Home Installation Guide

Installation Guide

CookieLet
By CookieLet
2 articles

Getting started with CookieLet: from Sign-up to a Live Cookie Banner

This guide walks you through the complete CookieLet setup — creating your account, adding your website, running your first cookie scan, designing your consent banner, and installing it on your site. Time required: about 10 minutes You will need: your website URL and the ability to edit your site's <head> (directly, or through Google Tag Manager) Step 1 — Create your account Go to cookielet.com and select Sign up. Fill in the four fields: - Full name — your name - Business name — your company or organisation name - Work email — the address you want account and billing notices sent to - Password — at least 8 characters Tick I agree to the Terms and Privacy Policy, then select Create account. Note: No credit card is required to create an account. You choose a plan later, per website, and the Free plan requires no payment at all. Step 2 — Verify your email address As soon as your account is created, you are taken to your dashboard, with an Email Verification Required notice at the top. Check your inbox for an email from CookieLet with the subject "Confirm your email to complete your setup." Select Verify My Email. If the button doesn't work, copy the fallback link from the email and paste it into your browser's address bar. Didn't get the email? 1. Check your spam, junk and promotions folders. 2. Select Resend Verification Email in the dashboard notice. 3. If it still doesn't arrive, contact support@cookielet.com and we'll verify the account manually. Step 3 — Open your dashboard Once verified, the notice disappears and your dashboard is ready. The left sidebar holds everything you'll use from here: - My Dashboard — overview of the currently selected website - Analytics — consent rates, opt-in/opt-out breakdowns and traffic insights - Cookie Banner — design and behaviour of your consent banner - Cookie Manager — every cookie found by the scanner, and its category - Consent Log — auditable record of each consent decision - Languages — banner translations - Policy Generators — cookie policy and privacy policy generators - Advanced — script blocking, Google Consent Mode, TCF and GPP settings Menu items stay greyed out until you add your first website. Select Add Website to continue. Step 4 — Add your website and choose a plan Complete the dialog: 1. Workspace Selection — choose the workspace this site belongs to. If this is your first site, leave the default. 2. Website URL — enter the full URL including https://, for example https://www.example.com. Enter the domain the banner will actually run on. 3. Website Name — a label for your own reference, such as "Acme Retail — Main Site". 4. Pricing Plan — switch between Monthly and Annual billing, then select a plan. The plans available are: - Free — 5,000 pageviews per month, cookie scanner covering 100 pages, manual scans - Starter — 150,000+ pageviews per month, 1,000 pages per scan, monthly auto-scans - Pro — 700,000+ pageviews per month, 6,000 pages per scan, weekly auto-scans - Premium — unlimited pageviews, 10,000 pages per scan, 30 languages with auto-translation Select Compare Plans for the full feature matrix, then Next when you're done. Important: Plans are assigned per website, not per account. If you manage several domains, each one carries its own plan. If you chose the Free plan, skip ahead to Step 6 — Your first cookie scan. Step 5 — Complete checkout (paid plans only) Paid plans are processed by FastSpring, our authorised reseller. You'll be redirected to a secure checkout window. Enter your email, name, payment method and billing address, then select Pay. Card, PayPal and Google Pay are supported. About the amount shown: the checkout total is displayed in your local currency and may include VAT or sales tax, so it can differ from the USD price shown on the plan card. After you pay, CookieLet provisions your subscription. Don't refresh the page or use your browser's back button while this screen is showing. Step 6 — Your first cookie scan CookieLet now crawls your site and identifies every cookie and tracker it sets, then sorts them into categories — Necessary, Functional, Analytics, Advertisement and Personalisation. The scan usually takes a few seconds to a few minutes, depending on the size of your site and your plan's page limit. You can review and re-categorise everything it found later, under Cookie Manager. Step 7 — Configure your consent banner Next, design the banner your visitors will see. The live preview on the right updates as you change each setting. Banner Language Select the language your banner text should appear in. Additional languages and automatic translation can be added later from the Languages menu, subject to your plan. Legislation Preset Select the regulation your banner should follow. This determines