLC. Terms of use: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy policy: https://policies.google.com/privacy Google Analytics 4 – analytics service; loaded from www.googletagmanager.com/gtag/js via wp_enqueue_script. Provider: Google LLC. Terms of use: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy policy: https://policies.google.com/privacy Google Ads – conversion tracking and remarketing service; loaded from www.googletagmanager.com/gtag/js via wp_enqueue_script. Provider: Google LLC. Terms of use: https://ads.google.com/intl/en/home/terms/ Privacy policy: https://policies.google.com/privacy Meta Pixel – advertising measurement service; loaded from connect.facebook.net. Provider: Meta Platforms, Inc. Terms of use: https://www.facebook.com/legal/terms Privacy policy: https://www.facebook.com/privacy/policy/ TikTok Pixel – advertising measurement service; loaded from analytics.tiktok.com. Provider: TikTok Inc. / ByteDance Ltd. Terms of use: https://ads.tiktok.com/i18n/official/policy/business-products-terms Privacy policy: https://www.tiktok.com/legal/privacy-policy Microsoft Clarity – session analytics and heatmaps service; loaded from www.clarity.ms. Provider: Microsoft Corporation. Terms of use: https://clarity.microsoft.com/terms Privacy policy: https://privacy.microsoft.com/en-us/privacystatement Hotjar – heatmaps, recordings, and feedback service; loaded from static.hotjar.com. Provider: Hotjar Ltd. Terms of use: https://www.hotjar.com/legal/policies/terms-of-service/ Privacy policy: https://www.hotjar.com/legal/policies/privacy/ Matomo – analytics service; loaded from the site administrator’s configured Matomo instance URL. Provider: InnoCraft Ltd. or the site owner’s Matomo host. Terms of use: https://matomo.org/matomo-cloud-terms-of-service/ Privacy policy: https://matomo.org/matomo-cloud-privacy-policy/ Yandex Metrica – analytics service; loaded from mc.yandex.ru. Provider: Yandex LLC. Terms of use: https://yandex.com/legal/metrica_termsofuse/ Privacy policy: https://yandex.com/legal/confidential/ Heap Analytics – analytics service; loaded from cdn.heapanalytics.com. Provider: Heap Inc. Terms of use: https://heap.io/legal/heap-terms-of-service Privacy policy: https://heap.io/legal/privacy Mixpanel – analytics service; loaded from cdn.mxpnl.com. Provider: Mixpanel, Inc. Terms of use: https://mixpanel.com/legal/terms-of-use/ Privacy policy: https://mixpanel.com/legal/privacy-policy/ PostHog – analytics and feature flags service; loaded from the site administrator’s configured PostHog host. Provider: PostHog, Inc. Terms of use: https://posthog.com/terms Privacy policy: https://posthog.com/privacy LinkedIn Insight Tag – advertising measurement service; loaded from snap.licdn.com. Provider: LinkedIn Corporation. Terms of use: https://www.linkedin.com/legal/l/li-marketing-terms Privacy policy: https://www.linkedin.com/legal/privacy-policy Pinterest Tag – advertising measurement service; loaded from s.pinimg.com. Provider: Pinterest, Inc. Terms of use: https://policy.pinterest.com/en/terms-of-service Privacy policy: https://policy.pinterest.com/en/privacy-policy Snapchat Pixel – advertising measurement service; loaded from sc-static.net. Provider: Snap Inc. Terms of use: https://snap.com/en-US/terms Privacy policy: https://snap.com/en-US/privacy/privacy-policy Twitter/X Pixel – advertising measurement service; loaded from static.ads-twitter.com. Provider: X Corp. Terms of use: https://twitter.com/en/tos Privacy policy: https://twitter.com/en/privacy Microsoft Advertising UET – conversion tracking service; loaded from bat.bing.com. Provider: Microsoft Corporation. Terms of use: https://about.ads.microsoft.com/en-us/policies/legal Privacy policy: https://privacy.microsoft.com/en-us/privacystatement Intercom – customer messaging service; loaded from widget.intercom.io and api-iam.intercom.io. Provider: Intercom, Inc. Terms of use: https://www.intercom.com/legal/terms-and-policies Privacy policy: https://www.intercom.com/legal/privacy LiveChat – support chat service; loaded from cdn.livechatinc.com. Provider: LiveChat, Inc. Terms of use: https://www.livechat.com/legal/terms-of-service/ Privacy policy: https://www.livechat.com/legal/privacy-policy/ Crisp – customer messaging and chat service; loaded from client.crisp.chat. Provider: Crisp IM SAS. Terms of use: https://crisp.chat/en/terms/ Privacy policy: https://crisp.chat/en/privacy/ Tawk.to – support chat service; loaded from embed.tawk.to. Provider: Tawk.to Ltd. Terms of use: https://www.tawk.to/legal/terms-of-service/ Privacy policy: https://www.tawk.to/legal/privacy-policy/ Script blocker safe domains The automatic script blocker does not block scripts from essential service domains (payment