Privacy & Compliance
Your Website Is Collecting Data Under Laws You Have Not Read
Analytics, pixels, chat widgets, and embedded tools collect visitor data from the moment a page loads. Consent, disclosure, and documentation are legal requirements in a growing list of states and countries. We set it up, keep it current, and keep it documented.
Why This Is Not Optional Anymore
The law count keeps climbing
GDPR and CCPA were the beginning. Sixteen-plus additional US state privacy laws are now in effect, each with its own thresholds and requirements. A policy written three years ago does not cover what is enforceable today.
Your tools are the exposure
Google Analytics, the Meta pixel, a chat widget, an embedded video, a heatmap tool. Each one collects something. Most sites cannot produce a list of what is running, which is the first question in any complaint.
Consent has to be provable
It is not enough to show a banner. You need a record of who consented to what and when, and a way for a visitor to change or withdraw it later. Without logs, you cannot demonstrate compliance if asked.
What Is Actually Covered
Websites
- Consent banner configured for the regions you actually operate in
- Consent preference center so visitors can change or withdraw consent
- Cookie scanning that identifies what is running on the site, including things nobody remembers installing
- Cookie policy generated from the scan and kept current
- Privacy policy, terms, and the supporting policy set
- Consent logging for demonstrable proof
- Cross-domain consent where subdomains are in play
Web & Mobile Apps
- App-specific privacy disclosures matching what the app actually collects
- Consent flows suited to app context rather than a web banner bolted on
- Policy coverage for account data, usage telemetry, billing, and third-party SDKs
- Documentation aligned with App Store and Google Play privacy requirements
Building for the app stores? Store privacy requirements are a submission blocker — see App Store Services.
Partner
Built on Termly, Managed by Us
We implement and manage compliance infrastructure through Termly, whose legal team monitors privacy legislation globally and pushes policy updates as laws change. Coverage spans GDPR, UK GDPR, PIPEDA, CCPA and CPRA, and additional US state laws — around thirty in total, with the list growing as legislation passes.
The platform does the monitoring. We do the part that actually determines whether it works: scanning your site, configuring the banner for your regions, mapping the tools you are running, connecting consent mode to your analytics and ad platforms, and keeping the whole thing accurate as your site changes.
Licensed through us
managed under our agency relationship, so you are not administering another vendor account
Configured for your site
a banner that blocks the right things before consent, which is where most self-installed setups fail
Kept current
policies update automatically as laws change; configuration gets reviewed as your site changes
Packages
Compliance License + Setup
$250 setup + $20/month
Licensing under our agency relationship. Self-managed after handoff.
Best for: a site that wants compliance configured correctly once, with a team comfortable maintaining it
Deliverables
- Full cookie scan of the site
- Consent banner configured for your regions
- Script categorization and blocking setup
- Privacy policy, cookie policy, and supporting policy set generated and embedded
- Consent logging enabled
- Policies update automatically as privacy laws change
- Weekly automated cookie scans
- Google Consent Mode v2 connected to your analytics and ad platforms
- Regional consent rules and multi-language banner support
Not Included
- Ongoing management (available below)
- Legal advice or legal review
- App-level compliance (scoped separately)
Managed Compliance
+$49/month
Add-on to Compliance License + Setup. We manage your instance end to end.
Best for: a business that wants compliance handled entirely, with nobody internal touching the platform
Deliverables
- Everything in Compliance License + Setup, plus:
- Weekly scan results reviewed and new scripts categorized
- Blocking configuration updated as your site changes
- Consent Mode health checks after tag and site changes
- New privacy laws reviewed for whether they apply to you
- Policies updated when your data practices change
- Consent logs archived with a periodic compliance summary
Not Included
- Legal advice or legal review
- Site rebuilds or new-property setups (quoted separately)
- App-level compliance (scoped separately)
App-level compliance is available for web and mobile apps and is scoped separately from website coverage.
Compliance That Stays Current
Privacy regulations change continuously across jurisdictions. This is protective infrastructure that keeps pace without you tracking legislation, rewriting policies, or wondering what your site is collecting.