الأسئلة الشائعة
إجابات مختصرة عن أكثر ما يُسأل حول إدارة الموافقة مع Cookietrace.
ما هي Cookietrace؟
منصة لإدارة الموافقة على ملفات تعريف الارتباط وفق GDPR وePrivacy وأنظمة PDPL في السعودية والإمارات وكذلك KVKK وCCPA. يُركَّب سطر واحد خلال 3 دقائق تقريبًا، ويرسل إشارات Google Consent Mode v2، ويحفظ سجلات موقّعة أكثر من 3 سنوات.
كم يستغرق التركيب؟
نحو 3 دقائق: أضف سطر JavaScript واحدًا في ترويسة الصفحة أو عبر Google Tag Manager. لا حاجة لتعديل الشيفرة أو لمطور.
ماذا يحدث إذا رفض الزائر كل شيء؟
تُحذف ملفات تعريف الارتباط للفئات المرفوضة، ويُبلَّغ المزوّدون الذين يدعمون واجهات الموافقة بالإلغاء، وعند تفعيل حجب طلبات التتبع تُوقَف طلبات أدوات التتبع المعروفة داخل المتصفح.
كم التكلفة؟
Pro بسعر 39 دولارًا شهريًا (10 نطاقات) وPremium بسعر 79 دولارًا شهريًا (100 نطاق)، وEnterprise بسعر مخصص. التجربة 14 يومًا دون بطاقة ائتمان.
أين تُخزَّن البيانات؟
الاستضافة في الاتحاد الأوروبي افتراضيًا، مع خيار الاستضافة في تركيا. لا نقدّم استضافة داخل دول الخليج.
كيف تعمل Cookietrace
يُركَّب سطر برمجي واحد خلال 3 دقائق تقريبًا، مباشرة أو عبر Google Tag Manager. يفحص الموقع بحثًا عن ملفات تعريف الارتباط والبكسلات واستخدام التخزين، ويصنّف كل أداة تتبع، ويعرض لافتة الموافقة بلغة الزائر، ولا يسمح بتشغيل الوسوم غير الضرورية إلا بعد ذلك. تنبّهك عمليات الفحص العميق الدورية عند ظهور أداة تتبع جديدة.
- اكتشاف تلقائي لملفات تعريف الارتباط والبكسلات والبصمة الرقمية مع فحص مجدول.
- فئات دقيقة: ضرورية، وظيفية، تحليلية، تسويقية، اجتماعية.
- إشارات Google Consent Mode v2 وIAB TCF v2.2 جاهزة.
- حجب اختياري لطلبات أدوات التتبع المرفوضة داخل المتصفح.
- سجلات موافقة موقّعة ومختومة زمنيًا تُحفظ أكثر من 3 سنوات.
الأنظمة المشمولة
GDPR وePrivacy في الاتحاد الأوروبي والمملكة المتحدة، ونظام حماية البيانات الشخصية السعودي (PDPL بإشراف SDAIA)، وقانون حماية البيانات الاتحادي في الإمارات مع أطر DIFC وADGM، وKVKK في تركيا، وCCPA/CPRA في كاليفورنيا، إضافة إلى دعم الإفصاح وفق المادة 50 من قانون الذكاء الاصطناعي الأوروبي.
الباقات والأسعار
الأسعار شهرية بعملة USD وتعتمد على عدد النطاقات: Pro: $39 شهريًا · Premium: $79 شهريًا · Enterprise: سعر مخصص. تحتفظ كل الباقات بميزات الامتثال، والتجربة 14 يومًا دون بطاقة.
الشركة
Cookietrace by Ezeratech Digital (EZERA DIGITAL TECHNOLOGIES FZCO)، تأسست عام 2024. المكاتب: IFZA Business Park, Dubai Silicon Oasis, Dubai (AE) · İstanbul (TR) · London (GB). الواجهة والدعم بالعربية والإنجليزية والتركية والإسبانية والإيطالية. التواصل: [email protected] (المبيعات)، [email protected] (الدعم)، [email protected] (الخصوصية).
What is Cookietrace?
