Website Privacy and Consent Compliance: A Guide for Operators
7 min
website privacy and consent compliance a guide for operators this guide is for storage operators using the storagely platform it covers what website privacy and cookie consent compliance involves, who is responsible for what, and the steps to get a compliant setup in place this is general information based on storagely's practical experience helping other operators, not legal advice storagely does not recommend legal counsel or third party compliance audits, and we do not represent operators on the legal merits of any complaint if you are responding to an actual complaint or demand letter, your own legal counsel is best positioned to advise on next steps why this matters a growing number of state laws govern how websites collect, use, and share visitor data the two most relevant for us based operators are cipa (california invasion of privacy act) originally a wiretap statute, cipa has become the basis for a wave of lawsuits and demand letters against businesses whose websites send visitor data, such as chat messages, form entries, or search activity, to third party tools before the visitor has consented filings have grown sharply in recent years, and current cases increasingly focus on timing whether tracking scripts fire before a visitor makes a consent choice, not just whether a consent banner exists at all ccpa/cpra (california consumer privacy act / california privacy rights act) this is an opt out model rather than opt in it requires transparency about what data is collected, an accessible way to opt out of the sale or sharing of personal information, and support for browser level opt out signals such as global privacy control (gpc) several other states, including virginia, colorado, texas, utah, florida, and connecticut, have their own comprehensive privacy laws with broadly similar themes transparency, opt out rights, and honoring universal opt out signals if your locations operate outside california, it is worth checking whether any of these apply to you who is responsible for what the operator (you) owns privacy policy content and keeping it current the decision to enable a consent banner and how it behaves (what counts as essential vs nonessential tracking) disclosing which third party technologies your site uses (analytics, advertising, chat, heatmaps, embeds, etc ) selecting and managing a consent management platform (cmp) account, if you choose to use one legal compliance determinations for your business and locations storagely owns building and hosting the site implementing the technical pieces you provide, such as embedding a cmp script or adding a footer link to consent preferences general platform security and uptime this split is standard across our service agreements clients are responsible for compliance with third party terms tied to the software, apis, and integrations they choose to use on their site storagely is not a compliance or legal service think of us as the contractor who wires in what you decide to install, not the one who decides what code applies the shopify / wix comparison the easiest way to think about this storagely supplies the platform, the same way shopify or wix supplies a platform to the businesses that build on it a platform provider does not control every third party tag a business adds for its own marketing and tracking, things like google ads, google analytics, a heatmap tool, or a form embed routed through a tag manager keeping those aligned with privacy requirements is the business owner's responsibility, not the platform's it is the same model that applies to website accessibility (ada) compliance storagely cannot control what an operator adds or changes on their own site, so compliance sits with the operator, regardless of which platform the site runs on two buckets of scripts, one important distinction it helps to separate what is running on your site into two categories tools you or your marketing team added for your own purposes (google ads, google analytics, microsoft clarity, hubspot forms, other tag manager tags) these are squarely your responsibility to disclose and gate behind consent platform level protective scripts (for example, recaptcha or other spam and fraud protection) storagely can disable these on request, but doing so removes that protection from your site, so it is not the first move routing these through a consent tool, or working with us to scope out a narrower fix, is generally the better path what storagely can and can't do storagely can disable specific scripts on request, including things like security captchas, understanding that this can leave the site more exposed (for example, to spam or fraud), so it should not be the first response to a complaint complete some of the cmp setup on your behalf once you have an account, such as embedding a script or adding a footer link storagely does not own or manage your privacy and consent compliance control third party marketing and tracking tags that you or your marketing team add provide legal advice, recommend legal counsel, or run third party compliance audits on your behalf indemnify operators for privacy or accessibility compliance issues what typically needs to be disclosed and gated behind consent most cipa and cookie consent reviews focus on nonessential technologies that collect or transmit visitor data common examples analytics (google analytics, ga4, google tag manager) advertising and remarketing (google ads conversion tracking, conversion linker, remarketing pixels, meta pixel) heatmaps and session recording (hotjar, microsoft clarity, and similar tools) chat and ai assistants (swivl chat, other live chat widgets) embedded maps and video (google maps, youtube embeds) review and reputation tools (birdeye and similar) any other third party analytics, marketing, or tracking technology active on the site search, contact forms, and reservation or rental forms are typically treated as essential, but the data they submit may still need disclosure in your privacy policy depending on where it is sent setting up a compliant consent flow audit what is running on your site list every analytics, advertising, chat, and tracking tool currently active, including anything added outside the standard storagely template choose a consent management platform