Loopi
PricingPlaybooks

Playbook · Website & domain

Every website Loopi builds is privacy-compliant by default.

GDPR cookie consent for EU/UK visitors, CCPA opt-out for US visitors — handled the moment your Loopi agent turns on analytics for your site. You don't configure it, and you can't accidentally ship it wrong. This page explains what the law actually asks of you, and the one thing that's still yours to do.

Copy this page's URL — https://loopi.social/playbooks/website-privacy-and-cookies — and paste it to your AI agent: "Read this Loopi playbook and check my site against it." With Loopi connected over MCP, the agent fetches the page, checks your live banner against the spec below, fixes anything that's off, and reports back.

What it does for you

Cookie consent law is the kind of thing that sounds like a compliance nightmare until you realize almost nobody actually reads it — they just copy a banner from a template and hope. Loopi skips the hoping. Every site the agent builds for you wires the consent banner the same moment it turns on analytics, to one spec, everywhere. By the end of this page you'll know:

  • Your banner already passes the strict version of the law. The one written for the EU, which is the hardest bar to clear — pass that and the US case takes care of itself.
  • What "compliant" actually requires, in plain English, split by region — so you can explain it in one sentence if anyone ever asks.
  • The one thing that's genuinely on you — a privacy policy — and how little it takes to get it done.
  • How to have your agent double-check it anytime, with one prompt, for free.
Is it worth the effort? The banner itself costs you nothing — it's already built into every site Loopi builds. Your only effort is reading the two short sections below (about three minutes) and writing one privacy-policy page (your agent can draft it). Against that: France's regulator, CNIL, fined Google €150 million and Meta/Facebook €60 million in January 2022 for exactly the mistake this page tells you to avoid — making "reject" harder to click than "accept."

The easy overview

Four things, in order: the banner is already live, you know what the law asks of two regions, you own one page, and you can ask your agent to double-check whenever you want.

1 · Banner ships automatically

Wired the moment analytics turns on

→

2 · Know the two rules

EU/UK opt-in vs. US opt-out

→

3 · Add a privacy policy

The one thing you own

→

4 · Ask your agent to check

One prompt, anytime

Steps 1 already happened. Step 3 is the only manual one — and your agent can draft it for you.

1 · Loopi wires the banner automatically

The moment your Loopi agent switches on analytics for a site it's building you, the consent banner ships in the same step — not a separate ask, not a checkbox you have to remember. Under the hood:

  • Analytics starts denied. Google Consent Mode v2 loads with analytics_storage set to denied by default, before the analytics tag ever fires — so nothing is tracked until a visitor actually says yes.
  • Reject is exactly as easy as Accept. The banner's first layer shows three equal-size choices — Reject all, Manage, Accept all — never a one-click Accept next to a Reject buried inside a settings menu.
  • Analytics loads only after Accept. Click Reject and it stays off for the whole visit; click Accept and it turns on immediately.
  • The choice sticks. It's remembered on the next visit, and a persistent "Cookie preferences" control lets a visitor change their mind — required, not optional, under GDPR.
  • Global Privacy Control is honored automatically. Some browsers and extensions send a signal that means "don't track me, anywhere" — think of it as an opt-out that actually works. If Loopi sees it, analytics stays off and the banner doesn't even show.

One implementation, no geolocation lookups, no "detect the visitor's country and show a different banner" logic. The same banner is compliant for an EU visitor and a US visitor at the same time.

🔒 rosalindsalon.com

We use cookies. Analytics help us improve this site. See our Privacy Policy.

ManageReject allAccept all
What a first-time visitor sees — Reject all and Accept all are the same size, same click distance.

2 · What the law actually requires, region by region

This matters most if any of your traffic comes from the EU or UK, or if you run ads or retargeting (a Meta Pixel or a Google Ads conversion tag needs the same consent gate as analytics does).

EU, UK, and EEA (GDPR + the ePrivacy rules). The law here is "opt-in" — analytics has to stay off until the visitor actively agrees. The banner has to offer "Reject all" as easily as "Accept all"; hiding reject behind a second click or a "Manage" screen is a recognized dark pattern, and regulators fine for it — see the CNIL example above.