Cookietrace is an enterprise-grade Consent Management Platform (CMP) that keeps websites compliant with GDPR, KVKK, ePrivacy and CCPA. Built by Ezera Digital Technologies FZCO (Ezeratech Digital).
Who uses Cookietrace?
E-commerce sites, fintech, SaaS, agencies, telecom and SMBs. Suitable for any size of website that needs KVKK in Türkiye, GDPR in the EU, CCPA in the US.
How long does setup take?
3 minutes with a single-line script. No code changes or developer help required. Can also be added through a tag manager.
How many languages does Cookietrace support?
The banner UI ships in 8 languages: Turkish, English, German, French, Spanish, Italian, Dutch and Polish. Custom language additions are available from the Pro plan.
Which countries are covered?
Geo-targeting works worldwide. The banner shows the right regulation per country: KVKK for TR, GDPR for the EU, CCPA/CPRA for US states, LGPD for Brazil.
Is Cookietrace compliant with the KVKK Authority's 2022 Cookie Guide?
Yes, 100%. Disclosure for essential cookies, plain-language requirement, equal-prominence Accept/Reject buttons, separate consent for cross-border transfer — all articles are applied by default.
Is GDPR compliance not enough?
If you operate in Türkiye, GDPR alone is not enough. KVKK Art. 9 (cross-border transfer), the explicit consent definition and VERBİS obligations differ. Cookietrace is designed KVKK-native.
Does it comply with the ePrivacy Directive?
Yes. Per the EU ePrivacy Directive (Cookie Law), all non-essential cookies are blocked before consent. No pre-ticked checkboxes, no dark patterns.
Does Cookietrace block cookies before consent?
With Cookietrace's Prior Blocking setting enabled, non-essential cookies and trackers detected by the scan — whether loaded via GTM or embedded directly in the page — are not executed until the visitor makes a choice; if the visitor rejects, they never run, and if they accept, only the accepted categories load.
Does it support California (CCPA/CPRA)?
Yes. For US users, the 'Do Not Sell My Personal Information' link, opt-out management and Global Privacy Control (GPC) signal are automatically supported.
How are consent logs stored?
Each consent event is stored immutably with timestamp, IP hash, banner version and cryptographic hash. In an audit you can prove 'this user made this choice at this time'. Default retention is 3 years, extendable per plan.
Does it help with VERBİS registration?
Cookietrace automatically lists your cookie inventory and data processing activities — you can use this as a reference in your VERBİS registration. Cookietrace is a software solution and does not provide legal advisory services. For the legal aspects of VERBİS registration, please consult your own legal counsel.
Who is the data controller?
As the website owner, you are the data controller. Cookietrace acts as the data processor. A KVKK-compliant standard Data Processing Agreement (DPA) is included in all plans.
What is the script weight?
Under 15 KB (gzip). With edge-cached delivery and async-defer loading the impact on Core Web Vitals is negligible. Test sites show no measurable change in LCP/CLS.
Will it slow down my site?
No. The banner script, written with a modern stack, is non-blocking and loads async. There is no visible drop in your Lighthouse scores.
What is automated cookie discovery?
The Deep Scan engine crawls your site weekly, automatically finds and categorizes newly added cookies and trackers. No manual updates needed.
Does it support Single Page Applications (SPA)?
Yes. Fully compatible with React, Vue, Angular, Next.js and other SPA frameworks. Banner state persists across page transitions.
Does it work on AMP pages?
Yes, we offer an AMP-compatible banner version. Included from the Pro plan and above.
Is there a free plan?
There is no permanently free plan. Every plan starts with a 14-day trial that needs no credit card and includes the consent banner, tracker request blocking, audit logs, 8 languages, and Google Consent Mode v2.
What is the contract length?
Cancel monthly. We offer 20% off for annual billing but there is no long-term lock-in.
Is there an extra fee for multiple domains?
Pro includes 10 domains, Premium includes 100 domains and Enterprise is unlimited. Additional domains can be purchased modularly.
How is my data secured?
