$5,000
per violation in statutory damages, no proof of harm required
SiteTrust Consent · Data & Privacy
A 1990s California wiretapping law is being used against everyday business websites: $5,000 per violation, no proof of harm required, and the tools at issue are ones nearly every site runs: analytics, ad pixels, chat, session recording. SiteTrust Consent makes your site consent-first: trackers off until the visitor says yes, policies that match reality, and the evidence to show it.
Included in every Trusted Site plan, from $299/yr.
$5,000
per violation in statutory damages, no proof of harm required
4,000+
known web-tracking suits by mid-2026, up from about 600 in early 2025
Aug 2026
EU AI Act chatbot-disclosure obligations take effect
1
visitor from California is all it takes, wherever your business is
The Hidden Risk
Businesses learn about this risk the week a demand letter lands. Serial claimants and plaintiff firms scan sites with automated tools, then send letters by the thousands.
Analytics, ad pixels, live chat, session recording: if they load before the visitor consents, the wiretap theory attaches. It is not about doing something exotic. It is the default setup.
The legislative fix collapsed in committee this summer. GDPR and state privacy laws keep layering on. A banner you set once and forget is a policy already going stale.
How It Works
Not another cookie banner. A consent layer built the way the demand letters read, with the defaults that matter and the records to back them up.
01 · Ask first
Trackers stay off until your visitor says yes. Opt-in by default, equal buttons, no dark patterns: the configuration that matches how the law is actually being enforced.
02 · Block by default
Curated blocking for the trackers that matter most, plus manual script control for everything else. What should not fire, does not.
03 · Keep the receipts
Every consent, timestamped and stored. When someone asks what your site did and when, you answer with records, not recollection.
04 · Policies that keep up
Privacy and cookie policies maintained under attorney supervision, updated as the law moves, so what your policy says matches what your site does.
Every SiteTrust Consent site gets the evidence report: we test your site the way a plaintiff's tool would, and put the results on record.
Before
What loads before anyone clicks: the exact question a demand letter asks.
After
What loads only after the visitor says yes: demonstrable, dated, repeatable.
On record
A dated report you can hand to counsel, a partner, or a carrier. Renewed on your plan's cadence.
Every consent tool on the market discloses cookies. None discloses AI. SiteTrust Consent can tell your visitors when AI is in the room: chatbot disclosure where EU AI Act and state transparency rules expect it, on the surface your visitors already see. One layer: permission asked, AI disclosed. The same banner that keeps trackers off until consent also names the AI your site uses, so the visitor is not guessing and you are not explaining it after the fact.
In Every Plan
It is not an add-on. Every Trusted Site plan runs consent-first. Deeper plans add more sites, geo modes, dashboards, and continuous scanning.
$299/yr or $30/mo
Consent-first banner, records, annual evidence report: 1 website.
$849/yr or $85/mo
Geo modes, Consent Mode v2, analytics dashboard, quarterly evidence reports: 3 websites.
$1,650/yr or $165/mo
Continuous tracker scanner, full evidence archive, priority updates: 5 websites.
Technical Integration
Everything a developer or assessor needs to verify the implementation.
SiteTrust Consent sets all four Consent Mode v2 signals on every page load — ad_storage, analytics_storage, ad_user_data, and ad_personalization. Default is denied before any tag fires. On the visitor's choice, all four update immediately.
The consent default fires as the very first operation — before DOM ready, before config fetch, before any observer. No Google tag can load before the visitor has made a choice.
Install by adding one script tag to the site head, before Google Tag Manager. Works on WordPress, Shopify, Squarespace, Wix, Webflow, and any custom HTML site. GTM installation is also supported using the Consent Initialization trigger.
Every visitor choice produces a timestamped record with: categories selected or declined (analytics, marketing, functional), choice timestamp in ISO format, banner version, and a unique consent ID. Records are stored in localStorage and accessible to the visitor at any time via the Privacy Choices button.
SiteTrust Consent ships in basic mode by default — trackers are blocked until the visitor makes a choice. Advanced mode, where Google tags send cookieless pings before consent, is available on request.
Geo consent modes — applying different consent defaults based on visitor region — are available on Verify and Audit plans. EEA visitors receive a stricter default; non-EEA visitors can be configured separately.
Works with WordPress, Shopify, Squarespace, Wix, and Webflow: one snippet, guided setup, and an evidence test before you are done.