Preguntas frecuentes
Respuestas breves a las dudas más habituales sobre la gestión del consentimiento con Cookietrace.
¿Qué es Cookietrace?
Una plataforma de gestión del consentimiento para RGPD, ePrivacy, CCPA y KVKK. Un script se instala en unos 3 minutos, envía señales de Consent Mode v2 y guarda registros firmados durante más de 3 años.
¿Cuánto tarda la instalación?
Unos 3 minutos: añada una línea de JavaScript en el head o mediante Google Tag Manager. Sin cambios de código.
¿Qué ocurre si el visitante rechaza todo?
Se eliminan las cookies de las categorías rechazadas, se notifica la revocación a los proveedores con API de consentimiento y, si el bloqueo de solicitudes está activo, las peticiones de rastreadores reconocidos se detienen en el navegador.
¿Cuánto cuesta?
Gratis hasta 25.000 páginas vistas al mes. Pro cuesta 39 $/mes; Business y Enterprise añaden más dominios y mayor retención.
Cómo funciona Cookietrace
Un único script se instala en unos 3 minutos, directamente o mediante Google Tag Manager. Escanea el sitio en busca de cookies, píxeles y uso de almacenamiento, clasifica cada rastreador, muestra el banner en el idioma del visitante y solo después permite las etiquetas no esenciales. Los reescaneos periódicos avisan cuando aparece un rastreador nuevo.
- Descubrimiento automático de cookies, píxeles y fingerprinting con reescaneos programados.
- Categorías granulares: necesarias, funcionales, analíticas, marketing y sociales.
- Señales de Google Consent Mode v2 e IAB TCF v2.2 incluidas.
- Bloqueo opcional de solicitudes de rastreadores rechazados en el navegador.
- Registros de consentimiento firmados y con sello de tiempo, conservados más de 3 años.
Normativas cubiertas
RGPD y ePrivacy para la UE y Reino Unido, KVKK y la guía de cookies de 2022 para Turquía, CCPA/CPRA para California, además del soporte de divulgación del artículo 50 de la Ley de IA. El banner, la retención y la prueba de consentimiento siguen la norma de la jurisdicción del visitante.
Planes y precios
Precio mensual en USD, según el número de dominios: Pro: $39/mes · Premium: $79/mes · Enterprise: precio a medida. Todos los planes mantienen las funciones de cumplimiento; la prueba de 14 días no requiere tarjeta.
Empresa
Cookietrace by Ezeratech Digital (EZERA DIGITAL TECHNOLOGIES FZCO), fundada en 2024. Oficinas: IFZA Business Park, Dubai Silicon Oasis, Dubai (AE) · İstanbul (TR) · London (GB). Interfaz y soporte en inglés, turco, español e italiano. Contacto: [email protected] (ventas), [email protected] (soporte), [email protected] (privacidad).
What is Cookietrace?
Cookietrace is an enterprise-grade Consent Management Platform (CMP) that keeps websites compliant with GDPR, KVKK, ePrivacy and CCPA. Built by Ezera Digital Technologies FZCO (Ezeratech Digital).
Who uses Cookietrace?
E-commerce sites, fintech, SaaS, agencies, telecom and SMBs. Suitable for any size of website that needs KVKK in Türkiye, GDPR in the EU, CCPA in the US.
How long does setup take?
3 minutes with a single-line script. No code changes or developer help required. Can also be added through a tag manager.
How many languages does Cookietrace support?
The banner UI ships in 8 languages: Turkish, English, German, French, Spanish, Italian, Dutch and Polish. Custom language additions are available from the Pro plan.
Which countries are covered?
Geo-targeting works worldwide. The banner shows the right regulation per country: KVKK for TR, GDPR for the EU, CCPA/CPRA for US states, LGPD for Brazil.
Is Cookietrace compliant with the KVKK Authority's 2022 Cookie Guide?
Yes, 100%. Disclosure for essential cookies, plain-language requirement, equal-prominence Accept/Reject buttons, separate consent for cross-border transfer — all articles are applied by default.
Is GDPR compliance not enough?
If you operate in Türkiye, GDPR alone is not enough. KVKK Art. 9 (cross-border transfer), the explicit consent definition and VERBİS obligations differ. Cookietrace is designed KVKK-native.
Does it comply with the ePrivacy Directive?
Yes. Per the EU ePrivacy Directive (Cookie Law), all non-essential cookies are blocked before consent. No pre-ticked checkboxes, no dark patterns.
Does it support California (CCPA/CPRA)?
Yes. For US users, the 'Do Not Sell My Personal Information' link, opt-out management and Global Privacy Control (GPC) signal are automatically supported.
How are consent logs stored?
Each consent event is stored immutably with timestamp, IP hash, banner version and cryptographic hash. In an audit you can prove 'this user made this choice at this time'. Default retention is 3 years, extendable per plan.
Does it help with VERBİS registration?
Cookietrace automatically lists your cookie inventory and data processing activities — you can use this as a reference in your VERBİS registration. Cookietrace is a software solution and does not provide legal advisory services. For the legal aspects of VERBİS registration, please consult your own legal counsel.
Who is the data controller?
As the website owner, you are the data controller. Cookietrace acts as the data processor. A KVKK-compliant standard Data Processing Agreement (DPA) is included in all plans.
What is the script weight?
Under 15 KB (gzip). With edge-cached delivery and async-defer loading the impact on Core Web Vitals is negligible. Test sites show no measurable change in LCP/CLS.
Will it slow down my site?
