Cookie Policy
Last updated: September 17, 2026
1. What this policy covers
Consent Pro is a consent management platform. It is unusual among the things this kind of policy normally describes, because it is itself the mechanism by which trackers are controlled. That makes the scope boundary the most important part of this document.
This policy describes two things:
- The storage Consent Pro itself places on a visitor's device when the Consent Pro script runs on a website operated by one of our customers — the record of that visitor's own consent choice, and the small amount of state needed to make the banner and preference panel work.
- The cookies and similar technologies used on our own web properties — the Consent Pro marketing site and our documentation, both on the consentpro.com domain, and the Consent Pro application, which is not (see §6). The named, itemised inventory for consentpro.com lives in a companion Cookie Declaration, generated through Consent Pro's own product for consentpro.com specifically; §6 of this policy describes the categories used across our own properties, including our documentation, and explains the application's different scope.
This policy does not describe:
- The cookies, pixels, tags, or other trackers set by the website you are visiting. Those belong to that website's operator, who decides which trackers to run and is responsible for describing them. Their own cookie notice — which may itself have been generated using Consent Pro — is the place to look.
- Anything set by third parties whose content that website has embedded.
If you arrived here from a banner on someone else's website, the second list is almost certainly what you were looking for, and the operator of that website is the right place to ask.
2. Who is responsible for what
The answer differs depending on which of the two surfaces above is in play. This matters because it determines who you exercise your rights against.
On a customer's website. The website operator decides that Consent Pro will run, configures the banner, and determines which tracker categories exist. They are the controller. Finsweet operates Consent Pro on their instructions as a processor. Requests about a consent record captured on their site should go to them; we will support them in responding, but we do not act on the record without their instruction.
On our own properties (the Consent Pro website, application, and documentation). Finsweet is the controller.
3. Storage Consent Pro places on a visitor's device
Consent Pro's own storage is limited to what is needed to remember your choice and to apply it on subsequent pages. It is not used for analytics, profiling, advertising, or measurement of any kind, and it is not read on any site other than the one that set it (or, on a Webflow staging address, that staging address).
Consent Pro currently runs one of two script generations, depending on when the website operator installed or last updated it; both remain in active use, so this section describes both. Nothing described below is set before you interact with the banner.
Current version:
| Name | Type | Purpose | Party |
|---|---|---|---|
fs-consent | Cookie | Stores your consent choice — a record ID generated for that choice, your per-category selections, when the choice was made, and a coarse region signal — so the banner does not reappear and your choice is applied to trackers on each page. | First party |
Legacy version (still running on websites that installed Consent Pro before the current version was released, including websites on legacy or Lifetime plans that have not updated their installation):
| Name | Type | Purpose | Party |
|---|---|---|---|
fs-consent | Cookie | Stores a record ID and your per-category selections. | First party |
fs-consent-updated | Cookie | Records that your choice has been updated since it was first made. | First party |
fs-consent-[signal] (e.g. fs-consent-analytics_storage) | Cookie | Where the website operator uses Google's consent-signaling framework, records the granted or denied state for each signal the operator has configured, so it can be passed to that framework. Only set for signals the operator actually uses. | First party |
Legal basis / exemption. Consent Pro uses this storage solely to remember and apply the privacy choice you have made. We treat that storage as strictly necessary for providing that preference functionality and therefore do not use a second consent request merely to remember your consent decision. The storage is not used for analytics, advertising or profiling. Website operators remain responsible for the requirements that apply to their own deployment under applicable local law. We do not ask for consent to store your consent — that would be circular. We do tell you about it, which is what this section is.
3.1 How long the consent record lasts
By default, your choice is remembered for 365 days from when you made it. The website operator can set this to any period from 1 to 365 days through the Consent Pro dashboard. After that period, the stored choice expires and the banner will ask again, unless a new choice has been made in the meantime.
4. The consent record we hold on our servers
This is not a cookie, and most cookie policies would not mention it. We mention it because it would be misleading not to: when you make a choice through a Consent Pro banner, a record of that choice is also sent to us and stored, so the website operator can demonstrate that consent was obtained as Article 7(1) GDPR requires of them.
