Cookies, Consent & A Free Cookie Banner Solution

by Henri Rapp | Sep 7, 2026 | Web Marketing

A lot of what's been written about cookie consent was written by a company selling cookie consent software. That shapes the advice more than you'd think. The truth of this conversation is complex, and whether you need cookie consent at all is "it depends." That however is less covered when you're selling GDPR cookie consent plugin subscriptions.

I'm not selling one. I've got no stake in what you decide here. What I've got is a free, open source tool I use on my own site, and a straight read on when this matters and when it doesn't.

What Is Cookie Consent?

A cookie is a small file a website stores in your browser. Some of them are boring and necessary for core website functionality. Some of them follow you around the internet.

Consent, in this context, means asking a visitor's permission before the second kind starts running.

Cookie Consent

Cookies That Keep Your Site Working

These are usually called essential or strictly necessary cookies, and they're the reason you can log into a site, keep items in a cart, or have your language preference remembered between pages.

Security tools land in this bucket too. If you're running reCAPTCHA on your contact form, that's doing a real job: keeping bots from filling your inbox with garbage. Gate it behind consent and you've handed your forms to spammers, because a bot isn't going to click accept before it starts hammering your site. Anything protecting core functionality stays on.

You can't turn these off, and no cookie banner should let you. Switch them off and the site stops working. That's why every properly built consent banner shows essential cookies as locked on.

Cookies And Scripts That Track You

This is the category consent is actually about.

Google Analytics drops a cookie so it can tell whether you're a new visitor or a returning one. The Meta pixel drops one so Facebook can show you an ad for the thing you looked at yesterday. Embedded YouTube videos set cookies before you've even hit play.

Most of these are third party, meaning the cookie belongs to a company that isn't you. You put their script on your site, and now that company knows something about your visitor. That's the part people have opinions about, and reasonably so.

Cookie Consent In Action

A real consent banner doesn't just display a message. It holds those tracking scripts back until someone clicks accept. There's no shortage of tools built to handle that for you, free and paid, most of them positioned around GDPR or CCPA compliance.

Legal Reality For US Businesses

Before I go further, the necessary disclaimer: I'm not a lawyer, this isn't legal advice, and none of what follows should be treated as a determination about your specific business. Privacy law changes constantly and this reflects the landscape as of September 2026. If compliance genuinely matters for your situation, talk to an actual attorney.

With that said, here's the shape of it.

Opt In Versus Opt Out

The single most useful thing to understand is that Europe and the United States approach this from opposite directions.

Under the EU's GDPR, you need permission before you collect anything. Prior consent. Nothing tracks until the visitor agrees. That's why every European site throws a wall of cookie choices at you before you can read the article.

US state privacy laws generally work the other way. In most cases you don't need prior consent to collect information, but you do need to tell people what you're collecting and give them a real way to opt out of it.

So the GDPR-style banner that blocks everything until you click accept goes further than US law requires. That's a choice, not an obligation.

California CCPA & If It Applies To You

The California Consumer Privacy Act, usually shortened to CCPA, is the state law that gives Californians the right to know what personal information a business collects about them and to tell that business to stop selling or sharing it.

The CCPA doesn't apply to every business with a website. It kicks in for for-profit companies that hit at least one of three thresholds: annual gross revenue over roughly $25 million, processing the personal information of 100,000 or more California residents in a year, or making more than half your revenue from selling or sharing personal information.

Plenty of California businesses don't come close to those thresholds, let alone a plumber in Akron with a five page website. I don't hit them either.

"Probably Fine" Isn't A Guarantee

Now the other side.

More than 20 states run their own privacy frameworks, and California has a history of enforcing. Disney paid $2.75 million in 2026 over opt-outs that didn't work. Penalties run to $7,500 per intentional violation, per consumer.

Those are big companies, but there are attorneys who scan small sites and send demand letters. Unlikely target, not an impossible one.

I can't tell you you're safe. I'm not qualified to. I can show you where the lines are so you can ask someone who is.

What About GDPR & EU Visitors Finding Your Site?

This one comes up a lot, and it comes up for me personally. I've had people in the EU read my articles. I've been hired by production companies in Europe for work shot in the United States.

GDPR's territorial scope hinges on whether you're targeting people in the EU. Offering goods and services to them, or monitoring their behavior. The regulators' own guidance draws the line at intent: are you actually trying to reach that market? The signals they look at are things like listing prices in euros, offering EU country language options, advertising into those regions.