No. The banner script, written with a modern stack, is non-blocking and loads async. There is no visible drop in your Lighthouse scores.
What is automated cookie discovery?
The Deep Scan engine crawls your site weekly, automatically finds and categorizes newly added cookies and trackers. No manual updates needed.
Does it support Single Page Applications (SPA)?
Yes. Fully compatible with React, Vue, Angular, Next.js and other SPA frameworks. Banner state persists across page transitions.
Does it work on AMP pages?
Yes, we offer an AMP-compatible banner version. Included from the Pro plan and above.
Is there a free plan?
There is no permanently free plan. Every plan starts with a 14-day trial that needs no credit card and includes the consent banner, tracker request blocking, audit logs, 8 languages, and Google Consent Mode v2.
What is the contract length?
Cancel monthly. We offer 20% off for annual billing but there is no long-term lock-in.
Is there an extra fee for multiple domains?
Pro includes 10 domains, Premium includes 100 domains and Enterprise is unlimited. Additional domains can be purchased modularly.
How is my data secured?
All traffic runs over HTTPS, consent data is stored encrypted. Stored consent records are immutable — cannot be modified. Regular backups and access logs are maintained.
Where is my data stored?
By default in an EU (Frankfurt) data center. Türkiye-based data residency is available on request — eliminating the KVKK Art. 9 cross-border transfer obligation.
What happens in case of a data breach?
Our DPA includes a reasonable-time notification obligation. We notify the data controller per KVKK Art. 12 and GDPR Art. 33. All security events are automatically logged.
Does it work with Google Tag Manager?
Yes, native GTM integration. Tags are automatically triggered or blocked based on consent state.
Does it support Google Consent Mode v2?
Yes, out-of-the-box. The Consent Mode v2 signals required for Google Ads and GA4 to function properly in the EU and TR are sent automatically.
Are there Shopify, WooCommerce, Wix integrations?
Yes, official one-click plugins/apps are available for all of them. There is also a universal script option that works with any CMS.
Does it work with the programmatic ad ecosystem?
Yes. The banner is compatible with Google Ads, Meta Ads and other major ad-tech platforms. Ad scripts are automatically triggered or blocked based on consent state.
Is there API and webhook access?
Yes, REST API and webhook access are included on all plans. You can stream consent events to your own data warehouse.
When does EU AI Act Article 50 become enforceable?
2 August 2026 for systems placed on the market after that date. Systems already on the market before then have until 2 December 2026 — the grace period was shortened from 6 to 3 months by the 7 May 2026 Digital Omnibus agreement.
Does the EU AI Act apply to my non-EU company?
Yes, if you have EU users or offer an AI system on the EU market. The Act's territorial scope mirrors GDPR — being established outside the EU does not exempt you.
What are the 4 obligations of Article 50?
(1) Chatbot / AI interaction disclosure — tell users they are talking to AI. (2) AI-generated content marking — machine-readable watermark/metadata for synthetic text/image/video/audio. (3) Emotion recognition & biometric categorisation — inform exposed individuals. (4) Deepfake & public-interest content labelling — visible label.
What are the penalties?
Article 50 violations can be fined up to €15 million or 3% of global annual turnover, whichever is higher. California SB 942 carries $5,000 per violation; Oregon SB 1546 grants $1,000 statutory damages per violation.
I only use ChatGPT for support. Am I in scope?
Yes. Any user-facing AI interaction — including third-party chatbots — falls under Article 50(1). Colorado, Oregon and Washington have parallel rules.
How do I 'machine-readable' mark AI-generated content?
The C2PA (Coalition for Content Provenance and Authenticity) standard is the de facto solution: cryptographically signed provenance metadata embedded in the media file. The Cookietrace AI Disclosure Module produces C2PA for image/video/audio.
Is there a US federal AI transparency law?
No. The 11 December 2025 Trump executive order challenges state laws, but until courts decide, state laws such as California SB 942, Colorado AI Act, Texas TRAIGA (HB 149), Oregon SB 1546 and Washington HB 2225 remain in force.
When does the Cookietrace AI Disclosure Module ship?
June 2026 — two months ahead of EU Article 50 enforcement. It shares the same loader as our CMP, no extra integration needed. Details: /ai-disclosure page.
¿Qué ocurre cuando un visitante pulsa "Rechazar todo"?
Las cookies ya establecidas por las categorías rechazadas se eliminan, a los proveedores con API de consentimiento (Meta, Clarity, TikTok) se les comunica la revocación y —si activas el bloqueo de solicitudes— las peticiones salientes hacia rastreadores conocidos se detienen antes de salir del navegador. Los scripts ya cargados no se eliminan de la página; lo que se detiene es su transmisión de datos.
¿Podéis bloquear rastreadores antes de que el visitante elija?
Sí, con una segunda opción facultativa. Cuando está activa, los rastreadores no esenciales se detienen hasta que el visitante elige, que es lo que esperan las reglas opt-in. Está desactivada por defecto porque reduce el tráfico medido y porque la decisión te corresponde como responsable del tratamiento. Una limitación: nuestro widget se carga de forma asíncrona, por lo que no puede deshacer una solicitud ya enviada en los primeros instantes de la primera visita. El efecto pleno se alcanza a partir de la siguiente visita.
¿Google Analytics recoge datos antes del consentimiento?
Con Google Consent Mode v2 las etiquetas reciben una señal de "sin consentimiento": GA no escribe cookies y envía un ping sin cookies. Tras el consentimiento pasa a la medición completa. Si también quieres detener ese ping, activa el bloqueo de solicitudes con la opción previa al consentimiento.