One script on your site. A banner that blocks tags until visitors choose, a scanner that checks your site actually does, a privacy policy that writes itself, and a consent log you can hand to an auditor.
Free · no account needed
Enter a domain and a headless browser opens it without touching the banner. You get a grade and the list of trackers it contacted before anyone consented.
Free document generators. Imprint, privacy policy, cookie policy, terms, right of withdrawal, accessibility statement and newsletter consent texts. Four languages, no account. Non-binding drafts with no legal validity, which is exactly what the paid platform fixes.
Open the free toolsThe stack
A banner alone is not compliance. The widget is the visible part; the scanner, the policy generator and the consent log are what make it hold up when someone asks.
A headless browser crawls up to 20 pages of your site without ever consenting, and reports every cookie and third-party host it meets. Rescans run on a schedule.
Findings are matched against a curated signature list and the Open Cookie Database, so each cookie arrives with a provider, a category and a description. Import them, or let auto-import do it.
The scan doubles as a blocking test: any non-essential cookie or tracker host that fires before the visitor has chosen gets flagged. It is the single most-audited failure, so it is checked every time.
Mark a tag with a category and the browser leaves it inert until that category is granted. Revoke consent and it is blocked again, with its cookies cleared. Or let the platform inject scripts for you.
Defaults are pushed before any Google tag loads, and an update follows every decision. Standard category names map automatically; custom ones map to whichever signals you choose.
Generated in English, German, French and Italian from what you documented, in a GDPR or GDPR + Swiss FADP variant. Host it here or embed it on your page; the cookie list updates itself.
Every decision is recorded with the config version it was made against. Look up a receipt, watch the accept rate, and answer "show me the consent record" with an actual record.
For every third-party service you use, the platform finds its privacy policy, terms and DPA, assesses them for GDPR and FADP friendliness, and tells you when a document changes.
An Article 30 register of processing activities, built from what you already documented: categories become purposes, providers become recipients, cookie lifetimes become retention periods.
Imprint, terms, withdrawal and refunds, shipping, accessibility statement, DPA and sub-processor list, generated from company details you enter once. Hosted, versioned, embeddable, in four languages.
A hosted form for access and deletion requests with the 30-day deadline tracked per request, and a breach register with the 72-hour authority clock running from the moment you log it.
An axe-core scan grades your pages against WCAG 2.1 AA so the accessibility statement claims what is true, and a public trust page brings policies, sub-processors and contacts together at one URL.
A consent API records proof for newsletter sign-ups, contact forms and registrations in the same log as the banner, and the scan checks your footer actually links the pages the law requires.
Invite clients to a read-only portal for their site, keep an audit log of who changed what, run DPIA screenings, and get email alerts when a policy is published, a vendor changes its terms or a deadline nears.
A compliance report per site as PDF or shareable link, with your agency's logo and colours. Monthly by email if you want it. The check is free for anyone; the fix is one script.
How it works
Enter a name and a domain. The first scan starts immediately and comes back with every cookie and host it found, already classified.
Import the findings, pick a policy variant, theme the banner, and paste one script tag as the first thing in your <head>.
Scheduled rescans catch new cookies and alert you. The health score tells you at a glance whether anything needs attention.
<script src="https://consent.ampersand.ch/js/ampsand-consent.js"
data-config="https://consent.ampersand.ch/c/<your-site>.json" defer></script>
Who it's for
One team, every client site on a single dashboard. Health scores surface the ones that need work; invitations bring the client in when they want to see for themselves.
The revised FADP and the GDPR side by side, with a policy variant that covers both. Four languages out of the box, because your visitors do not all read the same one.
Consent Mode v2 done properly: signals set before the tags load, updated on every decision, and a dataLayer event for your GTM triggers. Conversion modelling keeps working.
Consent records, a processing register, vendor assessments and a dated policy history. The documents a reviewer asks for, produced from data you were keeping anyway.