whether the banner uses an opt-in or opt-out consent model, and which buttons appear. - GDPR — EU & UK. Use when your visitors are mainly in the EU/EEA and the UK. Opt-in: nothing non-essential loads until the visitor accepts. - US State Laws — United States. Use when your visitors are mainly in the US. Opt-out: visitors can decline the sale or sharing of their data. - GDPR & US State Laws — Worldwide. Use when you have international traffic. Geo-targeted: each visitor sees the banner required in their region. Recommended: if you're unsure, choose GDPR & US State Laws — Worldwide. It applies the strictest rule that fits each visitor's location. Banner Layout - Banner — full-width bar across the top or bottom of the page - Box — centred dialog with a background overlay - Popup — compact card in a corner of the page Position Choose Bottom, Center, Bottom Left or Bottom Right. Available positions depend on the layout you selected. Banner Colors Choose Light or Dark to match your site. Full colour customisation is available afterwards from Cookie Banner in the sidebar. Select Next when the preview looks right. Step 8 — Banner build CookieLet compiles your banner and publishes it to our CDN. This takes a moment. Stay on the page until it completes. Step 9 — Install your CookieLet code This is the only step that touches your website. 1. Copy the code snippet Select Copy Code. Your snippet looks like this, with your own site ID in the URL: <script src="https://cdn.cookielet.com/YOUR-WORKSPACE-ID/YOUR-SITE-ID/consent.js" async ></script> Don't share this snippet publicly and don't reuse it on another domain. It's unique to this website, and every consent record it produces is attributed to it. Each additional site needs its own snippet. 2. Paste it into your head tag Paste the snippet immediately after the opening <head> tag, before any analytics, advertising or marketing tags. Why placement matters: CookieLet blocks tracking scripts until the visitor gives consent. If another tag loads before CookieLet, it can set cookies before consent has been recorded — which is exactly what the banner exists to prevent. Choose the method that matches your site. HTML or custom-built site Open your site template and paste the snippet directly after <head>. If your site has multiple templates, add it to every one — or to the shared header include. Google Tag Manager 1. In GTM, go to Tags → New → Custom HTML. 2. Paste the snippet. 3. Tick Support document.write. 4. Set the trigger to Consent Initialization – All Pages. This ensures CookieLet fires before every other tag. 5. Save, then Submit to publish the container. 3. Verify and activate Open your website in a new browser tab and confirm the banner appears. Use a private or incognito window, since your browser may already hold a consent decision. Return to CookieLet and select Verify Installation. When verification succeeds, your banner is live, CookieLet begins recording consent, and you will be taken back to your Dashboard What to do next - Review and re-categorise the cookies found by the scan — Cookie Manager - Go to Cookie Manager in your dashboard and initiate a full scan. - Customise banner text, colours and buttons — Cookie Banner - Add more languages — Languages - Generate a cookie policy or privacy policy — Policy Generators - Turn on Google Consent Mode v2, IAB TCF or GPC - Check consent rates and opt-in performance — Analytics - Export your auditable consent records — Consent Log Troubleshooting The banner doesn't appear on my site - Confirm the snippet is in the <head> of the page you're testing, not the <body>. - Test in a private or incognito window — you may have already accepted or declined. - Check that the domain you added in CookieLet exactly matches the domain you're testing, including www or its absence. - Clear your site's cache and CDN cache after adding the snippet. Verify Installation fails - Allow a minute after publishing, then try again. - If your site is behind a firewall, password wall or "coming soon" page, our verifier can't reach it. Make the page publicly reachable and retry. - Confirm the snippet wasn't stripped by a security or optimisation plugin. The scan found fewer cookies than expected - Cookies set only after login, or only on specific pages, may fall outside the crawl. Check your plan's page-per-scan limit. - Re-run the scan from Cookie Manager after making changes to your site. I added the wrong website URL Contact support@cookielet.com with your account email and the correct URL, and we'll update it for you. I chose the wrong plan You can change a website's plan anytime from Manage Plans under Organisation & Sites. Upgrades and Downgrades take effect immediately. Still need help? Email support@cookielet.com or use the Support option in your dashboard sidebar. Include your account email and the website URL you're working on so we can help faster.