gateways, CAPTCHAs, translation). These domains are whitelisted so the script blocker does not interfere with site-critical functionality provided by other plugins or themes. The CookieBoxs plugin itself does not load any files from these domains — they are only whitelisted to prevent breakage: Stripe – payment processing service; loaded by other plugins from js.stripe.com and checkout.stripe.com. Provider: Stripe, Inc. Terms of use: https://stripe.com/legal/ssa Privacy policy: https://stripe.com/privacy PayPal – payment processing service; loaded by other plugins from www.paypal.com and www.paypalobjects.com. Provider: PayPal Holdings, Inc. Terms of use: https://www.paypal.com/us/legalhub/useragreement-full Privacy policy: https://www.paypal.com/us/legalhub/privacy-full Google reCAPTCHA – spam protection service; loaded by other plugins from recaptcha.net. Provider: Google LLC. Terms of use: https://policies.google.com/terms Privacy policy: https://policies.google.com/privacy hCaptcha – spam protection service; loaded by other plugins from js.hcaptcha.com. Provider: Intuition Machines, Inc. Terms of use: https://www.hcaptcha.com/terms Privacy policy: https://www.hcaptcha.com/privacy Cloudflare Turnstile – bot protection service; loaded by other plugins from challenges.cloudflare.com. Provider: Cloudflare, Inc. Terms of use: https://www.cloudflare.com/terms/ Privacy policy: https://www.cloudflare.com/privacypolicy/ Google Translate – translation service widget; loaded by other plugins from translate.google.com and translate.googleapis.com. Provider: Google LLC. Terms of use: https://policies.google.com/terms Privacy policy: https://policies.google.com/privacy Content blockers Content blockers are an optional feature that replaces embedded third-party media (YouTube, Vimeo, Google Maps) with a placeholder until the visitor grants consent. When consent is given, the embed loads normally from the service provider. YouTube – video embeds can be blocked until consent; loaded from www.youtube.com and www.youtube-nocookie.com. Provider: Google LLC. Terms of use: https://www.youtube.com/t/terms Privacy policy: https://policies.google.com/privacy Vimeo – video embeds can be blocked until consent; loaded from player.vimeo.com and vimeo.com. Provider: Vimeo, Inc. Terms of use: https://vimeo.com/terms Privacy policy: https://vimeo.com/privacy Google Maps – map embeds can be blocked until consent; loaded from www.google.com/maps and maps.googleapis.com. Provider: Google LLC. Terms of use: https://cloud.google.com/maps-platform/terms Privacy policy: https://policies.google.com/privacy
Top keywords
- com95×4.90%
- https89×4.59%
- privacy56×2.89%
- terms50×2.58%
- policy39×2.01%
- provider37×1.91%
- privacy policy36×1.86%
- google35×1.81%
- policy https34×1.76%
- privacy policy https34×1.76%
- service33×1.70%
- loaded31×1.60%
SureCookie – GDPR Cookie Consent Banner, Cookie Scanner & Script Blocking
SureCookie is a WordPress cookie consent plugin that helps you scan cookies, display a customizable cookie banner, block non-essential scripts before consent, and store consent logs inside your WordPress database. It is built for site owners, E-commerce stores, agencies, bloggers, and WordPress professionals who want more than a basic cookie notice. SureCookie helps you understand what cookies and third-party services are running on your site, lets visitors manage their choices, and gives you a practical consent workflow without visitor-based pricing. 👉 Try the live demo of SureCookie. Not Just a Cookie Banner A cookie notice can tell visitors that your site uses cookies, but that alone does not manage consent. If analytics scripts, marketing pixels, video embeds, maps, or tag manager scripts run before visitors choose, the banner is only cosmetic. SureCookie connects the banner to the rest of the workflow: scan the site, review detected cookies, block non-essential scripts before consent, store consent logs locally, and keep your cookie policy easier to maintain. How SureCookie Works SureCookie follows a simple WordPress cookie consent workflow: Scan selected pages with the real browser cookie scanner. Review detected cookies, scripts, resources, and third-party domains. Organize cookies into consent categories such as Essential, Functional, Analytics, and Marketing. Enable script blocking so non-essential scripts wait for consent. Show the cookie consent banner and preference modal to visitors. Store consent logs locally in WordPress for review and export. Generate or connect a cookie policy page that reflects your cookie setup. Generate a privacy policy draft whose cookie and consent sections stay in step with your settings. This makes SureCookie more than a WordPress cookie banner. Many cookie plugins focus only on