Keep all cookies untill user consent

Michael
Written by MichaelLast updated 1 hour ago

Keep Cookies Until Consent

By default, CookieScript deletes non-essential cookies that are already on a visitor's device before the visitor makes a consent choice. The **Keep cookies until consent** option turns this deletion off. Cookies stay on the device until the visitor accepts or declines, and are then handled based on that choice.

The option affects **cookies only**. Script blocking, Google Consent Mode, IAB TCF and the other consent features work as usual.

How to enable

1. Log in to your CookieScript account.

2. Open your banner and go to **Settings > Cookie behavior**.

3. Set **Keep cookies until consent** to **Yes**.

4. Save the changes. If you install CookieScript with the code snippet, no code changes are needed.

How it works

Option disabled (default)

1. A visitor opens your website.

2. CookieScript blocks third-party scripts that need consent.

3. Any non-essential cookies that are already on the device are deleted, even before the visitor makes a choice.

4. The visitor makes a choice, and cookies are allowed or deleted based on it.

Option enabled

1. A visitor opens your website.

2. CookieScript blocks third-party scripts that need consent, **exactly as before**.

3. Non-essential cookies that are already on the device are **not deleted** while the visitor has not made a choice.

4. The visitor makes a choice:

   - **Accept all.** All cookies are kept.

   - **Decline all.** Cookies from declined categories are deleted, as usual.

   - **Custom choice (Save & Close).** Cookies from accepted categories are kept, and cookies from declined categories are deleted.

Once the choice is made, everything works as if the option were disabled.

What does not change

| Feature | Behavior with this option enabled |

| Third-party script blocking | Scripts are still blocked until consent |

| Google Consent Mode | Consent signals are sent as usual (denied by default) |

| IAB TCF | TC string is created and updated as usual |

| Strictly necessary cookies | Always kept, as before |

| Consent recording | Works as usual |

| Cookies after a "Decline" choice | Deleted based on the visitor's choice |

Where do these cookies come from?

When scripts are blocked, a visitor can still have non-essential cookies before making a choice. Common sources are:

- **Server-side cookies** set by your website, platform or CMS through HTTP headers.

- **Cookies from a previous visit**, for example after the visitor's consent expired or was reset.

- **Cookies shared between subdomains**, set by another part of your website.

- **Scripts that load before CookieScript** or are not blocked, for example inline code added directly to your theme.

## When to use this option

This option is useful when deleting cookies before consent causes problems on your website. For example:

- **Platform features break.** Some e-commerce or CMS platforms set cookies on the server and expect them to stay, for example for carts, A/B tests or session handling.

- **Analytics data is lost.** Deleting identifier cookies before a choice can make returning visitors look like new ones once they accept.

- **Cookies keep coming back.** If your server sets a cookie on every page load, deleting it again and again has no real effect and only creates extra work in the browser.

If the problem only concerns cookies the Cookie Scanner did not detect, use **Keep unknown cookies** instead. If it only concerns Google Analytics cookies, use **Keep Google Analytics Cookies**.

Privacy compliance

Keeping non-essential cookies before consent is **not compliant** with laws that require prior (opt-in) consent for cookies. In regions with an opt-out model it is generally acceptable.

**Recommendation:** If your website has visitors from the EU, UK or other opt-in regions, keep this option disabled unless the kept cookies are strictly necessary. Mark such cookies as **Strictly necessary** in your cookie declaration instead.

> This article is for general information and is not legal advice. Check with your legal advisor which settings fit your website.

## Related settings

- **Keep unknown cookies.** Keeps cookies the Cookie Scanner did not detect, at all times.

- **Keep Google Analytics Cookies.** Keeps Google Analytics cookies only.

- **Consent mode (Explicit / Implied).** Implied mode loads scripts **and** keeps cookies before a choice. Keep cookies until consent affects cookies only.

- **Additional Strictly Necessary Cookies.** Lists cookies that should never be deleted.

FAQ

**Will scripts like Google Analytics or Meta Pixel load before consent?**

No. Script blocking is not affected, so these scripts still wait for consent.

**What happens if the visitor declines?**

Cookies from the declined categories are deleted, as with the option disabled.

**What happens if the visitor closes the banner without a choice?**

This depends on the **Close button action** setting. If the button only closes the banner, cookies stay on the device until the visitor makes a choice. If it is set to accept or reject all cookies, cookies are handled based on that choice.

**Does this option change the banner?**

No. The banner looks and works the same.

Did this article help you solve your issue?