Skip to main content

Domande frequenti

Risposte brevi alle domande più comuni sulla gestione del consenso con Cookietrace.

Che cos'è Cookietrace?

Una piattaforma di gestione del consenso per GDPR, ePrivacy, CCPA e KVKK. Uno script si installa in circa 3 minuti, invia i segnali Consent Mode v2 e conserva log firmati per oltre 3 anni.

Quanto dura l'installazione?

Circa 3 minuti: aggiungi una riga di JavaScript nell'head o tramite Google Tag Manager. Nessuna modifica al codice.

Cosa succede se il visitatore rifiuta tutto?

I cookie delle categorie rifiutate vengono eliminati, la revoca viene inviata ai fornitori con API di consenso e, se il blocco delle richieste è attivo, le chiamate dei tracker riconosciuti vengono fermate nel browser.

Quanto costa?

Gratis fino a 25.000 pagine viste al mese. Pro costa 39 $/mese; Business ed Enterprise aggiungono più domini e retention più lunga.

Come funziona Cookietrace

Un solo script si installa in circa 3 minuti, direttamente o tramite Google Tag Manager. Analizza il sito alla ricerca di cookie, pixel e uso dello storage, classifica ogni tracker, mostra il banner nella lingua del visitatore e solo dopo consente i tag non essenziali. Le scansioni periodiche segnalano ogni nuovo tracker.

  • Rilevamento automatico di cookie, pixel e fingerprinting con riscansioni programmate.
  • Categorie granulari: necessari, funzionali, analitici, marketing, social.
  • Segnali Google Consent Mode v2 e IAB TCF v2.2 inclusi.
  • Blocco opzionale delle richieste dei tracker rifiutati nel browser.
  • Log di consenso firmati e con marca temporale, conservati oltre 3 anni.

Normative coperte

GDPR ed ePrivacy per UE e Regno Unito, KVKK e la guida cookie 2022 per la Turchia, CCPA/CPRA per la California, oltre al supporto per l'informativa dell'articolo 50 dell'AI Act. Banner, conservazione e prova del consenso seguono le regole della giurisdizione del visitatore.

Piani e prezzi

Prezzo mensile in USD, in base al numero di domini: Pro: $39/mese · Premium: $79/mese · Enterprise: prezzo su misura. Tutti i piani mantengono le funzioni di compliance; la prova di 14 giorni non richiede carta.

Azienda

Cookietrace by Ezeratech Digital (EZERA DIGITAL TECHNOLOGIES FZCO), fondata nel 2024. Sedi: IFZA Business Park, Dubai Silicon Oasis, Dubai (AE) · İstanbul (TR) · London (GB). Interfaccia e supporto in inglese, turco, spagnolo e italiano. Contatti: [email protected] (vendite), [email protected] (supporto), [email protected] (privacy).

What is Cookietrace?

Cookietrace is an enterprise-grade Consent Management Platform (CMP) that keeps websites compliant with GDPR, KVKK, ePrivacy and CCPA. Built by Ezera Digital Technologies FZCO (Ezeratech Digital).

Who uses Cookietrace?

E-commerce sites, fintech, SaaS, agencies, telecom and SMBs. Suitable for any size of website that needs KVKK in Türkiye, GDPR in the EU, CCPA in the US.

How long does setup take?

3 minutes with a single-line script. No code changes or developer help required. Can also be added through a tag manager.

How many languages does Cookietrace support?

The banner UI ships in 8 languages: Turkish, English, German, French, Spanish, Italian, Dutch and Polish. Custom language additions are available from the Pro plan.

Which countries are covered?

Geo-targeting works worldwide. The banner shows the right regulation per country: KVKK for TR, GDPR for the EU, CCPA/CPRA for US states, LGPD for Brazil.

Is Cookietrace compliant with the KVKK Authority's 2022 Cookie Guide?

Yes, 100%. Disclosure for essential cookies, plain-language requirement, equal-prominence Accept/Reject buttons, separate consent for cross-border transfer — all articles are applied by default.

Is GDPR compliance not enough?

If you operate in Türkiye, GDPR alone is not enough. KVKK Art. 9 (cross-border transfer), the explicit consent definition and VERBİS obligations differ. Cookietrace is designed KVKK-native.

Does it comply with the ePrivacy Directive?

Yes. Per the EU ePrivacy Directive (Cookie Law), all non-essential cookies are blocked before consent. No pre-ticked checkboxes, no dark patterns.

Does it support California (CCPA/CPRA)?

Yes. For US users, the 'Do Not Sell My Personal Information' link, opt-out management and Global Privacy Control (GPC) signal are automatically supported.

How are consent logs stored?

Each consent event is stored immutably with timestamp, IP hash, banner version and cryptographic hash. In an audit you can prove 'this user made this choice at this time'. Default retention is 3 years, extendable per plan.

Does it help with VERBİS registration?

Cookietrace automatically lists your cookie inventory and data processing activities — you can use this as a reference in your VERBİS registration. Cookietrace is a software solution and does not provide legal advisory services. For the legal aspects of VERBİS registration, please consult your own legal counsel.

Who is the data controller?

As the website owner, you are the data controller. Cookietrace acts as the data processor. A KVKK-compliant standard Data Processing Agreement (DPA) is included in all plans.

What is the script weight?

Under 15 KB (gzip). With edge-cached delivery and async-defer loading the impact on Core Web Vitals is negligible. Test sites show no measurable change in LCP/CLS.

Will it slow down my site?

No. The banner script, written with a modern stack, is non-blocking and loads async. There is no visible drop in your Lighthouse scores.

