Answer a few questions and get a ready-to-use privacy policy and terms of service — required by Google, Apple and the law. Copy or download, no sign-up.
Templates for general guidance, not legal advice. Review before publishing.
The banner obtains consent. The policy explains what you are asking consent for. You need both, and one does not substitute for the other — a beautifully written cookie policy on a site that drops analytics before anyone clicks is still a breach.
For each cookie or category you should give:
This is where most cookie policies fail. They are written once, then the site gains a chat widget, a heatmap, an embedded video and a new ads pixel — each setting cookies the policy never mentions.
Check what your site actually sets. Open it in a private window, go to Application → Cookies in your browser’s developer tools, and compare the real list against your policy. Most people find several they cannot account for.
Embedded content is the usual culprit. A YouTube video, a Google Map or a social feed can each set third-party cookies on page load. If they load before consent, that is the same problem as an analytics tag firing early.
Give the policy a last-updated date and review it whenever you add anything to the site that touches visitor data. A cookie policy that no longer matches the site is evidence of a problem rather than protection against one.
The banner collects consent; the policy explains what the cookies are and what they do. You need both.
For each cookie or category: its name or category, what it does in plain language, whether it is first or third party, how long it lasts, and whether it needs consent.
Open the site in a private window and check Application → Cookies in your browser's developer tools. Compare that list against your policy.
Frequently, yes. YouTube embeds, maps and social feeds can set third-party cookies on page load, which is a problem if they load before consent.