Cookie policy for a Squarespace or Wix website

Cookie policy and consent settings for a Squarespace or Wix site, drafted with the privacy notice for the site owner, £595, five working days.

Share
Buy now, £595

Squarespace and Wix sites set the platform's cookies, which the owner cannot change, offer a built-in consent banner that is off or set to the wrong mode by default, and acquire trackers through apps, embedded content and code the owner pastes in without thinking of it as code. The policy lists what the site sets, the banner is configured so that non-essential cookies wait for consent, and the owner learns what the platform's banner can and cannot control. The cookie notice, the privacy notice and the guidance on configuring consent are drafted for the business for £595, fixed, in five working days.

Who this is for

Businesses in England and Wales with a website on Squarespace, Wix or a similar hosted builder, whose banner was switched on once and never looked at again.

What the platform sets and what the owner cannot change

A hosted builder sets its own cookies for sessions, security, the cart and checkout where there is commerce, and its own analytics, which the platform documents and the owner cannot remove, and the cookie notice should list them from the platform's published list by category (strictly necessary, functional, analytics, marketing) with name, purpose, provider and duration; the policy should say which cookies the platform controls and which the owner has added, because the owner answers for both but can configure only the second, and a visitor who asks why a cookie is set should be able to find it in the notice.

The built-in banner, what it does and what it does not do

Consent must come before any non-essential cookie or similar technology is set, under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, and both platforms offer a banner that can be set to require consent before their own non-essential cookies and compliant integrations load, but the banner is off by default on one platform and set to a notification-only mode on the other, neither blocks third-party scripts the owner has injected, and the reject option is not always as prominent as accept; the guidance covers switching the banner to the mode that blocks, giving reject equal prominence, restricting the banner's appearance to the regions that need it, and testing that the analytics and marketing cookies wait, because the platform's default is what the regulator's letters to site owners complain of.

The apps, embeds and injected code that add trackers

Form apps, booking widgets, chat tools, review feeds, embedded videos and maps, social feeds, and the advertising and analytics tags the owner adds through the platform's code injection or header fields each set cookies and pass the visitor's data to their providers before consent, outside the platform's banner, and the policy should identify each; the guidance explains which can be made to wait for consent (through the provider's consent mode or a third-party consent tool the platform supports), which can be replaced with privacy-enhanced versions, and which should be removed, because an embedded video that loads a tracker on the home page undoes the banner.

Building the cookie notice starts with an audit of the live site: each page type is visited in a logged-out browser, first with consent refused and then with it accepted, because the apps differ by page, and the result is combined with the platform's documented list; the notice is regenerated whenever apps are added or removed, the pack supplies the notice from the audit with a repeatable procedure, and the privacy notice cross-refers to the cookie notice, so that the owner maintains one list.

The consent mechanism should record each visitor's choice with a timestamp where the platform's banner or the consent tool supports it, should let the visitor change or withdraw consent later (a footer link or a floating control), should re-ask after a stated period, and should respect the choice across the site; the Data (Use and Access) Act 2025 adds an exception for some analytics cookies on an opt-out basis once in force and where the conditions are met, which the platform's own analytics may satisfy and third-party analytics usually do not; the guidance sets out the configuration for both positions.

The privacy notice alongside and the platform as processor

Hosting the site, the platform processes visitors' and customers' data as the owner's processor under the terms (with their data processing addendum) accepted on sign-up, in data centres outside the United Kingdom that need the Article 46 safeguards under the UK GDPR, while using some data for its own ends as a controller; the privacy notice explains that alongside the forms, any commerce, the marketing under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 and the other processors, and it states the registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018; the pack includes it.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Only if it is in the mode that blocks non-essential cookies until consent, with reject as prominent as accept, and only for the cookies and integrations it controls. Injected code and most embeds sit outside it. The guidance covers the settings and the test.

We pasted a tracking tag into the header. Does the banner cover it?

It does not. Code injected into the header loads before and outside the banner. It needs the provider's consent mode or a consent tool the platform supports, or it should come out. The audit finds it.

Under the 2025 Act's exception for statistics-only cookies with an opt-out, once in force and where the platform's analytics meet the conditions, possibly. Third-party analytics usually do not. The guidance explains both positions.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.