What is automated cookie discovery?

The Deep Scan engine crawls your site weekly, automatically finds and categorizes newly added cookies and trackers. No manual updates needed.

Does it support Single Page Applications (SPA)?

Yes. Fully compatible with React, Vue, Angular, Next.js and other SPA frameworks. Banner state persists across page transitions.

Does it work on AMP pages?

Yes, we offer an AMP-compatible banner version. Included from the Pro plan and above.

Is there a free plan?

There is no permanently free plan. Every plan starts with a 14-day trial that needs no credit card and includes the consent banner, tracker request blocking, audit logs, 8 languages, and Google Consent Mode v2.

What is the contract length?

Cancel monthly. We offer 20% off for annual billing but there is no long-term lock-in.

Is there an extra fee for multiple domains?

Pro includes 10 domains, Premium includes 100 domains and Enterprise is unlimited. Additional domains can be purchased modularly.

How is my data secured?

All traffic runs over HTTPS, consent data is stored encrypted. Stored consent records are immutable — cannot be modified. Regular backups and access logs are maintained.

Where is my data stored?

By default in an EU (Frankfurt) data center. Türkiye-based data residency is available on request — eliminating the KVKK Art. 9 cross-border transfer obligation.

What happens in case of a data breach?

Our DPA includes a reasonable-time notification obligation. We notify the data controller per KVKK Art. 12 and GDPR Art. 33. All security events are automatically logged.

Does it work with Google Tag Manager?

Yes, native GTM integration. Tags are automatically triggered or blocked based on consent state.

Does it support Google Consent Mode v2?

Yes, out-of-the-box. The Consent Mode v2 signals required for Google Ads and GA4 to function properly in the EU and TR are sent automatically.

Are there Shopify, WooCommerce, Wix integrations?

Yes, official one-click plugins/apps are available for all of them. There is also a universal script option that works with any CMS.

Does it work with the programmatic ad ecosystem?

Yes. The banner is compatible with Google Ads, Meta Ads and other major ad-tech platforms. Ad scripts are automatically triggered or blocked based on consent state.

Is there API and webhook access?

Yes, REST API and webhook access are included on all plans. You can stream consent events to your own data warehouse.

When does EU AI Act Article 50 become enforceable?

2 August 2026 for systems placed on the market after that date. Systems already on the market before then have until 2 December 2026 — the grace period was shortened from 6 to 3 months by the 7 May 2026 Digital Omnibus agreement.

Does the EU AI Act apply to my non-EU company?

Yes, if you have EU users or offer an AI system on the EU market. The Act's territorial scope mirrors GDPR — being established outside the EU does not exempt you.

What are the 4 obligations of Article 50?

(1) Chatbot / AI interaction disclosure — tell users they are talking to AI. (2) AI-generated content marking — machine-readable watermark/metadata for synthetic text/image/video/audio. (3) Emotion recognition & biometric categorisation — inform exposed individuals. (4) Deepfake & public-interest content labelling — visible label.

What are the penalties?

Article 50 violations can be fined up to €15 million or 3% of global annual turnover, whichever is higher. California SB 942 carries $5,000 per violation; Oregon SB 1546 grants $1,000 statutory damages per violation.

I only use ChatGPT for support. Am I in scope?

Yes. Any user-facing AI interaction — including third-party chatbots — falls under Article 50(1). Colorado, Oregon and Washington have parallel rules.

How do I 'machine-readable' mark AI-generated content?

The C2PA (Coalition for Content Provenance and Authenticity) standard is the de facto solution: cryptographically signed provenance metadata embedded in the media file. The Cookietrace AI Disclosure Module produces C2PA for image/video/audio.

Is there a US federal AI transparency law?

No. The 11 December 2025 Trump executive order challenges state laws, but until courts decide, state laws such as California SB 942, Colorado AI Act, Texas TRAIGA (HB 149), Oregon SB 1546 and Washington HB 2225 remain in force.

When does the Cookietrace AI Disclosure Module ship?

June 2026 — two months ahead of EU Article 50 enforcement. It shares the same loader as our CMP, no extra integration needed. Details: /ai-disclosure page.

Cosa succede quando un visitatore clicca "Rifiuta tutto"?

I cookie già impostati dalle categorie rifiutate vengono eliminati, ai fornitori con un'API di consenso (Meta, Clarity, TikTok) viene comunicata la revoca e, se hai attivato il blocco delle richieste, le richieste verso i tracker riconosciuti vengono fermate prima di lasciare il browser. Gli script già caricati non vengono rimossi dalla pagina; ciò che si ferma è la trasmissione dei dati.

Potete bloccare i tracker prima che il visitatore effettui una scelta?

Sì, con una seconda opzione facoltativa. Quando è attiva, i tracker non essenziali vengono fermati finché il visitatore non sceglie — è ciò che prevedono le regole opt-in. È disattivata per impostazione predefinita perché riduce il traffico misurato e perché la decisione spetta a te come titolare del trattamento. Un limite da conoscere: il nostro widget si carica in modo asincrono, quindi non può annullare una richiesta già inviata nei primissimi istanti di una prima visita. L'effetto pieno si ottiene dalla visita successiva in poi.

Google Analytics raccoglie dati prima del consenso?

Con Google Consent Mode v2 i tag ricevono un segnale di "nessun consenso": GA non scrive cookie e invia invece un ping senza cookie. Dopo il consenso passa alla misurazione completa. Se vuoi fermare anche quel ping, attiva il blocco delle richieste con l'opzione precedente al consenso.