a cmp scans your site for cookies and trackers, classifies them, generates policy language, and powers the consent banner we recommend termly it is the cmp we have seen operators get running fastest with the least back and forth, and we are familiar with its setup you are not required to use it other reputable options include cookiebot, osano, cookieyes, clym, usercentrics, and onetrust whatever you choose, confirm it supports blocking scripts until consent is given, not just displaying a banner alternative manage it manually if you would rather not use a cmp, you can write and maintain your own privacy policy and consent banner copy, either placing it on the site yourself or sending us the copy to publish on your behalf this works, but it is more labor intensive and depends on you tracking every technology on your site and every relevant law yourself regulations and requirements change often, and a manual policy will not automatically adjust to those changes the way a cmp does this is the main reason we point operators toward a cmp it keeps your cookie classifications and policy language current with far less ongoing effort on your part configure the banner correctly current best practice, and increasingly a legal requirement, is that accept all and reject all must be equally easy to select a prominent accept button paired with a small or hidden reject option is considered a dark pattern and is a common basis for claims make sure nonessential scripts do not fire until the visitor makes a choice support opt out signals if gpc or similar browser signals are enabled, your cmp should recognize and honor them automatically update your privacy policy it should name the categories of technology in use, ideally the specific vendors, how visitor data is collected and shared, and how visitors can exercise their rights send us what needs to be embedded once your cmp account and policy language are ready, send the script or snippet to your storagely contact and we will handle the technical implementation on your site test it load the site in an incognito window and confirm nothing nonessential fires before you interact with the banner, then confirm reject all actually stops those scripts if you receive a cipa notice or demand letter if you get a demand letter or complaint alleging your site tracked a visitor before they consented, a few things are worth knowing before you react this is not a sign anything is broken with your site these notices have become a common, high volume trend aimed at business websites across the country, especially in california, and are frequently sent in bulk by senders looking for a quick settlement rather than pursuing a real claim getting one does not mean your site is uniquely at fault the responsibility split above still applies the scripts named in these letters are almost always third party marketing and tracking tools added for the operator's own purposes (google ads, google analytics, microsoft clarity, hubspot forms, and similar), so addressing them is on the operator side, the same as it would be on any platform the fastest path forward is a cmp like termly in our experience, operators who promptly put a consent solution in place have generally seen these complaints go away, since senders are often looking for money without much effort on their part this is practical experience from helping other customers, not legal advice, so if you are dealing with an actual complaint, your own legal counsel should guide how you respond to it disabling scripts is a last resort, not a first step storagely can turn off flagged scripts on request, including things like spam and fraud protection, but that trades away real protection for your site getting a cmp in place first is almost always the better move faq do we have to use termly? no use whichever cmp fits your business, as long as it can classify your trackers, generate policy language, and gate nonessential scripts behind consent termly is just the one we have the most experience implementing do we have to use a cmp at all? no you can write your own privacy policy and consent banner copy and either place it on the site yourself or send us the copy to publish for you it is a valid path, just more labor intensive, and it will not keep itself current as laws and requirements change the way a cmp does that gap is why we generally recommend a cmp as the lower effort, more durable option will storagely tell us how to classify our cookies or write our policy? that is a decision for you and your cmp vendor to make, since it depends on the specific technologies running on your site depending on availability, our team may be able to offer informal pointers, but we do not own that determination, do not provide legal advice, and cannot guarantee accuracy for your specific situation we received a demand letter or complaint about our site what should we do? see "if you receive a cipa notice or demand letter" above short version it is common, it is not a sign your site is broken, and putting a cmp like termly in place is usually the fastest path to resolving it we can't advise on the legal merits of a specific complaint, so loop in your own counsel for that piece will storagely disable a flagged script for us if we get a complaint? we can, on request, but it should not be the first move since it removes whatever protection that script was providing (for example, spam or fraud protection on a captcha) getting a cmp in place first is generally the better fix what do we send to storagely to get this live? your cmp embed script or snippet, and any footer link text you want added (for example, a "consent preferences" link) once we have that, implementation is typically quick who do we contact for help? reach out to your storagely account contact with your cmp details and any specific requests, such as footer link placement or banner styling questions as always, if you have any questions during this process, our customer success team is here to help the best way to reach us is by submitting a support ticket submit a ticket https //d1s7s share hsforms com/297gkkisitsmdgskuyt9s2g
Have a question?
Our super-smart AI, knowledgeable support team and an awesome community will get you an answer in a flash.
To ask a question or participate in discussions, you'll need to authenticate first.