Someone in Berlin clicking in to your blog post from a Google search is incidental, not targeted. The EU's own guidance uses almost exactly that example, a tourist reading a US news site, and says it doesn't pull that site into GDPR.

If you're actively marketing to European customers, that's a different conversation and it's one to have with a lawyer. If you're a US business serving US clients and European people occasionally land on your content, you're not suddenly operating under European law because someone shared your article.

Why Bother If Not Required To?

Consent matters. And not just in the bedroom. Here's the thing that gets lost in all the compliance talk. Whether or not a law requires it, you're putting scripts on your site that hand information about your visitors to companies those visitors have never heard of. Telling them that's happening, and giving them a say in it, is just a decent way to treat people.

One small side effect worth mentioning: your analytics get a little more honest. You'll see fewer sessions, since only people who actively clicked accept get counted, and automated traffic isn't clicking anything. Smaller numbers, but the ones you're looking at are real people who engaged with your site.

It's A Trust Signal

Your website is making an argument about who you are before anyone reads a word of your copy. Broken layouts, stock photos, missing contact info, all of it registers. So does shipping visitor data off to Meta without mentioning it.

A clean, well-designed consent banner says you thought about this. It says you're the kind of operation that handles the details. That's the same signal a fast, well-built, accessible website sends, and it compounds with all the other small decisions that make someone trust you enough to fill out your form.

Getting Ahead Of Changing Privacy Regulation

Privacy regulation has been moving in one direction for a decade. More states, more requirements, not fewer. Set it up now, so if regulation shifts you're ahead of it rather than scrambling when your state passes something. If your business grows past those CCPA thresholds someday, you're already there.

The Free Solution: Silktide Consent Manager

I looked at a lot of options for this. Most of the good ones are freemium, where the free tier does the basics and anything genuinely useful, like customizing its appearance, sits behind a subscription. Fine for an enterprise level company, hard to explain to a small business owner as a recurring line item on top of hosting.

Silktide Consent Manager is the one I landed on. It's free, it's open source, and there's no account, no domain limit, and no page view cap.

Why Open Source Matters

Open source means the code is published publicly under a license that lets you use and modify it. Same underlying idea as WordPress, which is why the software running most of the internet is free.

Two practical consequences for you. First, you can change it. The code is right there. If you want the buttons to match your brand, you edit it, you don't file a feature request and wait. Second, it's yours permanently. It's released under the MIT license, which can't be revoked for a version already published. Even if the company behind it changed direction tomorrow, the version you're running keeps working forever.

That's a meaningfully different relationship than renting a cookie banner for $10/month.

It Works On Any Website

This isn't a WordPress plugin. It's a stylesheet and a script, which means it works on WordPress, Squarespace, Shopify, Webflow, a hand-coded HTML site, whatever you've got. Anywhere you can paste code into the head of your site, this runs.

Who It's Good For, And Who It Isn't

Good fit: a US-focused business running Google Analytics and maybe an ad pixel or two. Local service businesses, freelancers, small shops, professional practices. That covers most people reading this.

Not a good fit, and I'd rather say so: if you have real European traffic you're actively marketing to, if you need a documented record proving each visitor consented, if you're in healthcare or finance, or if you're running e-commerce with serious remarketing. Those situations need a full consent management platform with audit logging and geo-targeting, and that's worth paying for.

If any of that describes you, talk to an attorney about what you actually need before picking a tool.

Setting Up Silktide Cookie Consent Manager

Silktide has an install wizard that builds your code for you. You work top to bottom through eight sections and the whole thing takes about ten minutes. None of it requires writing code, but knowing what each setting does will keep you from accepting defaults that don't fit your site.

1. Color Scheme

There are four built in presets to start but I'd just skip past that and use the three color fields underneath to match your website's identity.

Background is the panel itself. Text is your body copy. Primary color drives the buttons and links, so usually your brand identity's accent color. Set all three from your own palette rather than living with the defaults. A banner sitting in someone else's purple is the first thing that tells a visitor this was bolted on after the fact.

Silktide Cookie Consent - Color Scheme

2. Position

Where the banner sits when someone lands on your site for the first time. Center, bottom left, bottom right, or bottom center.

Center drops it in front of the content as a modal. The three bottom options anchor it to a corner or the bottom edge and let people keep reading. A bottom corner is the least disruptive and it's what I use. Center is the right call if you'd rather force the decision before anyone goes further, which is a legitimate position to take. Just know what you're trading for it.

