GDPR · Swiss FADP · Google Consent Mode v2

Cookie consent
that proves itself.

https://www.example.ch We use cookies Reject Accept all Before-consent check 18 pages · 14 cookies · 6 hosts 92 No tracker contacted before consent Every cookie documented 1 vendor policy changed — review

One script on your site. A banner that blocks tags until visitors choose, a scanner that checks your site actually does, a privacy policy that writes itself, and a consent log you can hand to an auditor.

Cookie scanner Script blocking Consent Mode v2 Privacy policy Imprint & terms Privacy requests Consent log Vendor checks Processing register Breach register Accessibility scan Trust page Consent API Client portal Agency reports EN · DE · FR · IT

Free · no account needed

Check your site for free.

Enter a domain and a headless browser opens it without touching the banner. You get a grade and the list of trackers it contacted before anyone consented.

Up to 5 public pages, about a minute. Full cookie list with a free account.

Free document generators. Imprint, privacy policy, cookie policy, terms, right of withdrawal, accessibility statement and newsletter consent texts. Four languages, no account. Non-binding drafts with no legal validity, which is exactly what the paid platform fixes.

Open the free tools

The stack

Everything between your visitor and your analytics tag.

A banner alone is not compliance. The widget is the visible part; the scanner, the policy generator and the consent log are what make it hold up when someone asks.

Automated cookie scan

A headless browser crawls up to 20 pages of your site without ever consenting, and reports every cookie and third-party host it meets. Rescans run on a schedule.

One-click classification

Findings are matched against a curated signature list and the Open Cookie Database, so each cookie arrives with a provider, a category and a description. Import them, or let auto-import do it.

Before-consent check

The scan doubles as a blocking test: any non-essential cookie or tracker host that fires before the visitor has chosen gets flagged. It is the single most-audited failure, so it is checked every time.

Script blocking

Mark a tag with a category and the browser leaves it inert until that category is granted. Revoke consent and it is blocked again, with its cookies cleared. Or let the platform inject scripts for you.

Google Consent Mode v2

Defaults are pushed before any Google tag loads, and an update follows every decision. Standard category names map automatically; custom ones map to whichever signals you choose.

Privacy policy that stays current

Generated in English, German, French and Italian from what you documented, in a GDPR or GDPR + Swiss FADP variant. Host it here or embed it on your page; the cookie list updates itself.

Consent log

Every decision is recorded with the config version it was made against. Look up a receipt, watch the accept rate, and answer "show me the consent record" with an actual record.

Vendor checks

For every third-party service you use, the platform finds its privacy policy, terms and DPA, assesses them for GDPR and FADP friendliness, and tells you when a document changes.

Processing register

An Article 30 register of processing activities, built from what you already documented: categories become purposes, providers become recipients, cookie lifetimes become retention periods.

Every other legal page

Imprint, terms, withdrawal and refunds, shipping, accessibility statement, DPA and sub-processor list, generated from company details you enter once. Hosted, versioned, embeddable, in four languages.

Privacy requests and breaches

A hosted form for access and deletion requests with the 30-day deadline tracked per request, and a breach register with the 72-hour authority clock running from the moment you log it.

Accessibility and trust

An axe-core scan grades your pages against WCAG 2.1 AA so the accessibility statement claims what is true, and a public trust page brings policies, sub-processors and contacts together at one URL.

Consent for every channel

A consent API records proof for newsletter sign-ups, contact forms and registrations in the same log as the banner, and the scan checks your footer actually links the pages the law requires.

Built for agencies

Invite clients to a read-only portal for their site, keep an audit log of who changed what, run DPIA screenings, and get email alerts when a policy is published, a vendor changes its terms or a deadline nears.

Reports in your brand

A compliance report per site as PDF or shareable link, with your agency's logo and colours. Monthly by email if you want it. The check is free for anyone; the fix is one script.

How it works

Three steps. One script. Nothing from a third-party CDN.

01

Add your site

Enter a name and a domain. The first scan starts immediately and comes back with every cookie and host it found, already classified.

02

Review and publish

Import the findings, pick a policy variant, theme the banner, and paste one script tag as the first thing in your <head>.

03

Stay compliant

Scheduled rescans catch new cookies and alert you. The health score tells you at a glance whether anything needs attention.

The whole integration index.html
<script src="https://consent.ampersand.ch/js/ampsand-consent.js"
        data-config="https://consent.ampersand.ch/c/<your-site>.json" defer></script>

Who it's for

For the people who get asked to prove it.

Agencies with many client sites

One team, every client site on a single dashboard. Health scores surface the ones that need work; invitations bring the client in when they want to see for themselves.

Swiss businesses

The revised FADP and the GDPR side by side, with a policy variant that covers both. Four languages out of the box, because your visitors do not all read the same one.

Shops and SaaS running Google Ads

Consent Mode v2 done properly: signals set before the tags load, updated on every decision, and a dataLayer event for your GTM triggers. Conversion modelling keeps working.

Anyone facing a data-protection review

Consent records, a processing register, vendor assessments and a dated policy history. The documents a reviewer asks for, produced from data you were keeping anyway.

For law firms

Put your name on the texts your clients actually use.

Verified legal partners review templates, take review orders, publish jurisdiction packs and keep clients informed. The platform handles distribution and payment.

Verified standard texts

Sign off a template for your jurisdiction and language. Every site using it shows "Reviewed by your firm" instead of a disclaimer, and a changed template invalidates the sign-off automatically.