What the record contains. The full, authoritative field list is set out in our Privacy Policy (§3.2) — we do not repeat it here, to avoid two descriptions of the same record drifting apart. In short: the record links the same record ID stored in your fs-consent cookie to your choice, to when and where it was made, and to a separate, server-generated pseudonymous identifier — two distinct identifiers, not one; see below for why.
Custom-endpoint forwarding. Where a website operator configures a custom storage endpoint, we forward a subset of this record to that operator-controlled destination: the record ID, the action taken, your per-category choices, the literal banner text, the page URL, and the user agent string. We do not forward the pseudonymous identifier, the timestamp, the region signal, or any other field described in the Privacy Policy — those stay only in Finsweet's own storage. This is a real, separate data flow to a destination Finsweet does not control, and the operator — not Finsweet — determines what that endpoint does with the data once received.
About that identifier. It is derived by hashing your IP address together with a secret value we hold, and truncating the result. Your IP address is not stored. The identifier is pseudonymous, not anonymous — because we hold the secret, the identifier remains linkable in principle, and we treat it as personal data. We say this plainly because a number of vendors in this market describe equivalent constructions as "anonymous", and that is not accurate.
Where it is stored. Cloudflare R2, in the Western Europe region.
How long we keep it. Our retention policy is to keep each consent record for five years from that record's own date — the date of the consent interaction it reflects. Where you later make a new choice, that choice is recorded as a separate consent record with its own five-year period; an earlier record's retention period is not extended or reset by a later one. We have not yet implemented an automated mechanism that deletes a record once this period elapses — until we do, a record is not automatically deleted at the five-year mark. The hashing secret used to derive the identifier does not currently rotate; because the identifier is IP-derived rather than tied to a persistent client-side token, it changes whenever a visitor's IP address does (for example, when the visitor changes networks or their public IP address is reassigned), regardless of the secret — the non-rotating secret does not make the identifier stable for a given visitor over the retention period, only for repeat records from the same IP address.
Access and deletion. Consent Pro does not offer end users a self-service route to locate, export, or delete an individual consent record. Where the website operator (the controller) instructs us, identifying the record including by its Consent ID, we access or export that specific record. We do not correct or edit a consent record once it has been recorded — a later change in choice is captured as a new record, not an edit to an earlier one. Once a record has been exported, or forwarded to a destination the operator controls, any changes made to that copy are the operator's own and do not change the record we hold. We do not currently support deleting an individual consent record, a visitor's records, or an operator's consent logs, through Consent Pro or via our API. Where an operator needs all of its data removed before the retention period above otherwise applies, we can do so through Finsweet's existing account-level data-deletion process ("Forget Me Finsweet"), which removes all of that operator's data rather than a single record. If you are an end user, contact the operator of the website where you made the choice; they decide whether and how the instruction is given.
5. Global Privacy Control and other opt-out preference signals
Consent Pro automatically detects the Global Privacy Control (GPC) signal transmitted by your browser. Where GPC communicates an opt-out from sale or sharing under applicable law, Consent Pro applies that opt-out to the applicable choices at runtime, including where an earlier stored choice would otherwise permit the affected activity. A website operator cannot disable detection of the signal. Other consent choices continue to be handled according to the banner mode configured by the operator and your valid choices.
On consentpro.com, Finsweet is the website operator, and a qualifying GPC signal is recognized as an opt-out of sale or sharing where applicable to the advertising technology used there — see §6 and Privacy Policy §2.3/§8.
Where a qualifying signal changes what is applied, the banner may display a confirmation that the signal was honoured. That confirmation element is included by default in newly generated Opt-Out and "Do Not Sell" banners, but whether it appears on any particular site depends on that operator's own banner configuration.
What we do not do with the signal. The signal is applied at runtime but is not written into the stored consent record. The practical consequence is that the record does not, on its own, evidence that a signal was received or why non-essential categories were off. We state this plainly rather than imply otherwise; it matches §3.4 of our Privacy Policy and §4.2 of our data processing agreement. If the ingest path begins capturing the signal server-side, this section will be updated to describe the record field.