the visitor-facing notice, while SureCookie focuses on what happens before and after it: cookie detection, script blocking, consent records, and policy support. Free Features Included The WordPress.org version of SureCookie includes the core consent workflow: Cookie consent banner: Show a clean banner or notice for visitors. Privacy policy generator: Build a privacy policy draft from your cookie and consent settings, with the factual sections kept current by shortcodes. Business details: Enter your legal entity, address and privacy contact once, then reuse them anywhere with shortcodes such as [surecookie_company_name]. Preference modal: Let visitors review and manage cookie categories. Accept, Accept All, Decline, and Preferences buttons: Control the button text and order. Real browser cookie scanner: Scan selected pages using a browser-based scanning service. Cookie categories: Use Essential, Functional, Analytics, Marketing, and Uncategorized categories. See managing cookie categories. Custom cookies: Add and manage cookies manually when needed. Script blocking: Block non-essential scripts before consent is given. Resource blocking: Manage scripts, iframes, embeds, and objects found during scans. Consent logs: Store visitor choices inside your WordPress database. Consent log filters: Search and filter logs by action, country, IP, and session ID. Consent PDF export: Export individual consent records for documentation. Consent retention settings: Control how long consent logs are kept. Monthly automatic scanning: Schedule recurring scans on the free plan. Scan history and change detection: See what changed between scans, including newly detected cookies and domains. Rule-based category suggestions: Get suggested categories for newly detected cookies. Cookie policy page: Generate a page with dynamic cookie tables. Re-consent controls: Add a Cookie Preferences link through a shortcode or menu item. Re-request consent: Ask all visitors to review choices again when needed. Google Consent Mode support: Send consent states to supported Google services. WP Consent API support: Share consent state with compatible WordPress plugins. Multilingual support: Work with WPML and Polylang for banner and admin text. RTL support: Display frontend cookie policy content correctly for RTL languages. MCP and WordPress Abilities support: Enable AI assistant access to SureCookie management actions when supported. No visitor-based limits: SureCookie does not charge by traffic or monthly visitors. Free vs Pro Clarity Everything listed above is in the free plugin. Advanced workflows are reserved for SureCookie Pro: weekly automatic scans, email scan digests, auto-apply behavior, compliance guard workflows, geographic targeting (which applies CCPA-style opt-out rules per region), and consent forwarding. Compare on the features page or see plans and pricing. Real Browser Cookie Scanner SureCookie uses a browser-based scanning service at https://library.surecookie.com/ to inspect selected pages. See how the cookie scanner works. Instead of only reading static HTML, the scanner loads your pages in a real browser environment. This helps detect cookies and resources that appear after page load, through tag managers, or through third-party scripts. The scanner can help identify: Analytics, marketing, advertising, functional, and preference cookies WooCommerce and WordPress session cookies Third-party domains and resources Tag manager loaded and dynamically injected scripts Monthly Automatic Scanning When enabled, SureCookie runs scheduled monthly scans through WP-Cron. The scan uses the same scanner engine, respects the configured scan scope, and records the latest scan history. Full setup is in the automatic scheduled scanning guide. The scan history can show: Newly detected cookies Removed cookies Recategorized cookies Newly detected third-party domains Whether the scan was manual or automatic The last scan date and cookie count Script Blocking Before Consent SureCookie can block non-essential scripts before the visitor gives consent. When blocking is enabled, SureCookie processes the frontend HTML and converts matching resources so they do not execute until the relevant cookie category is allowed. It can handle scripts as well as embedded content such as iframes, embeds, and objects. This matters because a banner alone does not stop tracking. SureCookie is designed to connect consent choices with technical enforcement. The script blocker also includes safeguards so it skips admin pages, REST requests, AJAX requests, feeds, JSON responses, XML responses, and scanner bypass requests. The resource and script blocking guide covers how scripts, iframes and embeds are matched. Customizable Banner and Preferences