We measure our own site, and your visitors are a different question
Our marketing site measures itself. The widget on your site does not measure anyone.
Last updated
What runs where
This site — the one you are reading — runs Google Analytics, and nothing is requested from any Google host until a visitor presses Accept. Somebody who declines loads nothing, and somebody who never answers loads nothing either. The widget a customer embeds is a different artefact on a different page and contacts nobody but us. Keeping those two sentences apart is the entire subject here, because collapsing them is the easiest available lie in this category.
Why not the recommended arrangement
Google's own advice is to load the tag straight away in a denied state and switch it on when somebody accepts. That still contacts Google, and it still sends a pingback for every visitor who closes the banner without answering. As a reading of the law it is defensible. As a thing to run on a page arguing that the product being sold contacts nobody, it is indefensible, so we took the version that costs us data instead.
What we look at it for
Which pages people read, what they were reading before, and roughly where in the world they were. That is the whole of it. It has never been joined to a customer account and there is nothing on our side that could join it — the analytics property knows about visits to a marketing site and the product database knows about people who signed up, and the two have no key in common.
The banner's own record is not a cookie
What remembers your answer is a single key in the browser's own storage. It goes to no server, ours included, and there is nothing in it but the answer. A consent banner whose own mechanism required consent would be a joke at the reader's expense, and it is a joke a surprising number of sites are currently telling.
Why say any of this
Because the alternative was to leave two true sentences next to each other and let readers draw the wrong conclusion from them, which is a thing a vendor can do without ever writing anything false. If our position is that a widget you embed should be able to state what it does, the site selling it does not get an exemption.
What this is evidence from
lib/analytics.ts- the gate itself, and the reasoning for refusing the load-then-deny arrangement recommended by the vendor
components/ConsentGate.tsx- the banner, the way an acceptance is stored, and the control that takes it back
app/privacy/page.tsx- the same distinction written where somebody looking for it would go first
- 0 cookies
- set by a widget on a customer's site, which is the number this piece exists to keep separate from our own