Comparison · cookie banner and consent
Cookiebot and our CMP do the same core job: stop trackers from firing before consent and remember the guest's answer. They differ in how that work is evidenced and how it is sold. We name both differences plainly, including where the vendor is stronger.
Facts about Cookiebot were captured from cookiebot.com and usercentrics.com on 5 and 12 September 2026; each one carries a link and a date. www.cookiebot.com/en
No card · the base tier is free · lifting the scanner limits costs $9/mo
A guest from the EU opens your site for the first time, and the site runs analytics, a pixel and an embedded video. Here is what happens on each side — first through the guest's eyes, then through the owner's.
What the guest sees, and what has already happened to the trackers by then.
Vendor · Cookiebot
Us · Cenaly.com
What you configure it with, what you can evidence, and what stays in your hands.
Vendor · Cookiebot
Us · Cenaly.com
For a standalone consent vendor the banner is the product, and its dashboard is built around the scanner and reports. For us the banner is part of the same account where the site, the orders and the shift live — which creates a few links a separate service cannot have.
Once a week the server checks whether our loader is still on the site. A "was there → gone" transition becomes a card in the work chat with a link to the website section, deduplicated for a week. Without it a broken install stays silent until you notice the leads have stopped.
The cookie banner is raised by the same loader as the chat, the callback and the order widget. There is no separate snippet to remember to restore after a theme change.
A threshold of 18 or 21, confirmation by button or by birth year, memory for 1 to 365 days. The gate stands in front of the banner: until the age is confirmed the guest sees neither the site nor the cookie question. The birth year is never stored, and a refusal is deliberately not remembered.
Nothing to paste at all: the loader is baked into the template, and consent, legal documents and chat are enabled by default on a new site.
A public tool shows what runs on a page and whether a banner is present — without an account and without asking for an email.
For a consent banner installation matters more than for any other widget: put it in the wrong place and "blocking before consent" stops being blocking.
| What we compare | Cookiebot | Cenaly.com |
|---|---|---|
| Where the tag goes | Installation is presented as three steps plus a Consent Mode v2 course; no precise requirement for the tag's position in the markup appears on the captured pages. source · 2026-09-05 | First script in the head, with no async and no defer. Through the shared loader consent is raised first among our widgets, but it will not outrun third-party analytics nailed higher in the head — for strict "before consent" the tag goes in separately and first. |
| Installing through Google Tag Manager | Integration with Consent Mode v2 and tags is stated; a separate walkthrough of installing the banner itself through GTM does not appear on the captured pages. source · 2026-09-05 | Technically it works, but there is little point: GTM loads asynchronously while the banner has to execute before third-party analytics. On top of that our install check never sees a GTM tag — it reads the markup rather than executing the page. |
| A single-page app | Behaviour during navigation without a reload is not described on the captured pages. (not stated on the pages we captured) | The banner is redrawn when changes — that is watched by an observer. The guest's decision is kept in the browser and survives transitions; excluded pages are set by path masks. |
| A site with Content-Security-Policy | The captured pages carry no CSP requirements and no host list. (not stated on the pages we captured) | The loader copies its nonce onto both the banner and the lazy age gate. Banner styles live in a Shadow DOM and need style-src 'unsafe-inline'. If the lazy gate does not arrive, there is no gate: keeping someone's site closed because of our own hiccup is not acceptable. |
| What no in-page banner can intercept | The limits of interception are not named on the captured pages. (not stated on the pages we captured) | We name them plainly: cookies set by the server through Set-Cookie, scripts that executed before our tag, and service workers are not intercepted. That is a limit of browser-side CMPs as a class, not of our implementation. |
An empty cell on the left describes our snapshot of the vendor's marketing pages: its documentation almost certainly says more. For a banner this is especially worth checking before you choose.