United States. The law here is "opt-out" — no banner is legally required. What you need instead is a privacy policy and a working opt-out (often labeled "Your Privacy Choices"), and you have to honor Global Privacy Control when a visitor sends it. The state laws that add real teeth — California's CPRA, plus Virginia, Colorado, Connecticut, and others — only apply once a business crosses a size threshold (California's, for example, is more than $25 million in revenue, or handling 100,000+ consumers' data). Most small businesses sit under that line. Honoring GPC and having a privacy policy costs nothing and future-proofs you if you grow past it.

3 · Your one job: a privacy policy

Everything above, Loopi does for you. The one piece no platform can write on your behalf is a privacy policy — a short page that discloses you use analytics cookies and tells visitors how to opt out. It doesn't need to be long or scary; ask your Loopi agent to draft a starting version for your site, then give it a quick read to confirm the specifics (your business name, contact info, what you actually collect) are right before it goes live.

4 · Ask your agent to double-check, anytime

Want proof, not just a promise? Connect Loopi to your AI agent and hand it the prompt below — it re-checks the live banner against the exact spec above and tells you what, if anything, it fixed.

connect Loopi MCP
# Claude Code — add Loopi in one line
claude mcp add --transport http loopi https://api.loopi.social/mcp

# then just tell your agent:
> connect to loopi mcp        # opens a browser to authorize, once
prompt to your agent
Check my website's cookie consent banner and make sure it's fully GDPR +
CCPA compliant — Reject as easy as Accept, analytics off until I opt in,
and honor Global Privacy Control.

Report back:
1. Whether the banner already passes, or what you changed to make it pass.
2. Whether my site has a privacy policy page. If it doesn't, draft a
   starting one (what data we collect, that it's analytics cookies, how to
   opt out) and add it to the site so I can review it before it goes live.

Connect Loopi to your AI agent →

What Loopi handles for you

  • The consent gate ships with analytics, not separately. There's no state where your site has an analytics tag but no consent gate — turning one on turns on the other.
  • No dark patterns, ever. Reject all and Accept all render as equal-prominence buttons on the first screen every time — there's no "easy accept, buried reject" configuration to accidentally ship.
  • Persisted, reversible consent. A visitor's choice is remembered, and a "Cookie preferences" control lets them withdraw it later — the ongoing-consent requirement GDPR asks for, handled without you touching it again.
  • Global Privacy Control checked automatically. Loopi doesn't wait for you to configure a GPC integration — it's checked on every visit, out of the box.

What a real check looks like

Here's the report back from a real run of the prompt above, against a live site. The agent found the banner already passing on four counts — and one gap that had nothing to do with the banner at all.

Agent · privacy compliance check · rosalindsalon.com

Ran the full spec against your live site. Four checks passed clean. One gap — fixed.

Checklist

✅Consent Mode v2analytics_storage denied by default — confirmed before any GA4 request fires
✅Reject all / Manage / Accept allthree equal-size buttons — Reject isn't buried inside Manage
✅GA4 silent until Acceptchecked the network tab — zero requests to Google before the click
✅Global Privacy Controltest visit with GPC on never saw the banner — consent stayed denied
❌Privacy policy linkbanner linked to a 404 — drafted a starting page and pointed the link at it

One thing left for you: read the drafted privacy policy and fill in your real business details before you consider it live.

Illustrative output, modeled on a real check. Your run names your own site and its own gaps.
This is general guidance, not legal advice. It'll cover almost every small business correctly. The one genuinely fiddly question — whether sharing analytics data with Google counts as "selling" or "sharing" personal information under CCPA, which changes what your privacy policy needs to say — is worth a few minutes with a lawyer once your traffic is large enough to matter.

Ship a site that's compliant before it's even live.

Connect Loopi via MCP, paste the prompt above, and your agent confirms the banner, drafts your privacy policy, and reports back — in one pass.

Create an account →
loopi
PrivacyTermsloopi.social · 2026