SureCookie gives you control over the visitor-facing consent experience. You can customize: Banner message and description Rich text banner content Accept, Accept All, Decline, and Preferences button labels Button order Banner position and width Banner logo Banner animation Background overlay Preference modal heading and description Cookie category labels and descriptions Custom CSS Visitors can accept all cookies, decline non-essential cookies, or open the preferences modal and choose specific categories. See customizing banner content and banner layout for every option, and custom CSS for banner styling if you need finer control. Consent Logs Stored Locally SureCookie stores consent records inside your WordPress database. This is different from many SaaS consent management platforms where consent records live on an external platform. With SureCookie, your consent logs stay on your WordPress site and can be reviewed from the admin area. Consent logs can include: User session ID Consent action, such as accepted, declined, or partially accepted Cookie category preferences Masked IP address Timestamp Country Admins can view, search, filter, delete, and export logs from WordPress. SureCookie also includes retention settings so you can control how long logs are kept. See understanding consent logs and exporting consent logs to PDF or CSV. Cookie Policy Page and Generator SureCookie includes a cookie policy generator that can create a Cookie Policy page for your website. The generated page uses native WordPress blocks and includes a dynamic shortcode that displays cookie tables grouped by category and provider. The cookie policy content can include: Cookie categories Cookie names Purpose or description Duration Domain Last updated timestamp A table of contents when multiple categories are available You can edit the generated policy page in the WordPress editor and keep the dynamic cookie table connected to your scanned and manually added cookies. Walkthrough: how to generate a cookie policy page. Re-Consent and Re-Request Consent Visitors should be able to change their choices later. SureCookie includes a re-consent shortcode: [surecookie_reconsent_button] You can use it to add a Cookie Preferences button on your site. SureCookie can also add a virtual Cookie Preferences item to a selected WordPress navigation menu. Admins can also re-request consent from all visitors. This is useful after updating your cookie policy, adding new tracking tools, changing categories, or making a major consent workflow change. See the re-consent guide. Google Consent Mode When enabled, SureCookie sends consent states for supported Google services and updates them when visitors change their preferences. Setup steps: setting up Google Consent Mode v2. It maps SureCookie categories to Google consent signals, detects Google services from enqueued scripts or the page HTML, and hides block toggles that Google Consent Mode already manages. WP Consent API SureCookie reads its consent cookie and syncs the visitor’s consent state so compatible WordPress plugins can check consent using the standardized WP Consent API flow. Default category mapping includes: Essential to functional Functional to preferences Analytics to statistics Marketing to marketing Developers can customize mappings through filters. Multilingual and RTL Support SureCookie includes multilingual compatibility for WPML and Polylang. It can register and translate banner text, button labels, preference modal text, category labels, and related frontend strings. It also includes RTL support for cookie policy layouts. MCP and WordPress Abilities When enabled, AI assistants and compatible tools can use structured SureCookie abilities to manage settings, cookie categories, consent logs, cookie management, and site scanner actions. Scanner start actions still require care because they contact an external scanning service. Who Should Use SureCookie? SureCookie is a good fit for: WordPress site owners and agencies who need a cookie consent banner across client sites E-commerce stores and publishers using analytics, ads, pixels, embeds, or marketing tools Businesses running tag managers, heatmaps, video embeds, maps, forms, or CRM and conversion tracking Developers who want a WordPress-native consent workflow with hooks and APIs, and consent logs kept inside WordPress Important Legal Note SureCookie provides technical tools for cookie scanning, script blocking, consent collection, consent logging, and cookie policy management. No WordPress plugin can guarantee legal compliance on its own. Privacy and cookie requirements depend on your website, visitors, region, policies, data processing practices, and legal obligations. For legal advice, consult a qualified