‌‌‌‌​​‌‌​‍‌​‌​‌‌‍‍‌​‍‌‌​​‌​​‌‌​‍ One script tag · Free tier · No sign-up

Cookie choices your visitors can see.

Candor provides equally prominent accept and reject buttons, category preferences, and controls for tagged scripts.

Candor consent banner
Features

Cookie choices with clear controls.

Real accept/reject parity

Visitors can accept or reject from the same screen, with both choices given equal prominence.

Per-category script blocking

Mark third-party scripts type="text/plain" data-candor="analytics" and Candor keeps them inert until that category is granted — so trackers genuinely don't run before consent, not just "after the fact".

Edge geo-detection

Candor reads Cloudflare's CF-IPCountry header at the edge — free, no third-party IP lookup, no extra latency — so you can prompt where consent is required and stay quiet where it isn't.

No dark patterns, by design

Optional categories start unselected. The necessary category is always on and clearly labelled, and button text describes each choice without shaming visitors.

Consent records

When enabled, the log stores a hashed identifier, category choices, country code, site, action, and timestamp. The consent record excludes names, email addresses, and raw IP addresses.

One script tag, any site

Pure HTML/CSS/JS in a Shadow-DOM bubble — zero dependencies, ~18 KB on the wire, no build step, no framework. Drop it on WordPress, a static site, Webflow, anything that renders a <script> tag.

How it works

Set up the banner and tag your scripts.

1

Drop in the script.

One <script> tag in your <head>, with optional data-* attributes for your site name, accent color, and policy link.

2

Tag your trackers.

Change type="text/javascript" to type="text/plain" data-candor="analytics" on any script that sets cookies. Candor holds them until consent.

3

The visitor chooses.

Accept all, reject all, or open preferences and pick categories. Their choice persists in a first-party cookie + localStorage — no re-prompting on every page.

4

Scripts activate on grant.

Candor swaps the inert tags to live ones the moment a category is allowed, and fires a candor:consent event your code can hook.

What's included

The essentials are free. Scale and records are paid.

Free includes the banner and category controls. A license adds geo-targeting, the consent log, and multi-site scale.

Consent banner
Free
Accept / reject parity
Free
Per-category blocking
Free
localStorage + cookie
Free
Bar + box layouts
Free
Custom theming
Free
Geo-targeting
Paid
Consent log + export
Paid
Google Consent Mode
Paid
Template library
Paid
Multi-site license
Paid
Priority support
Paid
Pricing

Free banner controls. Licensed options for records and multiple sites.

Monthly Annual Save 15%
Free
Free
Banner and category controls for one site
$0forever
No credit card
  • Consent banner (bar + box)
  • Accept / reject parity
  • Per-category script blocking
  • Custom theme + policy link
  • Geo-targeting (locked)
  • Consent log (locked)
Get Free
Agency
Agency
For studios managing many sites
$39.95/month
billed monthly
$39.95/mo$33.95/month
$407.40 billed annually
  • Everything in Single
  • 10 domains + subdomains
  • Per-domain consent logs
  • CSV consent export
  • Email support
  • Priority support
Unlimited
Unlimited
For high-volume studios & enterprises
$99/month
billed monthly
$99/mo$84.15/month
$1,009.80 billed annually
  • Everything in Agency
  • Unlimited domains
  • Priority support (<24hr)
  • White-glove onboarding
  • Early access to new plugins
  • Volume pricing on full Suite
FAQ

Questions

Is Candor actually GDPR/CCPA compliant?

Candor provides accept and reject buttons, unselected optional categories, controls for tagged scripts, and consent records when enabled. Installing the banner alone does not establish compliance; review your site's scripts, configuration, and disclosures against the requirements that apply to it.

How does script blocking actually work?

You change a tracker's tag from type="text/javascript" to type="text/plain" data-candor="analytics". The browser won't execute a text/plain script, so it stays inert. When the visitor grants that category, Candor swaps it for a live <script> and it runs — not before. That's what "prior consent" means in practice.

Does the free tier expire?

No. The free tier includes parity buttons, per-category blocking, theming, and persisted choice. You only need a license for geo-targeting, the server-side consent log, Google Consent Mode, and multi-site use.

What does the consent log store?

When logging is enabled, each consent record contains a hash derived from the IP address, User-Agent, and day, plus category choices, country code, site, action, and timestamp. The record does not contain the raw IP, name, email, or page content. Records are configured to expire after 400 days. The identifier is pseudonymous; review retention and access as part of your privacy practices.

Will it slow my site down?

It's pure vanilla JS in a Shadow DOM, ~18 KB, zero dependencies, served from Cloudflare's edge. Geo-detection uses a request header that's already there — no blocking third-party IP lookup. The banner renders before paint so there's no flash of un-consented trackers.

Can I use one license on multiple sites?

Depends on the plan: Single = 1 domain, Agency = 10, Unlimited = unlimited. Domains bind automatically the first time the widget verifies. Need to move a site? Contact us to unbind a slot.

Get started

Give visitors clear cookie choices.

Add Candor to a site, configure the categories, and check how accept and reject affect your tagged scripts.