Cookie Consent Banner Positioning

3. Background

This controls what happens to the rest of the page while the banner is up. There's a checkbox to block the background until the banner is closed, plus color, opacity, and blur settings underneath it.

Blocking means nobody touches your site until they answer. It's the aggressive option. Leave it unchecked and people can browse and decide whenever they want.

If you do block, opacity is where taste comes in. The default is black at 0.2, which is a light dim. Push it much higher and you're hiding your own homepage behind a scrim to ask about cookies. Blur is there if you want it and stays off at zero.

Cookie Consent Banner Website Background

4. Cookie Icon

After someone closes the banner, this small floating icon is how they reopen their preferences later. Somebody who accepts on Monday and changes their mind on Friday needs a way back in, so treat it as required even though it's a setting.You get bottom left or bottom right for position, and four color treatments built from your primary color and a neutral dark.

Cookie Consent Preferences Icon

5. Cookie Types, Consent, And Integrations

The longest section in the wizard and the one that determines what actually gets blocked.

You start with three consent types: Essential, Analytics, and Marketing. Essential has "this consent is required" checked, which locks it on and makes it non-rejectable. That's correct, because it covers what the site needs to function. Analytics and Marketing stay optional. Each type has a label and a description that visitors read in the preferences pane, and the default wording is clear enough to keep unless your site does something it doesn't cover.

Under each optional type is a set of Google Consent Mode signals. Analytics gets analytics_storage. Marketing gets ad_storage, ad_user_data, and ad_personalization checked together, which is what Google Ads expects. There's also functionality_storage, personalization_storage, and security_storage if you need them. These are the switches that tell Google's tags whether they have permission to run, and Silktide's Consent Mode documentation covers the Tag Manager route if you're going that way.

Below the signals is Tracking and integrations, where you attach third-party scripts to a consent type. Anything you add gets injected when someone accepts and removed on the next page load if they revoke. This is the part that makes the banner functionally work at blocking scripts/cookies.

Tracking Cookies & Scripts integration for Silktide Cookie Consent

There's also a GTM dataLayer event name at the top of this section, defaulting to stcm_consent_update. Leave it alone unless you're wiring through Tag Manager and need a different event name.

6. Prompt Text

The copy on the banner itself. One description field plus the three buttons.

Each button has a visible label and an accessible label. Visible is what people read. Accessible is what a screen reader announces, which is why "Reject non-essential" on screen pairs with "Reject all non-essential cookies" out loud. Don't leave the accessible labels empty, and don't just duplicate the visible text when it's short enough to be ambiguous without the surrounding context.

The description field takes HTML, which means this is where your privacy policy link goes. Link it. A banner that brings up privacy and then points nowhere is doing half the job.

Silktide Cookie Consent Banner Prompt Text

7. Preference Pane Text

The copy inside the preferences pane. Title, description, the save button, and the credit button.

That last one is Silktide's own link, labeled "Get this banner for free" by default. You can rewrite it or clear it out entirely. Worth thinking about rather than reflexively deleting, and I'll come back to why.

Silktide Preferences Panel Text

8. Installation On The Site

The wizard hands you a block of code that goes in the head of your site, on every page. On WordPress with Divi that's Theme Options, Integration tab, the field for adding code to the head. Squarespace calls it code injection. Every platform has a spot for it.

There is also a self hosted version, but likely if you are using a wizard to generate code, then self hosting is more than you want to mess with.

Styling It To Match Your Site Identity

The default banner is fine. Fine is not the same as right.

Out of the box you can set colors, position, and all the wording through the wizard. Beyond that, you need custom CSS, and that's where the difference between a generic banner and one that belongs on your site shows up.

Everything is scoped under an ID called #stcm-wrapper, which is deliberate. It means the banner's styles won't leak into your site and your site's styles won't accidentally break the banner. Silktide documents the full set of configuration options, and that's the reference worth having open if you're going past the wizard.

Styling Silktide To Match Your Website's Visuals

Making It Look Native To Your Site

This is the main reason to go past the defaults, and for most people it's the whole reason.

If your site has a distinct typeface, buttons with a specific radius, a particular hover behavior, the stock banner won't match any of it. A visitor notices it looks disconnected from your website even if they couldn't tell you why. A cookie banner in Helvetica sitting on a site that uses a bold condensed display face reads as bolted on, because it is. Same for square buttons on a site full of rounded ones, or a hover state that does something your buttons never do.

