Consent setup (GDPR & PECR)
Leads are always captured. Consent controls what else the snippet may remember.
Trackfully captures leads from the moment the snippet is installed, with or without cookie consent. What consent controls is storage: until your site signals it, the snippet writes no cookies and no localStorage, keeps no visitor id, and remembers nothing between pages.
The two modes
Without consent (storage-free): when a visitor submits a form or starts a chat, the lead is sent with the details they typed and the context of that moment — the page URL (including any utm_* or gclid parameters on it) and the referrer. Nothing is stored on the visitor's device, so this stays inside PECR: the rules restrict storing or reading things on the device, not processing details a person chooses to send you.
With consent: the snippet also keeps a first-party visitor id, session, and first/last marketing touch, so a lead that arrives days after the ad click still attributes to that ad. This is the full-journey mode, and it needs the visitor's consent because it stores data on their device.
In short: you never lose the lead. Without consent you may lose the journey — attribution is limited to whatever the submit-time page reveals.
Signal consent
Two equivalent ways:
Before the snippet loads (if your banner state is known at page render):
<script>window.trackfullyConsent = true;</script>
<script async src="https://trackfully.app/t.js" data-site-key="tf_…"></script>
When the user accepts (from any cookie banner's accept callback):
trackfully('consent', true);
Consent persists across pages for that visitor, so you only need to signal it once.
With a consent management plugin
Using Complianz, Cookiebot, CookieYes or similar? Install the snippet directly in your site, not in the plugin's script blocker. Put only the consent call in the plugin, in your statistics or analytics category.
That means two pieces in two places:
- The snippet tag from your Tracking page goes in the site's head or footer so it loads on every page, outside the plugin entirely. It is storage-free until consent, so it needs no gating.
- The consent call goes in the plugin, in the category the plugin runs after the visitor accepts statistics or analytics cookies:
window.trackfully = window.trackfully || function () {
(window.trackfully.q = window.trackfully.q || []).push(arguments);
};
window.trackfully('consent', true);
The stub on the first three lines is safe to run before the snippet has loaded; the snippet picks the call up when it arrives.
Not recommended: letting the plugin inject the whole snippet after acceptance. If the snippet is inside the plugin's blocked category, visitors who decline (and, with most plugins, everyone until they choose) get no snippet at all, so their leads are never captured. A real install lost every lead this way. Keep the tag in the page and gate only the consent call.
Withdrawing consent
If your banner lets users change their mind, pass false:
<script>window.trackfullyConsent = false;</script>
on the next page load clears the stored consent and stops all storage. Storage-free lead capture continues — withdrawal removes what is remembered about the visitor, not your record of the enquiries they chose to send.
Opting a form out
Any form you never want captured (e.g. a login form):
<form data-trackfully="off">…</form>
What's stored, where
Without consent: nothing on the device. With consent: a first-party visitor id (cookie + localStorage), the visitor's first and last marketing touch, and a session marker. In both modes, submitted lead details are processed and stored in London (UK). Nothing is shared with ad networks.