Built from your site
Written from what your site actually loads.
Most generators ask you to list your tools from memory, and the list goes stale the day you add a tag. ConsentStack starts from what it detects: your privacy policy names each analytics, advertising and security service, your cookie policy lists the cookies they set, and both keep up as your tools change.
Detected, not remembered
With the banner installed, ConsentStack keeps track of the tools your pages load. Before that, a free compliance scan of your domain fills the same list.
Named with its provider
Each service is listed with its provider and purpose, with links to its privacy policy and opt-out page where the provider publishes them.
You add the rest
Payment processors, email platforms and CRMs never load in a browser. Add what they collect and who receives it, and your policy covers them too.
Privacy laws
The laws are worked out for you.
Answer a short business profile once: where you operate, whose information you collect and how big you are. ConsentStack works out which laws apply, down to each US state's thresholds, and your privacy policy lists the rights each one gives your visitors.
Publishing
Publish once. Link it everywhere.
Paste one snippet on each policy page. Every time you publish, that page shows the new version, with nothing to paste again.
Embed it anywhere
A Squarespace code block, a WordPress HTML block, a Webflow embed or any page that takes HTML. It works whether or not the ConsentStack banner is on the page.
Hosted for you
No policy page yet? Every published policy also has its own address on policies.consentstack.io, ready to link.
Every version kept
Each publish gets a permanent, dated address. Older versions say when they were replaced, so you can show what your policy said on any date.
Your banner links to it
Insert the policy link in your banner text once. From then on it points at your published policy, wherever it lives.
The full set
One profile, every policy.
Privacy policy, cookie policy, terms of service, disclaimer and accessibility statement are all built from the same business profile, so you answer each question once.
The Policy Generator writes your policies from your answers and what it detects on your site. It isn't legal advice, so have a lawyer review the result if you need certainty for your business.
Common questions
Yes. It's included on every ConsentStack plan, including the free Basic plan. On Basic, your policy ends with a short line crediting ConsentStack. On Pro and above you can remove it.
No. The Policy Generator writes your policy from your answers and from what it detects on your site. It isn't legal advice, so have a lawyer review the result if you need certainty for your business.
No. The embed works on any page, with or without the banner. Without the banner, ConsentStack fills in your services from a compliance scan of your site's domain, so run a free scan first and add your site with the same domain. With the banner, ConsentStack keeps track of the tools your pages load, and once you add the policy link to your banner text, it follows your published policy.
Payment processors, email platforms, CRMs and other tools you use behind the scenes never load in your visitors' browsers, so neither the banner nor a scan can see them. Add what they collect and who you share it with in the questionnaire. When you start your policy, everything ConsentStack has detected comes pre-filled, with the services it came from named next to each item.
Your business profile asks where you do business and whose information you collect: the EU and EEA, the United Kingdom, Canada (including Quebec), Australia and the US states with their own privacy laws. ConsentStack works out which of those laws apply to you, including whether you meet each state's thresholds, and your policy lists each right, who it applies to and how quickly you respond. If your banner honors Global Privacy Control, the opt-out signal some browsers send, your policy says that too.
Yes. Once an hour, ConsentStack checks every published policy against the tools it finds on your site. A new tool in a category your policy already covers, a tool that's gone (once it's been missing for 48 hours), and updated provider details or cookie durations publish on their own, each as a new dated version. Anything that changes what your policy promises, such as your first advertising tool or a tool ConsentStack's catalog lists as selling or sharing personal information, waits for your review and changes nothing live until you apply it. Workspace owners and admins get a daily email listing what published automatically and what's waiting for review. This covers your Privacy Policy and Cookie Policy.
Yes. Every publish gets its own permanent address, and the versions list shows each one with its date and the reason it was published. An older version opens with a notice saying when it was published and when it was replaced.
Yes. Link your own policy from the banner text like any other link. Everything else in ConsentStack works the same either way.
Each site gets its own business profile and its own policies, because different businesses collect different information and use different tools. The generator is part of every plan, the free one included, so it adds nothing to what a client site costs.
100+ happy customers
See what your policies should say.
Answer a short profile, check what ConsentStack found on your site, and publish. Free on every plan.