For law firms
Verified legal partners review templates, take review orders, publish jurisdiction packs and keep clients informed. The platform handles distribution and payment.
Sign off a template for your jurisdiction and language. Every site using it shows "Reviewed by your firm" instead of a disclaimer, and a changed template invalidates the sign-off automatically.
Customers post what they need. You send an offer with price and delivery time, they accept and pay through the platform, you deliver on the order thread, and the payout lands in your Stripe account.
Work directly in the client's account with counsel access limited to legal pages, time-limited and audited, so the reviewed text goes live without copy and paste.
Publish your own template variants and short law-change notes targeted by country and site type. Clients are alerted, and can order a review in one click.
Philosophy
A short list of things we hold to. If any of them ever stop being true, the product has stopped doing its job.
Plenty of sites show a banner and still fire Analytics on the first byte. That is why the scanner never consents: what it sees is exactly what a visitor gets before choosing, and that is what we grade.
The widget, your configuration and your policy are all served from this platform. No third-party CDN sees your visitors, and there is no extra vendor to add to your own register.
Visitors are re-asked when a cookie, provider or category changes, or when their consent expires. Changing a colour or rewording the banner does not reset anyone's choice.
Any link or button can reopen the preferences, or a floating button can sit on every page. Revoking a category blocks its scripts again and clears their cookies, no reload required.
A cookie that is documented but no longer set harms nobody. A cookie that is set but not documented is a finding. The platform errs on the side of listing more, and tells you when it does.
Pricing
Every plan starts with a 14-day trial. No card required.
Everything one website needs to be compliant.
For companies whose data protection reaches past the website.
For agencies and compliance teams running many sites.
Just need a document? The free generators produce a non-binding draft in a minute.
Prices exclude VAT. Billed per site, cancel any time from the billing portal — the trial never charges you.
FAQ
Things people ask before they sign up. The full integration guide is waiting inside once you do.
Yes. The widget is one script tag and does not depend on anything else on the page. It runs the same on plain HTML, WordPress, Shopify, Next.js, Nuxt and anything else. It renders inside a shadow DOM, so your site's styles never interfere with it.
Give a tag a non-JavaScript type and a category attribute. The browser treats it as inert, not even downloaded, until that category is granted, when the widget activates it. Alternatively, attach the script to a provider in the platform and let the widget inject it. Single-page apps can check the granted state from their own code and listen for the consent event.
When the configuration version changes, which happens automatically when you add or remove cookies, providers or categories, or after the consent-expiry period you set. Cosmetic changes such as colours and wording do not re-ask.
A scan flags it as undocumented and you are alerted. With auto-import on, it is added to your inventory automatically. Undocumented cookies drop the site's health score until they are dealt with.
Nothing breaks. It stays listed until you remove it. Over-declaring is the safe side; tidy it up when convenient.
Yes. Your configuration is served with revalidation, so setting changes appear on the next normal page load without a hard refresh, and unchanged configs cost a tiny 304.
Colours, fonts, radius, position, an optional blocking overlay, and glass and gradient effects are all in the Appearance tab. Every text the visitor sees can be overridden per language.
Imprint, terms and conditions, withdrawal and refund policy with the model form, shipping and payment information, a standalone cookie policy, an accessibility statement, a data processing agreement, a sub-processor list with change notifications, and newsletter consent texts. Tell us your site type and country and we show which of them are required. Every generated text is a template: have it reviewed before relying on it, or request a partner lawyer review from inside the app.
English, German, French and Italian for the generated text, in a GDPR variant and a GDPR + Swiss FADP variant. You can also supply your own policy text per language and let the platform drop the always-current cookie list into it.
The consent record stores the decision, the categories granted and the configuration version it was made against, so it can be produced as a receipt. The widget stores the visitor's choice in their own browser.
Settings, then Delete account. We confirm with your password, then erase your sites, scans and consent records.
The first scan takes a few minutes and costs nothing. So does every scan after that.