Lurox 1.0 is live — visual page building for Magento 2. Read the guide
Magento 2 · Privacy & Compliance

GDPR & cookie consent — done properly, self-hosted.

A cookie banner that actually blocks scripts before consent, customer data-export and deletion requests, and an admin console that turns "we should handle GDPR" into a defensible, logged process. Free to start. Pro when you need the paper trail.

Blocks before consent external + inline scripts Self-hosted no consent SaaS, no per-pageview fees DSAR built in export + deletion, with an audit trail Luma · Hyvä · Lurox static-first, no-JS safe
A Magento 2 storefront showing a cookie-consent banner holding analytics and marketing scripts until the shopper chooses accept or reject
Magento 2.4.x · PHP 8.4Open Source + Adobe CommerceLuma · Hyvä · LuroxSelf-hosted — no SaaSStatic-first — no-JS safe30-day money-back

The problem

A banner that doesn't gate the scripts isn't consent — it's decoration.

Most Magento "cookie" extensions drop a banner on the page and call it compliance — while Google Analytics, Meta Pixel and your tag manager have already fired before the shopper clicks anything. Real consent means the scripts wait for a real choice, every choice is logged, and when a shopper asks to be forgotten, they actually are.

Consent, data rights and oversight — the whole job.

A banner that actually blocks

Analytics, marketing and tag-manager scripts are held — including inline gtag()/fbq() snippets, not just src= tags — until the shopper consents. Accept / reject is a real choice, logged with a timestamp. Renders static-first, so it works even with JavaScript off.

Customer data rights, self-service

Shoppers request a data export or account deletion from their account area. Every consent change and request is written to an audit log you can stand behind.

Admin oversight (Pro)

A consent log and a DSAR workflow: view each request, process or deny it, and download the generated export. Deletion runs an extended right-to-be-forgotten — a real erasure, with a record that it happened.

A Magento storefront cookie-consent banner with Reject All, Cookie Settings and Accept All buttons, holding scripts until the shopper chooses

A cookie banner that actually blocks — not just asks.

Most "cookie" banners are decoration — the tracking scripts have already fired by the time the shopper sees them. This one holds them. Analytics, marketing and tag-manager scripts wait until the shopper makes a real choice.

  • Blocks external and inline scripts — src= tags and inline gtag()/fbq() snippets
  • Accept, Reject or Cookie Settings — every decision is a real, logged choice
  • Renders static-first: the banner and its buttons work with JavaScript off, then upgrade with Alpine
  • Position, text and privacy-policy link are all configurable per store
Read the guide
The Cookie Preferences panel with Necessary always-active plus Analytics, Marketing and Preferences toggles, and Reject All / Save Preferences buttons

Let shoppers choose, category by category.

Real consent is granular. The preferences panel lets a shopper choose category by category — and only the categories they allow are ever activated.

  • Necessary is always active; Analytics, Marketing and Preferences are each an explicit opt-in
  • Each category has its own plain-language description you control
  • The panel is a solid-backdrop overlay teleported to <body> — it escapes header stacking and works on any theme
  • Their exact choice is stored and written to the consent audit log

Why merchants pick CPS for GDPR.

Self-hosted, no SaaS tax

No per-pageview consent fees, no shopper data sent to a third party. It all runs inside your store.

Real blocking, inline included

Most cheap banners miss inline gtag()/fbq() snippets; this one holds them too, until consent.

Erasure that means it

Order PII, addresses, newsletter and consent-log IP/UA — scrubbed, not just the account row.

Theme-agnostic + no-JS safe

Luma, Hyvä and Lurox. Static fallback when Alpine isn't present — banner and forms still work.

The CPS GDPR admin consent-log grid — each row a shopper's accept/reject decision as JSON with version, IP, user agent and timestamp

Every consent, logged — and auditable.

When a regulator or a customer asks "what did this person consent to, and when?", you need an answer — not a shrug. Every consent decision is written to an immutable audit log, and Pro gives you the console to read it.

  • Exactly which categories each shopper accepted or rejected, as stored JSON
  • Consent version, IP address, user-agent and timestamp — the full evidentiary record
  • Filter and sort the whole history from one admin grid
  • Guests and logged-in customers alike — nothing slips through unlogged
The CPS GDPR admin DSAR workflow grid — export and deletion requests with a highlighted Status column (pending, denied, completed) and View / Manage actions

Handle data requests without the fire drill.

A data-subject request has a legal clock on it. Pro turns "someone emailed asking for their data" into a tracked queue you actually work — no spreadsheet, no fire drill.

  • Every export and deletion request in one grid, with its status — pending, completed or denied
  • View / Process / Deny / Download each request from the workflow, with the export delivered as a secure admin download
  • Deny with a reason; every action is timestamped for the record
  • A completed request survives even if the customer is later erased — the audit trail is kept on purpose

From the shopper's choice to your audit trail — see the whole flow.

Storefront cookie-consent banner with accept, reject and settings
The consent banner — scripts wait for a real choice.
Granular cookie-preferences panel with per-category toggles
The preferences panel — consent, category by category.
Admin consent audit log grid
The consent log (Pro) — every decision, with the evidence.
Admin DSAR workflow grid with statuses and actions
The DSAR workflow (Pro) — a queue you actually work.

Two kinds of "compliance"

A banner is the easy part. The record is the point.