Last updated on Sep 11, 2026

Install CookieLet with Google Tag Manager.

Google Tag Manager (GTM) is the easiest way to install CookieLet if you already manage your marketing and analytics tags there. Instead of editing your site's code, you add the CookieLet tag to your container once, and GTM loads it on every page. This guide covers the full setup: creating your container, adding the CookieLet template, configuring your default consent state, and verifying the banner is live. Time required: about 15 minutes You will need: a Google Tag Manager account with publish rights, and a website already added in your CookieLet dashboard Already installed CookieLet with the direct code snippet? Use one method or the other, never both. Two installations means two banners and duplicated consent records. Remove the snippet from your site before adding the GTM tag. How it works The CookieLet tag does three things on every page load: it tells Google's tags that consent has not been given yet, it loads your consent banner, and it passes the visitor's decision back to GTM so your other tags know whether they're allowed to fire. Because of that ordering, the CookieLet tag must always use the Consent Initialization – All Pages trigger. It's the only trigger GTM guarantees to run before everything else in the container. Step 1 — Create your GTM container Skip this step if GTM is already installed on your site. 1. Go to tagmanager.google.com and sign in. 2. Select Create Account. Enter your account name, country, and your website's domain as the container name. 3. Choose Web as the target platform and select Create. 4. GTM shows you two code snippets. Copy the first and paste it as high as possible inside the <head> of every page. Copy the second and paste it immediately after the opening <body> tag. 5. Save and publish your site changes, then select OK in GTM. Placement matters. If the GTM snippet sits below your analytics or advertising tags, those tags load before CookieLet can block them — and cookies get set before the visitor has consented. Step 2 — Find your Website ID and Account ID In your CookieLet dashboard, open the installation screen for your website and select the Install with GTM tab. Both IDs are listed there. Copy both values somewhere handy — you'll paste them into GTM in Step 4. Keep this tab open; you'll come back to it at the end to verify. Note on naming: CookieLet calls it your Website ID. The GTM template calls the same value Site Id. They are the same thing. Step 3 — Add the CookieLet template to your container CookieLet provides a ready-made GTM tag template, so you never have to paste custom HTML into your container. Option A — from the Community Template Gallery 1. In GTM, go to Tags → New and select Tag Configuration. 2. Select Discover more tag types in the Community Template Gallery. 3. Search for cookielet and select the Cookielet CMP template. 4. Select Add to workspace, review the permissions it requests, and select Add. Option B — import the template file Contact support@cookielet.com for the template file. It has a .tpl extension. 1. In GTM, open Templates from the left-hand menu. 2. In the Tag Templates section, select New. 3. Open the three-dot menu in the top right of the template editor and select Import. 4. Choose the .tpl file you were sent. 5. Select Save, then close the editor. Either way, the template now appears as Cookielet CMP in your container's tag type list. You add the template once per container. If you manage several GTM containers, repeat this step in each one. Step 4 — Create and configure the CookieLet tag 1. Go to Tags → New. 2. Select Tag Configuration and choose Cookielet CMP. Site Id and Account Id Paste your Website ID from Step 2 into the Site Id field, and your Account ID into the Account Id field. Both are required — the tag won't save without them. Double-check you haven't swapped them. If the two IDs are reversed, the tag fires successfully in GTM but the banner never loads. Default Consent Settings This is the consent state applied before the visitor has made a choice. Expand Default Consent Settings and select Add Row. Set the row like this: - Analytics Cookies — Disabled - Advertisement Cookies — Disabled - Functional Cookies — Disabled - Security Cookies — Enabled - Share user data with Google — Disabled - Use data for ads personalization — Disabled - Regions — All Select Add to save the row. Security is the only category that stays enabled, because it covers cookies your site needs to function and protect itself. Everything else is switched on only after the visitor accepts. Why set this explicitly? The template applies a denied-by-default state on its own if you leave the table empty, but adding the row makes your consent configuration visible to anyone auditing the container — and it's the row you'll copy when you add region-specific