Review orders

Customers post what they need. You send an offer with price and delivery time, they accept and pay through the platform, you deliver on the order thread, and the payout lands in your Stripe account.

Delegated access

Work directly in the client's account with counsel access limited to legal pages, time-limited and audited, so the reviewed text goes live without copy and paste.

Jurisdiction packs and regulatory notes

Publish your own template variants and short law-change notes targeted by country and site type. Clients are alerted, and can order a review in one click.

Philosophy

What we believe about consent.

A short list of things we hold to. If any of them ever stop being true, the product has stopped doing its job.

A banner is not compliance.

Plenty of sites show a banner and still fire Analytics on the first byte. That is why the scanner never consents: what it sees is exactly what a visitor gets before choosing, and that is what we grade.

Nothing loads from someone else's server.

The widget, your configuration and your policy are all served from this platform. No third-party CDN sees your visitors, and there is no extra vendor to add to your own register.

Ask again only when it matters.

Visitors are re-asked when a cookie, provider or category changes, or when their consent expires. Changing a colour or rewording the banner does not reset anyone's choice.

Withdrawing must be as easy as accepting.

Any link or button can reopen the preferences, or a floating button can sit on every page. Revoking a category blocks its scripts again and clears their cookies, no reload required.

Over-declare, never under-declare.

A cookie that is documented but no longer set harms nobody. A cookie that is set but not documented is a finding. The platform errs on the side of listing more, and tells you when it does.

Pricing

Simple plans. Priced per site, not per visitor.

Every plan starts with a 14-day trial. No card required.

Essential

Everything one website needs to be compliant.

CHF 9 per site / month
  • Consent widget, cookie scanner and before-consent check
  • Google Consent Mode v2 and privacy signals
  • Consent log with downloadable receipts
  • Privacy policy and legal pages in 4 languages, hosted and embeddable
  • Privacy request form with the 30-day deadline tracked
  • Self-service consent withdrawal page
  • Email alerts and weekly re-scans
  • Up to 3 team members
Most teams pick this

Professional

For companies whose data protection reaches past the website.

CHF 29 per site / month
  • Everything in Essential
  • Vendor register including offline processors — payroll, CRM, accounting and anything you use away from the website
  • Processing register (Art. 30) with your own manual activities
  • DPIA screening and the breach register with the 72-hour clock
  • Accessibility scans against WCAG 2.1 AA
  • Consent API for newsletters, contact forms and sign-ups
  • Public trust page and the DPA and sub-processor pages
  • Audit log and vendor change alerts
  • Unlimited team members

Enterprise

For agencies and compliance teams running many sites.

Custom annual
  • Everything in Professional
  • White-label reports, branding and monthly report emails
  • Client portal: read-only access for the site owner
  • SSO / SAML and configurable audit retention
  • Custom DPA and data residency options
  • Priority support

Just need a document? The free generators produce a non-binding draft in a minute.

Prices exclude VAT. Billed per site, cancel any time from the billing portal — the trial never charges you.

FAQ

Quick answers.

Things people ask before they sign up. The full integration guide is waiting inside once you do.

Does it work with my framework or CMS?

Yes. The widget is one script tag and does not depend on anything else on the page. It runs the same on plain HTML, WordPress, Shopify, Next.js, Nuxt and anything else. It renders inside a shadow DOM, so your site's styles never interfere with it.

How does script blocking actually work?

Give a tag a non-JavaScript type and a category attribute. The browser treats it as inert, not even downloaded, until that category is granted, when the widget activates it. Alternatively, attach the script to a provider in the platform and let the widget inject it. Single-page apps can check the granted state from their own code and listen for the consent event.

When are visitors asked again?

When the configuration version changes, which happens automatically when you add or remove cookies, providers or categories, or after the consent-expiry period you set. Cosmetic changes such as colours and wording do not re-ask.

What happens when a new cookie shows up on my site?

A scan flags it as undocumented and you are alerted. With auto-import on, it is added to your inventory automatically. Undocumented cookies drop the site's health score until they are dealt with.

What if a documented cookie is no longer used?

Nothing breaks. It stays listed until you remove it. Over-declaring is the safe side; tidy it up when convenient.

Does the widget work behind a cache or CDN?

Yes. Your configuration is served with revalidation, so setting changes appear on the next normal page load without a hard refresh, and unchanged configs cost a tiny 304.

Can I fully theme it?

Colours, fonts, radius, position, an optional blocking overlay, and glass and gradient effects are all in the Appearance tab. Every text the visitor sees can be overridden per language.

Which legal pages can you generate besides the privacy policy?

Imprint, terms and conditions, withdrawal and refund policy with the model form, shipping and payment information, a standalone cookie policy, an accessibility statement, a data processing agreement, a sub-processor list with change notifications, and newsletter consent texts. Tell us your site type and country and we show which of them are required. Every generated text is a template: have it reviewed before relying on it, or request a partner lawyer review from inside the app.

Which languages does the privacy policy come in?

English, German, French and Italian for the generated text, in a GDPR variant and a GDPR + Swiss FADP variant. You can also supply your own policy text per language and let the platform drop the always-current cookie list into it.

Do you store personal data about my visitors?

The consent record stores the decision, the categories granted and the configuration version it was made against, so it can be produced as a receipt. The widget stores the visitor's choice in their own browser.

How do I close my account?

Settings, then Delete account. We confirm with your password, then erase your sites, scans and consent records.

Find out what your site does before anyone clicks.

The first scan takes a few minutes and costs nothing. So does every scan after that.