> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sellauth.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cookie Consent

> Ask storefront visitors before analytics, marketing and chat scripts run, with a banner that follows GDPR, UK PECR and CCPA expectations.

The cookie consent banner asks visitors for permission before non-essential cookies are set on your storefront. It gates the integrations you configured (Google Analytics, Google Tag Manager, Meta Pixel, Crisp, tawk.to), the affiliate referral code and the campaign attribution SellAuth records on invoices, and it records the visitor's choice so they are not asked on every visit.

It is managed under [**Legal & Privacy > Cookie Banner**](https://dash.sellauth.com/shop/legal#cookie-consent).

<Warning>
  SellAuth provides the mechanics: blocking scripts until consent, a reject button that is as easy as accept, per-category preferences, a stored consent record and a way to withdraw. Whether you need the banner at all, in which mode, and what your cookie policy must say depends on where you and your buyers are. Have a professional review your setup.
</Warning>

## Who has it on

Shops created after the banner shipped have it on from the start. Shops that existed before keep their current behaviour until you switch it on, because turning it on changes what your visitors see and, in opt-in regions, delays your analytics until they accept.

## Consent modes

| Mode | What happens |
| - | - |
| **Automatic by region** (default) | Visitors whose browser time zone is in an EU or EEA country, the United Kingdom or Switzerland get the opt-in behaviour. Everyone else gets the opt-out behaviour. No lookup request is made; when the browser reports no time zone the visitor is treated as opt-in. |
| **Opt-in everywhere** | Nothing non-essential runs until the visitor accepts. Reject is one click. |
| **Opt-out everywhere** | Scripts run immediately. The banner still offers Reject and Preferences, and a visitor who rejects has the cookies removed and the page reloaded without them. |

In every mode the banner honours the browser's **Global Privacy Control** signal: analytics and marketing are treated as declined unless the visitor explicitly accepts them afterwards.

## Categories

Visitors choose per category. Strictly necessary cookies cannot be switched off.

| Category | What it covers on a SellAuth storefront |
| - | - |
| Strictly necessary | Customer login, the cart, secure payment and fraud prevention (Stripe, PayPal and other providers), the maintenance mode bypass, the Discord sign-in flow and the consent record itself. Always on. |
| Functional | Live chat (Crisp, tawk.to). Language, currency and light or dark mode are stored only when the visitor picks them, so they are not gated. |
| Analytics | Google Analytics, and the UTM and referrer attribution SellAuth stores on invoices. SellAuth's own cookieless visit statistics do not store an identifier on the device and keep running. |
| Marketing | Meta Pixel, Google Tag Manager and the affiliate referral code. |

Google Analytics and Google Tag Manager receive Google Consent Mode v2 signals that match the visitor's choice.

## Turning it on

<Steps>
  <Step title="Update your theme">
    The banner is part of the official themes. If your theme shows an update available under [**Themes**](https://dash.sellauth.com/theme), update it first.
  </Step>

  <Step title="Publish a cookie policy">
    The banner links to your Cookie Policy, falling back to your Privacy Policy. The Cookie Policy starter template under [**Legal & Privacy**](https://dash.sellauth.com/shop/legal) lists every cookie a SellAuth storefront and checkout can set, grouped by the same categories as the banner. If you inserted the template before the banner existed, insert it again to pick up the full list.
  </Step>

  <Step title="Choose a mode and position">
    Automatic by region is the default. The banner can sit as a bottom bar, a card in either bottom corner, or a centered dialog.
  </Step>

  <Step title="Enable and save">
    Tick **Show the cookie banner** and save. A "Cookie settings" link is added to your storefront footer so visitors can change their mind later.
  </Step>
</Steps>

## Text and appearance

The title and message are translated into every storefront language by default. If you write your own, your text is shown to every visitor regardless of language. The banner takes its surface, text and accent colours from your theme, so it looks native on every official theme in light and dark mode; only the Accept button uses the accent colour, so Reject stays equally visible.

## Asking again

Visitors are remembered for 180 days by default (30 to 365). When you add a new tracking tool or change your cookie policy, use **Ask again** under **Legal & Privacy > Cookie Banner**. It bumps the policy version, discards every stored choice and shows the banner to everyone once more.

## Checkout

The checkout runs on your storefront domain and reads the same consent record. It only loads the analytics, marketing and chat integrations the visitor allowed. A visitor who lands on the checkout directly, without passing the storefront, gets the opt-out behaviour outside the opt-in regions and no non-essential scripts inside them, until they visit a storefront page and choose.

The [embedded checkout](/developers/embed) on your own website runs inside an iframe on a different site, so it cannot read the storefront's consent cookie and behaves like a direct visit. Your own site's banner governs your own page.

## Custom themes

A custom theme has to ship the banner itself. Three pieces are needed:

1. Render `snippets/cookie-consent.njk` in your layout before the theme script and before Alpine. Copy the snippet from any official theme.
2. Mark every non-essential script as inert until consent: `<script type="text/plain" data-consent="analytics">` (or `functional` / `marketing`). The runtime activates them when the category is allowed. The official `snippets/script-integrations.njk` shows this for each integration.
3. Offer a way to reopen the banner: any link to `#cookie-settings` or an element with `data-cookie-settings`.

The runtime exposes `window.saConsent` with `has('analytics')`, `onChange(callback)`, `open()`, `acceptAll()` and `rejectAll()`, and fires a `sa:consent` event on `document` whenever the choice changes. See [Theme Structure](/developers/theme-structure).

## Next steps

<CardGroup cols={2}>
  <Card title="Legal pages" icon="scale-balanced" href="/guides/legal-pages">
    Publish the cookie policy the banner links to.
  </Card>

  <Card title="Analytics" icon="chart-line" href="/guides/analytics">
    The figures SellAuth reports without any cookies.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.