The tool exposes a set of CSS variables you can override for colors and typeface. Beyond those, the elements worth knowing are .stcm-button for the action buttons, #stcm-banner for the initial prompt, #stcm-modal for the preferences panel, and #stcm-icon for the floating reopener.

What you do with those depends entirely on your brand, which is exactly why I'm not going to hand you a stylesheet. Match your buttons. Match your type. Match your hover states. The specifics are yours.

Rethinking The Buttons

The default gives you accept and reject as two buttons of equal visual weight, plus a preferences link.

Equal weight is what EU regulators prefer, and making rejection meaningfully harder than acceptance is the kind of asymmetry regulators have penalized. So don't hide the reject option or bury it three clicks deep.

That said, there's real room between equal weight and obfuscation. Reducing the visual prominence of reject while keeping it obvious and one click away is standard UI/UX practice, and it's what most sites do. You're still giving people a genuine choice. You're just making accept the path of least resistance, which is what most visitors are going to pick anyway. I click accept on almost every banner I see, and I've built one.

Where you land on that is a design decision with real consequences. Just keep reject visible and easy to click.

Cookie Consent Banner

Removing The Branding

The free version includes a small Silktide logo and a link back to their site. Both can be hidden with CSS, and their license permits it as long as you keep the copyright notice in the source files.

Personally I'd rather my client's cookie banner not advertise a company their customers have never heard of. But I'm not stripping the credit and walking off either.

Relevance is what determines the quality of a link. One link from an article specifically about the tool, in the exact context it was built for, is a stronger signal than a footer link sitting on every page of a site about something else entirely. That's what this article is. Better outcome for them, cleaner site for me and my clients.

Fixing The Mobile Layout

The default layout is responsive, but "responsive" and "looks right on your site" aren't the same thing.

On narrow screens you'll often want the buttons to stack full width instead of sitting side by side, and you'll want to make sure the banner sits above any mobile menu you have rather than underneath it. Both are straightforward media query work.

Test it on an actual phone. Not just a narrow browser window.

The Heading Tag Problem

This one doesn't show up visually, which is why it's easy to ship and never catch. It's also a real SEO issue.

The preferences panel renders its title as an H1. Your page already has an H1, and it should be the only one, because that heading is one of the clearest signals telling search engines what the page is about. Now you've got a second one on every page of your site that says something about cookie preferences.

It takes a small piece of JavaScript to swap that heading for a paragraph styled to look identical. Visually nothing changes. Structurally, your page goes back to having one H1 that's actually about your business.

That's the kind of default behavior that's easy to miss when you're just trying to get the banner live, and it's the difference between an implementation that works and one that's correct.

Keeping It Honest As Your Site Changes

The banner doesn't break. Your stack does. Say you add a Meta pixel six months from now for a campaign. You paste it into the head of your site the way you'd paste anything, it starts collecting, and it fires for every visitor whether they accepted or not. Your banner still looks perfect. It still offers three categories. It's just lying now, because nothing ever wired that new script to the marketing category.

Cookie Consent Without The Subscription

If you're a small business in the United States, you're probably below the thresholds where cookie consent is legally required. Probably. That's not a guarantee, the landscape shifts, and I'm not the person to make that call for your business.

But the better reason to do this doesn't have much to do with the law. You've got scripts on your site handing information about your visitors to companies they've never heard of. Telling them, and giving them a real choice about it, is how you'd want to be treated. It's the same instinct behind a site that loads fast, works on a phone, and tells you what the business actually does. Small decisions that add up to whether someone trusts you. Consent matters.

Silktide Consent Manager is a genuinely good free tool for this. If you're US-based, you want something straightforward, and you don't need heavy customization, you can have it running in an afternoon using the wizard. No subscription, no vendor lock-in, and it's yours to modify.

A cookie banner is a small detail. Every detail of your website adds up, and a cohesive experience is representative of what your business is like. If that's the kind of website you want, Let's Rapp.

Let's Stay Connected!

Written By Henri Rapp

Hi, I'm Henri Rapp, a creative director and web designer based in Cleveland. What makes a website work is actually simple. Be obvious about what you do. Make it easy for a visitor to find and trust you fast. Give them a clear next step. No templates, no stock photos, just a site that authentically sounds and looks like you.

    Submission of forms is considered an agreement to my privacy policy.

    More Related Insights