legal professional. External Services SureCookie uses external services for cookie scanning, site verification, and geolocation. Cookie Scanning SureCookie connects to https://library.surecookie.com/ to provide real browser-based cookie scanning and smart categorization. When you run a scan, SureCookie sends the selected page URLs to the scanning service. A browser-based scanner visits those pages and detects cookies, scripts, resources, and third-party domains. Scanner Registration and Authentication Before the first scan, SureCookie performs a one-time registration handshake with library.surecookie.com/api/register. The request sends: Site URL WordPress admin email SureCookie version A temporary installation nonce (one-time, random) The scanning service verifies the site through a temporary REST endpoint, then returns site-specific credentials and a verification token. These credentials are stored locally in a non-autoloaded WordPress option and are used for authenticated scan requests. Consent IP Logs and Region Detection For consent logging and country detection, visitor IP addresses may be processed through MaxMind-backed region detection through SureCookie’s service. This helps SureCookie record the country in the consent log. IP addresses are masked before being stored in your WordPress database. MaxMind attribution: https://www.maxmind.com Service URLs SureCookie scanning and geolocation service: https://library.surecookie.com/ SureCookie privacy policy: https://surecookie.com/privacy-policy/ MaxMind: https://www.maxmind.com Data Stored Locally SureCookie stores plugin settings and consent data in your WordPress database. This can include: Banner and preference modal settings Cookie categories Custom cookies Scanned cookies Scanned resources Scan history Consent logs Cookie policy page ID Automatic scan settings Scanner credentials Consent logs and scan results can be viewed, exported, or deleted from the WordPress admin. Privacy and Data Processing SureCookie processes data through its API service at library.surecookie.com for cookie scanning, scanner authentication, and region-aware consent logging. Here is what happens and why. What We Send to SureCookie Services During the one-time scanner registration and site verification flow, SureCookie sends the site URL, the WordPress administrator email, the SureCookie version, and a temporary installation nonce. The scanning service uses these to verify your site and issue credentials, then returns a verification token that SureCookie exposes at a temporary REST endpoint for domain verification. After registration, scan requests use site-specific credentials stored locally in WordPress and do not resend the admin email. When a scan runs, SureCookie sends selected page URLs to the scanning service so a real browser can detect cookies, scripts, resources, and third-party domains. What Is Processed and Why Cookie scanning: Selected page URLs are scanned in a real browser environment to detect cookies, scripts, resources, and third-party domains. Cookie categorization: Detected cookie details, such as names, domains, and durations, are used to help categorize cookies. Region detection: Visitor IP addresses may be processed through MaxMind-backed region detection to determine country-level location for consent logs. IP addresses are masked before being stored in your WordPress database. Consent records: Consent choices, timestamps, category preferences, and session details are logged locally in your WordPress database. Where Data Lives Consent logs, scan results, settings, and scanner credentials are stored in your WordPress database. Data sent to library.surecookie.com for scanning and geolocation may be temporarily processed for those features. SureCookie does not sell this data or use it for advertising. Data Retention and Control Consent logs and scan results can be viewed, exported, or deleted from your WordPress admin. Consent log retention periods are configurable in plugin settings. Scanner credentials are stored locally in a non-autoloaded WordPress option. Security API communication uses HTTPS. Scan requests use authenticated site credentials after the registration flow. Site credentials are used to sign later scan requests. Because visitor data and selected page URLs can be processed through SureCookie services, you should mention this in your site’s privacy policy where appropriate. Full details: https://surecookie.com/privacy-policy/ For questions about data processing, visit https://surecookie.com/support/. Useful Links SureCookie Website Documentation Support Forum Privacy Policy Live Demo About Brainstorm Force SureCookie is built by Brainstorm Force, the team behind Astra and other widely used WordPress products.