A banner-only extensionWith CPS GDPR
Tracking scripts before consentAlready firedHeld until the shopper chooses
Inline gtag()/fbq() snippetsStill runBlocked too, not just src= tags
Proof of what was consentedNoneA timestamped audit log
A "delete my data" requestManual, ad-hoc, error-proneA tracked workflow + real erasure

How-to

How to turn on real cookie consent

From install to a script-gating banner takes minutes — no code, no core changes.

  1. 1Install the module, then in Stores → Configuration → Cabbage Patch Studios → GDPR / Privacy set Enable to Yes (it ships off by default), scoped per store.
  2. 2Set your banner text, position and privacy-policy link, and write a plain-language description for each cookie category.
  3. 3Under Script Blocking, add the patterns for your analytics and marketing tags — both external src= hosts and inline snippet keywords like gtag( or fbq(.
  4. 4That's it — the banner now gates those scripts until the shopper consents, and every choice is written to the consent audit log.

How-to

How to handle a data-subject request

When a shopper exercises their rights, Pro turns it into a tracked, defensible process.

  1. 1The shopper submits an export or deletion request from their account area — it lands in the DSAR queue with a status of pending.
  2. 2Open Cabbage Patch Studios → GDPR Data Requests, View the request, and Process it — an export is generated for secure admin download; a deletion runs the extended right-to-be-forgotten.
  3. 3Need to refuse? Deny with a reason (for example, an open order under statutory retention) — the reason and timestamp are kept on the record.
  4. 4Every action is logged, and a completed request survives even if the customer is later erased — so you always have proof it was honoured.

Compliance you can prove

Consent that holds up — because it's written down.

A banner is easy to fake. An audit log, a real script gate and an erasure you can evidence are not. CPS GDPR gives you the whole chain — consent, oversight and the right to be forgotten — self-hosted, so nothing leaves your store.

See how it works →

Free vs Pro

Start free. Upgrade for the paper trail.

FeatureFree$0Pro$129
Cookie-consent banner + granular panel (static-first)
Script/tag blocking (external + inline)
Customer DSAR request forms (export + deletion)
Consent audit log (data written)
Admin consent-log console
DSAR admin workflow (view / process / deny / download)
Secure export delivery
Extended right-to-be-forgotten (order PII + newsletter + log scrub)

Licensed per website — one Pro key covers one storefront domain. Every feature above is shipped today; nothing here is roadmap. Google Consent Mode v2 and geo/EU targeting are planned for a future release.

Start free, upgrade when you need the record

The admin console, DSAR workflow and full erasure — $129.

Licensed per website. Perpetual — your licence never expires.

Free

Free
$0 keep it forever
  • Cookie-consent banner + granular panel — static-first, no-JS safe
  • Script/tag blocking — external and inline snippets
  • Customer DSAR forms — data export + account deletion
  • Consent audit log
Start free

Pro

Pro
$129 one-time, per website
  • Everything in Free, plus:
  • Admin consent-log console
  • DSAR admin workflow — view / process / deny / download
  • Secure export delivery
  • Extended right-to-be-forgotten — order PII + addresses, newsletter, IP/UA scrub
  • 12 months of updates & support
Buy Pro — $129
✓ 30-day money-back✓ 12 months updates✓ Perpetual licence✓ 100% unencrypted code

Actively maintained

An honest version history.

Every release verified on Magento 2.4.x.

  • v1.0Jul 2026First release — the static-first cookie-consent banner and granular preferences panel, external and inline script blocking (gtag()/fbq() held until consent), the consent audit log, customer DSAR export & deletion forms, and the Pro admin: consent-log console, DSAR workflow (view / process / deny / secure download), and the extended right-to-be-forgotten.

Questions, answered.

Really blocks. External and inline analytics, marketing and tag-manager scripts are held until the shopper consents — not just src= tags, but inline gtag()/fbq() snippets too. The banner also renders static-first, so it works with JavaScript disabled.

Luma, Hyvä and Lurox. It renders static-first, so the banner and the data-request forms work even with JavaScript off; the granular preferences panel layers on top where Alpine is present.

In Pro, an erasure anonymises the customer record along with their order PII and order addresses, removes the newsletter subscription, and scrubs stored IP/UA from the consent log. It's a real erasure with a record that it happened — not a soft-delete.

No. It's fully self-hosted — no third-party consent SaaS, no per-pageview fees, nothing leaves your store.

The free tier covers consent, script blocking and customer requests. Pro adds the admin oversight and the audit trail most teams want when they have to prove it — the consent-log console, the DSAR workflow, and full erasure.

Not yet — both are on the roadmap for a future release, and we won't list them as shipping until they are. Everything else on this page works today.

Per website — one domain per key — and perpetual, with 12 months of updates and support included. The free tier needs no key. You own the code — 100% unencrypted.

Specific compliance requirement, or a bespoke consent flow?

The module covers consent, blocking, customer data rights and full erasure out of the box. If you need a particular script category wired up, a custom DSAR export format, or help mapping your data-processing obligations to the toolkit, tell us about your store and we'll scope it — usually within one business day.

We build these on top of the GDPR module, so you keep the whole toolkit and add exactly what you need.

We'll only use your details to reply to this enquiry.

GDPR consent and data rights for Magento 2 — self-hosted, and it actually blocks.

A cookie banner that gates scripts before consent, a granular preferences panel, customer data requests, and an admin console with a DSAR workflow and one-click right-to-be-forgotten. Free to start; Pro from $129.

See Pro — $129