What a cookie policy covers
A cookie policy tells visitors which cookies and similar technologies (local storage, pixels) your site uses, what each one is for, who sets it, how long it lasts, and how to accept, refuse or delete them. The ICO’s cookie guidance sums up the UK rules: tell people the cookies are there, explain what they do and why, and get consent. Cookies that are strictly necessary for a service the user asked for, like keeping them logged in or a shopping basket, don’t need consent.
How to use this generator
- Tick the kinds of cookies you use: strictly necessary, preferences, analytics and marketing.
- Build the cookie table. One click adds suggested rows for Google Analytics 4 (from Google’s cookie documentation) or Cloudflare bot protection (from Cloudflare’s cookie list). Edit every row to match your setup; replace <container-id> with your own ID.
- Describe your consent banner in your own words. The consent section only appears if you use cookies beyond strictly necessary ones.
- The draft links to the cookie help pages for Chrome, Firefox, Safari and Edge, and to Google’s Analytics opt-out add-on when your table includes Google Analytics.
A template is a starting point
A cookie policy is only as accurate as its table. Check your site’s real cookies after every new script or tool, update the effective date, and have a qualified lawyer review the policy and your banner together, since the rules differ between countries. See our own privacy policy and terms for plain-English examples.
Also draft a privacy policy and terms of service, and tag campaign links with the UTM builder so your analytics data is worth the cookies.