6. Cookies on our own properties
We use three separate properties. Their storage and consent treatment differ, so each is addressed separately below.
consentpro.com
The named, itemised inventory (cookie name, provider, purpose, category, expiry) is published in a companion Cookie Declaration, generated through Consent Pro's own product and kept current automatically as consentpro.com is scanned. Non-essential storage on consentpro.com requires your consent through the Consent Pro banner. The categories currently in use are:
| Purpose | What it does | Consent required |
|---|---|---|
| Analytics | Helps us understand how the marketing site is used. Provided via PostHog. | Yes |
| Marketing and advertising | Measures the effect of our campaigns on consentpro.com, including conversion measurement and remarketing/retargeting. Provided via Google Ads, Google Tag Manager and Google Analytics (GA4) — see Privacy Policy §2.3 and §8. | Yes |
The Cookie Declaration is the authoritative, current inventory for consentpro.com.
docs.consentpro.com
Our documentation is a separate property from consentpro.com and is not covered by the Cookie Declaration, which covers consentpro.com only. Analytics on our documentation is provided via PostHog in a cookieless, memory-only configuration: it does not set a cookie or use persistent browser storage. Because no cookie or similar storage is involved, we do not treat it as requiring cookie consent under this policy; whether it requires consent on some other legal basis is a question for our Privacy Policy, not this Cookie Policy.
Separately, our documentation site remembers your light or dark theme preference using localStorage (the key vitepress-theme-appearance). This is persistent, first-party browser storage used only for that purpose, and it is not shared with or read by consentpro.com.
The Consent Pro application
The application (the dashboard you use to configure and manage Consent Pro) is not a consentpro.com property: it runs as a Webflow Designer Extension served from Webflow's own webflow-ext.com infrastructure, inside the Webflow Designer interface. It is not included in the Cookie Declaration's scan-based inventory, and it does not set cookies. Finsweet's own code uses browser local storage there for a small amount of interface state, such as remembering that a one-time setup step has already run, and to send Finsweet product-usage analytics through PostHog, identified by your administrator login rather than by an end-user identifier. That analytics storage runs automatically as part of the application; there is currently no in-application control to disable it. Any storage the Webflow platform itself uses to run the Designer Extension, separately from Finsweet's own code, is Webflow's own platform storage, not Finsweet's, and is not addressed by this policy.
Managing these. You can control or clear cookies and similar storage through your browser settings on any of these properties at any time, though doing so may prevent parts of a site from working. On consentpro.com, where the Consent Pro banner offers a preferences control, use it to change or withdraw your choice. On docs.consentpro.com, your browser settings control the theme preference described above. The application does not currently have a separate preference control for its analytics storage.
7. International transfers
Consent records are stored in the Western Europe region. Finsweet is a US company and is not currently certified under the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. Data Privacy Framework, or the Swiss–U.S. Data Privacy Framework. Where an international transfer of personal data is subject to applicable data-transfer restrictions, Finsweet uses appropriate safeguards required by applicable law. For Personal Data processed on a customer's behalf under the Consent Pro Data Processing Agreement, the transfer mechanisms are described in Section 7 and Exhibits B–D of that DPA, including the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the required Swiss adaptations, where applicable. Relevant third-party providers may separately maintain their own lawful transfer mechanisms for processing they carry out in their own capacity.
8. Third parties
Information about Finsweet's service providers and Sub-Processors, including the current list maintained through Finsweet's Trust Center, is available on our Sub-Processors page. This includes the AI vendor (OpenAI), used for tracker categorisation and configuration form-fill assistance. Not every service provider on Finsweet's company-wide Trust Center roster processes Consent Pro data.
9. Your choices and your rights
On a customer's website. Reopen the preferences panel at any time — most operators place a link in the site footer — to change or withdraw your choice. To exercise data protection rights in relation to a consent record, contact the operator of that website; they are the controller.
On our own properties. Use your browser settings to manage the storage described in §6, or the preferences control on the relevant property where one is available. To exercise your rights, contact us at the address below.
Data Protection Officer (GDPR Art. 37): Rohan Ganachari — rohan.ganachari@finsweet.com
EU representative (GDPR Art. 27): Alexandre Iglesias Piñol — Lleida, Catalonia, Spain — alex.iglesias@finsweet.com
UK representative (UK GDPR Art. 27): Rohan Ganachari — Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom — rohan.ganachari@finsweet.com
10. Changes
We will update this policy when the product changes or the law does, and will post the revised version here with a new effective date. Where we make a material change, we provide notice in accordance with Terms of Service §1.5.
11. Contact
Finsweet Inc., 1732 Pettit Avenue, Unit A, Merrick, New York 11566, United States · privacy@finsweet.com