Appearance
US state laws
On the US template, a visitor from the US sees a short notice when they arrive: a title, a paragraph, and the same statutory link described below in The footer link — not nothing. Nothing is held back for a visitor who has not opted out — non-essential scripts run from the first request, notice or no notice. For a visitor who has, whether by saving the checkbox on an earlier visit or by signalling Global Privacy Control right now, marketing is held back from that same first request: the widget reads the answer before anything paints, not after. That is deliberate, not a gap: no US state privacy law requires a consent banner that blocks everything on arrival.
One exception, and only if you hold a script back by URL
Script URL pattern rules install before the widget has read its own configuration and location. For a visitor whose previous answer is not already cached on this device — chiefly a first-time visitor — a script matching one of your patterns is held until that configuration and location come back, even on a pageview where the eventual answer is "let it run." A returning visitor whose earlier answer is cached rarely sees this: their scripts are typically released the moment the page reads that cache, before any network call. Marking a script type="text/plain" instead of using a URL pattern has no install-time step to get ahead of the real answer this way — see Holding back third-party scripts for what each does and does not block.
Closing the notice is remembered for as long as Consent expiration allows — 365 days by default, capped at 390, the same setting that governs the consent cookie's lifetime. Until then it does not come back; a visitor who only dismissed the notice and never opened the dialog sees it again once that expires, the same way a decided visitor's banner re-asks on the GDPR template.
Safari is shorter
Safari caps cookies written by JavaScript at seven days, so on Safari an opt-out survives that long unless the visitor comes back and refreshes it. When it does expire, the notice returns with it, so they are asked again rather than quietly opted back in. This applies to any consent tool that runs in the browser.
In the meantime, the opt-out mechanism is reachable in two ways:
- the floating reopen icon
- a link you add to your site's footer
Either one opens the same opt-out dialog, described below.
On the combined template, a site runs both the GDPR banner and the US notice, and a visitor's country decides which one they get — a German visitor sees the GDPR banner, a Californian sees the notice, on the same page. Only a visitor in the United States loses the banner; everyone else keeps it, including visitors from countries that are neither American nor European: Brazil, Canada and Australia have opt-in laws of their own, and the GDPR half of the combined template is what covers them.
The combined template is available on the Pro plan and above. On Free and Start a site picks one of the two: GDPR, or US-only. A site that chose the combined template on Pro and later moved to a lower plan keeps the choice in the designer but is served the GDPR banner everywhere until it upgrades again or picks a single template — opt-in for everyone, never opt-out for a visitor whose law asks for consent first.
On the US-only template, there is no GDPR banner for anyone to lose — picking this template instead of combined means the site never runs one at all. A visitor from Germany, Brazil or anywhere else gets exactly the same notice and the same opt-out dialog a Californian does, checkbox and all, with no reject mechanism and no opt-in consent step, regardless of what their own country's law would otherwise ask for. That is the deliberate consequence of choosing US-only over combined, not a bug: the site owner declined to run a GDPR banner for anyone, and this template does not add one back in for visitors it was not built to cover. If your site has visitors GDPR reaches, the combined template is what serves them correctly; US-only is for a site that genuinely has none.
Why it's a notice, not a banner
The California Attorney General's guidance on the CCPA/CPRA describes a notice at collection — disclosed at or before the point data is collected, which a conspicuous notice or link satisfies online — plus a "clear and conspicuous Do Not Sell or Share My Personal Information" mechanism, plus honouring at least two opt-out signals, GPC among them. Colorado's guidance describes the same shape: opt-out for sale and targeted advertising, applied after collection has already started.
That is the opposite requirement from GDPR, which needs opt-in consent before anything non-essential runs — hence a banner that blocks first and asks second. These laws are opt-out: the default is that data may be sold or shared, and the visitor's job, if they want it, is to object. A banner that stops everything until a decision would be doing more than the law asks and adding friction the law does not require. A notice that discloses and links to the opt-out, without blocking anything, is the shape these laws actually describe.
The footer link
html
<a href="#" data-cookiewave="show-preferences">
Do Not Sell or Share My Personal Information
</a>Paste it into your footer as-is. The phrase is the one several of these statutes use for the mechanism itself, not marketing copy of ours — reword it and you may no longer be describing what the link does under the law that requires it. The wording is the part that is fixed; how you wire it up is not.
The attribute needs nothing else — no script, and no return false to stop the page jumping. If you prefer to call it from your own code, or the designer showed you the JavaScript form, that works identically:
html
<a href="#" onclick="window.CookieWave.showPreferences(); return false;">
Do Not Sell or Share My Personal Information
</a>One reason to prefer the attribute: if your site sends a Content-Security-Policy header, an inline onclick is a script, and a policy without unsafe-inline blocks it — silently.
Both forms, and what they open on each kind of banner, are in Let visitors reopen the banner.
The opt-out dialog
The dialog behind the notice, the floating icon, and the footer link is lighter than the one the GDPR template shows: no category list, just one control.
A checkbox, not a toggle, and inverted. It opens showing the visitor's current answer, not always blank: checked if they already count as opted out — a stored decision from an earlier visit, or Global Privacy Control signalling right now — unchecked otherwise. Unchecked means data may be sold or shared; checking it and saving withdraws that permission. The statutory phrasing runs in that direction, so the control has to read the way the law reads rather than the way our other toggles do.
Underneath it, two buttons: Cancel, which closes the dialog without changing anything, and Save My Preferences, which applies it.
Checking the box and saving:
- denies the
marketingcategory - deletes the cookies that category's scan catalogued
- sends the denied signal through Consent Mode, the same as a rejection would on the GDPR template
That is all it does. The checkbox does not touch analytics, preferences, or strictly necessary — those keep running exactly as they were before the visitor opened the dialog, whether the box ends up checked or not. CPRA's "sale" and "sharing" mean disclosure for cross-context behavioural advertising, which is what the marketing category is for. Analytics isn't that, whatever a vendor's own privacy policy might call it, and this dialog was built to leave it alone rather than fold it into a control that says one thing and does another.
Global Privacy Control
GPC carries more weight on this template than on the GDPR one, where it is a preference rather than a binding opt-out — Global Privacy Control sets out the difference. The visible effect here: a visitor signalling GPC opens the dialog with the checkbox already checked, opted out before they've clicked anything, and a consent they gave before turning GPC on no longer counts.
Turning the notice off
Settings → General has Show the notice to US visitors, on by default. It only appears for the US and combined GDPR+US templates.
Turn it off and a US visitor gets nothing on arrival — no title, no paragraph, no inline link, the way it worked before this notice existed. From then on, the floating icon and any link you've put in your own footer are the only ways into the dialog. Nothing on the page announces that either one exists, so if you turn the notice off, make sure at least one of them is somewhere a visitor would actually look.
What this does not handle
Most of these state laws also require opt-in consent for sensitive data, and California requires it for visitors under 16. The US template grants everything by default and has no notion of either category — it was not built to distinguish them, and this page cannot make it do so retroactively. If your site processes sensitive personal information or is directed at visitors under 16, that gap is yours to close, and closing it needs advice from your own counsel before it needs a setting from us.