All traffic runs over HTTPS, consent data is stored encrypted. Stored consent records are immutable — cannot be modified. Regular backups and access logs are maintained.
Where is my data stored?
By default in an EU (Frankfurt) data center. Türkiye-based data residency is available on request — eliminating the KVKK Art. 9 cross-border transfer obligation.
What happens in case of a data breach?
Our DPA includes a reasonable-time notification obligation. We notify the data controller per KVKK Art. 12 and GDPR Art. 33. All security events are automatically logged.
Does it work with Google Tag Manager?
Yes, native GTM integration. Tags are automatically triggered or blocked based on consent state.
Does it support Google Consent Mode v2?
Yes, out-of-the-box. The Consent Mode v2 signals required for Google Ads and GA4 to function properly in the EU and TR are sent automatically.
Are there Shopify, WooCommerce, Wix integrations?
Yes, official one-click plugins/apps are available for all of them. There is also a universal script option that works with any CMS.
Does it work with the programmatic ad ecosystem?
Yes. The banner is compatible with Google Ads, Meta Ads and other major ad-tech platforms. Ad scripts are automatically triggered or blocked based on consent state.
Is there API and webhook access?
Yes, REST API and webhook access are included on all plans. You can stream consent events to your own data warehouse.
When does EU AI Act Article 50 become enforceable?
2 August 2026 for systems placed on the market after that date. Systems already on the market before then have until 2 December 2026 — the grace period was shortened from 6 to 3 months by the 7 May 2026 Digital Omnibus agreement.
Does the EU AI Act apply to my non-EU company?
Yes, if you have EU users or offer an AI system on the EU market. The Act's territorial scope mirrors GDPR — being established outside the EU does not exempt you.
What are the 4 obligations of Article 50?
(1) Chatbot / AI interaction disclosure — tell users they are talking to AI. (2) AI-generated content marking — machine-readable watermark/metadata for synthetic text/image/video/audio. (3) Emotion recognition & biometric categorisation — inform exposed individuals. (4) Deepfake & public-interest content labelling — visible label.
What are the penalties?
Article 50 violations can be fined up to €15 million or 3% of global annual turnover, whichever is higher. California SB 942 carries $5,000 per violation; Oregon SB 1546 grants $1,000 statutory damages per violation.
I only use ChatGPT for support. Am I in scope?
Yes. Any user-facing AI interaction — including third-party chatbots — falls under Article 50(1). Colorado, Oregon and Washington have parallel rules.
How do I 'machine-readable' mark AI-generated content?
The C2PA (Coalition for Content Provenance and Authenticity) standard is the de facto solution: cryptographically signed provenance metadata embedded in the media file. The Cookietrace AI Disclosure Module produces C2PA for image/video/audio.
Is there a US federal AI transparency law?
No. The 11 December 2025 Trump executive order challenges state laws, but until courts decide, state laws such as California SB 942, Colorado AI Act, Texas TRAIGA (HB 149), Oregon SB 1546 and Washington HB 2225 remain in force.
When does the Cookietrace AI Disclosure Module ship?
June 2026 — two months ahead of EU Article 50 enforcement. It shares the same loader as our CMP, no extra integration needed. Details: /ai-disclosure page.
What happens when a visitor clicks "Reject All"?
Cookies already set by the rejected categories are deleted, providers with a consent API (Meta, Clarity, TikTok) are told to revoke, and — if you enable tracker request blocking — outgoing requests to known trackers are stopped before they leave the browser. Note that scripts already loaded are not removed from the page; what stops is their data transmission.
Can you block trackers before the visitor makes a choice?
With Cookietrace's Prior Blocking setting enabled, non-essential cookies and trackers detected by the scan — whether loaded via GTM or embedded directly in the page — are not executed until the visitor makes a choice; if the visitor rejects, they never run, and if they accept, only the accepted categories load.
Does Google Analytics collect data before consent?
With Google Consent Mode v2 the tags receive a "no consent" signal: GA does not write cookies and sends a cookieless ping instead. Once consent is given it switches to full measurement. If you also want that ping stopped, enable tracker request blocking with the before-consent option.