On the consent market the bill usually goes per domain and per scanning volume. Our banner is attached to a location of the account, and the paid extension lifts the scanner and log-retention limits.
| What we compare | Cookiebot | Cenaly.com |
|---|---|---|
| The banner itself | The price is not shown on the homepage and leads to a pricing page; free access is framed as a 14-day trial, and on 12 September 2026 the tiers gained names — Solopreneur, Emerging Business, Advanced Business Enterprise. source · 2026-09-12 | Free permanently rather than for a trial: banner, blocking, four categories, region modes, Consent Mode v2 and the log are in the base tier on any plan. |
| Scanning volume | The scanner is presented as the first-screen magnet; its limits are not named on the homepage and live on the pricing page. source · 2026-09-05 | Free — 10 pages once a month. The extension — up to 30 pages weekly, $9/mo. |
| Consent log retention | The log retention period is not named on the captured pages. (not stated on the pages we captured) | Free — 3 months; with the extension — 12 months. The log is anonymous: no IP and no precise User-Agent. |
| Number of domains | A separate Cookie Banner Cost Calculator appeared in the homepage footer on 12 September 2026 — the cost is computed from site parameters. source · 2026-09-12 | The banner is configured per location of the account. Several locations mean several sets of settings in one dashboard; there is no separate "per domain" charge. |
Cases where the honest answer is "take theirs". Below is what we do not have, and we will not pretend we do.
The vendor states ISO 27001 and ISO 27701, HIPAA readiness and Google-certified CMP status (captured 2026-09-12). We hold no such certifications and will not claim them. If the client's security team asks for a certificate, that settles it — not in our favour.
If your advertising partners require the IAB Transparency and Consent Framework, our banner will not do: we do not support it. Check the vendor's current TCF status with them.
An agency needs a dashboard organised around domains and clients. Ours is organised around a location of an account — convenient for an owner with several venues, inconvenient for a contractor with a hundred sites.
Consent vendors list their regional and legal coverage explicitly. We give five region modes and a per-country rule, but we publish no "these laws are covered" list — and we will not pass modes off as a legal opinion.
Our CMP is part of an account where you also run the site, the orders and the shift. If everything else lives in other systems, there is no reason to open an account for a banner alone: the shared-dashboard benefit never arrives.
Set-Cookie, scripts that executed before our tag, and service workers are not intercepted — that is the limit of browser-side CMPs as a class. Every claim above was captured from these pages on the date shown. The vendor may have changed since — the links go to the original, check for yourself.
We do not quote third-party reviews, logos or screenshots, and we never present a vendor's numbers as our own. Found a discrepancy with the vendor's page? Tell us and this page gets corrected.
Yes, and it starts before the config loads: the engine is installed synchronously, intercepts cookie writes, neutralises injection of block-listed scripts and replaces embedded videos and maps with a placeholder. After consent the scripts are re-injected. Server Set-Cookie, scripts that executed before our tag, and service workers are not intercepted.
First script in the head, without async or defer, above your analytics. Through the shared loader the banner is raised first among our widgets, but a third-party counter nailed higher in the head will not be outrun — and cannot be stopped retroactively.
Free: the banner, blocking, four categories, region modes, Consent Mode v2 and the log, plus a 10-page scan a month and 3 months of log retention. The extension — $9/mo — raises the scan to 30 pages weekly and the log to 12 months.
No, there is a plugin. It works in two modes: standalone, where the page itself supplies the config and no account is needed — but no consent log is written — and bound to a location through a one-off site token, where the log works as usual.
The page's language: it reads or the tag attribute, and the labels arrive as a pack from the CDN — 45 of them. Your own texts are set per language. The age gate, however, speaks only four languages, and you write its wording yourself.
With the public check tool: it shows the trackers and whether a banner is present on the given page, without signing up and without an email. Inside the account the same job is done by the site scanner, whose results feed the live cookie declaration table.
More detail — per-platform installation, settings and troubleshooting — in the docs. Installation guide →
The widget page explains how it works on our side, the docs cover installation and setup, the hub lists the other eleven.
Sign up, put the banner tag first in the `head` and set up the region modes — the base tier is free, and the extension is only needed once you hit the scanner limits.
Get started freeNo card · the base tier is free permanently · this is not legal advice