Cookie policy for a Squarespace or Wix website
Cookie policy and consent settings for a Squarespace or Wix site, drafted with the privacy notice for the site owner, £595, five working days.
Cookie policy for a Squarespace or Wix website
Buy now, £595Squarespace and Wix sites set the platform's cookies, which the owner cannot change, offer a built-in consent banner that is off or set to the wrong mode by default, and acquire trackers through apps, embedded content and code the owner pastes in without thinking of it as code. The policy lists what the site sets, the banner is configured so that non-essential cookies wait for consent, and the owner learns what the platform's banner can and cannot control. The cookie notice, the privacy notice and the guidance on configuring consent are drafted for the business for £595, fixed, in five working days.
Who this is for
Businesses in England and Wales with a website on Squarespace, Wix or a similar hosted builder, whose banner was switched on once and never looked at again.
What matters in a Squarespace or Wix cookie policy
What the platform sets and what the owner cannot change
A hosted builder sets its own cookies for sessions, security, the cart and checkout where there is commerce, and its own analytics, which the platform documents and the owner cannot remove, and the cookie notice should list them from the platform's published list by category (strictly necessary, functional, analytics, marketing) with name, purpose, provider and duration; the policy should say which cookies the platform controls and which the owner has added, because the owner answers for both but can configure only the second, and a visitor who asks why a cookie is set should be able to find it in the notice.
The built-in banner, what it does and what it does not do
Consent must come before any non-essential cookie or similar technology is set, under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, and both platforms offer a banner that can be set to require consent before their own non-essential cookies and compliant integrations load, but the banner is off by default on one platform and set to a notification-only mode on the other, neither blocks third-party scripts the owner has injected, and the reject option is not always as prominent as accept; the guidance covers switching the banner to the mode that blocks, giving reject equal prominence, restricting the banner's appearance to the regions that need it, and testing that the analytics and marketing cookies wait, because the platform's default is what the regulator's letters to site owners complain of.
The apps, embeds and injected code that add trackers
Form apps, booking widgets, chat tools, review feeds, embedded videos and maps, social feeds, and the advertising and analytics tags the owner adds through the platform's code injection or header fields each set cookies and pass the visitor's data to their providers before consent, outside the platform's banner, and the policy should identify each; the guidance explains which can be made to wait for consent (through the provider's consent mode or a third-party consent tool the platform supports), which can be replaced with privacy-enhanced versions, and which should be removed, because an embedded video that loads a tracker on the home page undoes the banner.
The cookie notice and the audit for a hosted site
Building the cookie notice starts with an audit of the live site: each page type is visited in a logged-out browser, first with consent refused and then with it accepted, because the apps differ by page, and the result is combined with the platform's documented list; the notice is regenerated whenever apps are added or removed, the pack supplies the notice from the audit with a repeatable procedure, and the privacy notice cross-refers to the cookie notice, so that the owner maintains one list.
Consent records, withdrawal and the settings that keep the site lawful
The consent mechanism should record each visitor's choice with a timestamp where the platform's banner or the consent tool supports it, should let the visitor change or withdraw consent later (a footer link or a floating control), should re-ask after a stated period, and should respect the choice across the site; the Data (Use and Access) Act 2025 adds an exception for some analytics cookies on an opt-out basis once in force and where the conditions are met, which the platform's own analytics may satisfy and third-party analytics usually do not; the guidance sets out the configuration for both positions.
The privacy notice alongside and the platform as processor
Hosting the site, the platform processes visitors' and customers' data as the owner's processor under the terms (with their data processing addendum) accepted on sign-up, in data centres outside the United Kingdom that need the Article 46 safeguards under the UK GDPR, while using some data for its own ends as a controller; the privacy notice explains that alongside the forms, any commerce, the marketing under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 and the other processors, and it states the registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018; the pack includes it.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our site has the platform's cookie banner switched on. Is that enough?
Only if it is in the mode that blocks non-essential cookies until consent, with reject as prominent as accept, and only for the cookies and integrations it controls. Injected code and most embeds sit outside it. The guidance covers the settings and the test.
We pasted a tracking tag into the header. Does the banner cover it?
It does not. Code injected into the header loads before and outside the banner. It needs the provider's consent mode or a consent tool the platform supports, or it should come out. The audit finds it.
Can we use the platform's own analytics without consent?
Under the 2025 Act's exception for statistics-only cookies with an opt-out, once in force and where the platform's analytics meet the conditions, possibly. Third-party analytics usually do not. The guidance explains both positions.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Cookie policy for a WordPress website
- Consent banners: what has to be in one
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.