This page explains what the product does. It is not legal advice. The built-in
banner texts and the default regions are a starting point: check them, and your
cookie and privacy policies, with your own counsel.
Turning it on
1
Pick how consent is collected
Go to Settings → Privacy & consent. Under Consent banner, set How
consent is collected:
2
Choose where to ask
Under Where to ask, switch regions on or off. Visitors are placed by the
country of their IP address.
Outside the regions you switch on, pages behave as if consent were off.
3
Add your policy links and save
Under Policy links, add your Cookie policy URL and Privacy policy
URL (a full
https:// address, or a path on your own domain such as
/privacy). They appear in the banner. Press Save.What is held until the visitor agrees
In a region where you ask for consent:- Ad pixels from your tracking integrations (Meta, Google Ads, TikTok, LinkedIn, Bing, Snapchat, Pinterest, Reddit, X, Outbrain) are sent to the page switched off and start only after the visitor accepts marketing.
- Google Analytics from your integrations waits for an analytics yes.
- Your custom tracking scripts (Pages → Tracking scripts) run as usual, because they are often needed for the page to work (affiliate link rewriting, for example). Switch on Also hold my custom tracking scripts under Before the visitor chooses to hold them for marketing consent too.
- Persistent identifiers. Until the visitor accepts analytics, ElasticFunnels sets no long-lived visitor cookie and uses no device id: your funnel reports still count the visit, tied to that one visit only.
A visitor who declines analytics is never tracked by the browser, whichever
option you pick. Orders are always recorded.
Holding a script of your own by hand
You can hold any script or pixel in your page HTML the same way. Write it withtype="text/plain", a data-ef-consent category and data-ef-src instead of
src:
marketing or analytics. When the visitor agrees, the element
is switched on in page order.
How the banner looks
Under Display style:
A blocking banner gets more choices made; the card and the bar interrupt less. In
every style, Reject all sits next to Accept all at the same size, and
Choose opens the category switches (necessary, analytics, marketing). The
blocking style keeps keyboard focus inside the card and ignores Escape until a
choice is made, and declining still lets the visitor into the page.
Button colour sets the colour of Accept all. Leave it empty to use your
brand colour, or near-black when there is none. The banner uses your page’s font.
Texts and languages
The banner has built-in texts in 38 languages: every official language of the EU and EEA, plus Turkish, Russian, Ukrainian, Arabic, Hebrew, Japanese, Korean, Chinese, Hindi, Indonesian, Thai and Vietnamese. It picks one per visitor:- the language of the page (its
<html lang>, or the language it is served in when you use translations); - otherwise, the visitor’s browser language;
- otherwise, English.
The built-in texts were machine-written and have not all been reviewed by native
speakers yet. Read them in the languages your visitors use.
Checkout email opt-in
Separate from cookie consent, Checkout email opt-in records whether a buyer agreed to receive marketing email from you. Switch on Show an email opt-in box on checkout pages to add an unticked box above the order button. Its text is under Banner text as Checkout email opt-in box text, per language. A checkout page that already has its ownallow_emails box keeps it.
SMS and email opt-in boxes on checkout and upsell pages
You can add your own opt-in boxes to a checkout page or an upsell page. In the page builder, drag the Customer Flag block (Checkout category) onto the page and pick SMS marketing or Email marketing in its settings; in the code editor, write the checkbox yourself:
A ticked box is stored on that order as a flag (
allow_sms or allow_emails). An unticked box stores
nothing. On an upsell page, the box is read when the buyer clicks the accept link ([UPSELL=...]),
for one-click and redirect upsells alike, and stored on the upsell order. A buyer who declines the
upsell is not recorded either way.
The flag records that the buyer ticked the box, not the words next to it. If you send SMS in the
US, keep a copy of the exact opt-in text each page used, with the date it went live, for your consent
records.
For developers: the window.ef.consent API
On pages where consent is on for the brand, window.ef.consent is available
from the <head> onwards.
required is true when the visitor is in a region where you ask. region is
one of eea, uk, ch, rest, unknown.
window.efConsent is the same object, kept for integrations written against it.
Use window.ef.consent in new code.Events
On every change, and once when the page loads with a choice the visitor made earlier, the page fires these events onwindow:
Each carries the same
detail:
source is banner for a click in our banner, api for window.ef.consent.set,
cmp for a choice read from your own consent tool, and stored for the choice
announced on page load.
Google Tag Manager
Every change (and the stored choice on page load) is also pushed todataLayer:
ef_consent_update, and two Data Layer Variables named
ef_consent.analytics and ef_consent.marketing. Then fire a tag only when, for
example, ef_consent.marketing equals true.
With Send Google Consent Mode signals on (the default), the page also sets
Google Consent Mode defaults (denied until the visitor chooses, in regions
where you ask) and sends an update after each choice, so Google tags you add
yourself follow it.
A “Cookie settings” link
Give visitors a way to change their mind. Any element withdata-ef-consent-open reopens the banner (for visitors in a region where you
ask, or who made a choice before):
Using your own consent tool
Set How consent is collected to My own consent tool. We show no banner, and pixels wait as described above until your tool reports a choice. Report it with:- Google Consent Mode: a
gtag('consent', 'update', ...)from your tool.analytics_storagesets analytics;ad_storage(withad_user_datanot denied) sets marketing. - IAB TCF v2: when your tool exposes
__tcfapi, marketing needs purposes 1, 3 and 4, and analytics needs purposes 1 and 8.