defaults. Region-specific defaults (optional) Keep the All row as your global fallback, then add extra rows for specific regions. Enter comma-separated country or region codes in the Regions column, for example GB, DE, FR or US-CA for California alone. A row with specific region codes applies only to visitors in those regions. The All row covers everyone else. Other Settings Expand Other Settings to reach these three options: - Wait For Time — how long, in milliseconds, Google's tags pause while waiting for a consent decision. The default of 2000 suits most sites. Raise it if your banner is slow to appear; lower it if you're losing analytics data from visitors who leave quickly. - Ads Data Redaction — recommended on. While advertising consent is denied, Google's ad tags strip advertising identifiers from requests and route traffic through cookieless domains. - URL Pass Through — optional. Preserves click identifiers such as gclid across pages when cookies are denied, so conversions are still attributed. Turn it on if you run Google Ads. CDN Host Leave this at https://cdn.cookielet.com. Only change it if CookieLet support gives you a different host. Triggering Select the Triggering section and choose Consent Initialization – All Pages. Don't use All Pages. The ordinary All Pages trigger fires alongside your other tags, not before them, which defeats the purpose of the consent banner. Give the tag a clear name, such as CookieLet CMP — Consent Init, and select Save. Step 5 — Make your other tags respect consent Google tags — GA4, Google Ads, Floodlight — read the consent state automatically once CookieLet sets it. Non-Google tags need to be told. For each third-party tag in your container (Meta Pixel, LinkedIn Insight, TikTok Pixel, Hotjar and similar): 1. Open the tag and expand Advanced Settings → Consent Settings. 2. Select Require additional consent for tag to fire. 3. Add the consent type the tag depends on — usually ad_storage for advertising tags and analytics_storage for analytics tags. The tag will now wait until the visitor grants that consent type. Step 6 — Preview and test 1. Select Preview in the top right of GTM and enter your website URL. 2. Tag Assistant opens your site in a new window. Confirm the CookieLet banner appears. 3. In Tag Assistant, open the Consent tab and check the On-page Default column. Every type except security_storage should read denied. 4. Accept cookies on the banner, then check the On-page Update column. The types you consented to should switch to granted. 5. Confirm your analytics and advertising tags only fire after that update. Step 7 — Submit and publish Close Preview, select Submit in GTM, give the version a name such as Added CookieLet consent banner, and select Publish. Nothing you configured is live on your website until you publish the container. Step 8 — Verify in CookieLet Return to the CookieLet installation screen and select Verify Installation. CookieLet checks your live site for the banner and activates consent recording. Once verification succeeds, open Consent Log in your dashboard to confirm decisions are being recorded. Troubleshooting The banner doesn't appear on my site - Confirm you published the container — saving the tag is not enough. - Check the GTM container snippet itself is on the page you're testing. - Re-check the Site Id and Account Id for typos or a swap. - Test in a private or incognito window; you may already have a stored consent decision. - Clear your site's cache and CDN cache. Two banners appear CookieLet is installed twice — usually the direct snippet is still in your site's <head> alongside the GTM tag. Remove the snippet and keep the GTM tag. Tags are firing before the visitor consents - Check the CookieLet tag is on the Consent Initialization – All Pages trigger, not All Pages. - Check the GTM container snippet is at the very top of your <head>. - For non-Google tags, confirm you added the additional consent checks described in Step 5. - Check no tag is hard-coded into your site outside GTM. Tags pasted directly into your theme aren't governed by your container. Verify Installation fails - Wait a minute after publishing and try again. - If your site is behind a password wall, staging login or "coming soon" page, our verifier can't reach it. - Check the GTM container is published to the live environment, not only to a preview or a custom workspace. Analytics data dropped after installing That's expected, and it's the point: visitors who decline are no longer tracked. If the drop is larger than expected, check that Wait For Time isn't too short, and consider turning on URL Pass Through so ad clicks are still attributed. Still need help? Email support@cookielet.com with your website URL and your GTM container ID (it starts with GTM-), and we'll check the configuration for you.

Last updated on Sep 14, 2026