Installing a managed property?
Add the runtime
Create the property first so its configured origin, public site key, and published consent configuration are available to the runtime.
- 1
Select the property
Open Integrations → Custom sites and select the destination property. Every property has a different site identifier. - 2
Copy the generated snippet
Use the Copy snippet action after confirming the selected property name and hostname. - 3
Place it before optional vendors
Add the runtime to the document head before analytics, advertising, personalization, or other optional scripts.
Example only
<script
src="http://localhost:3210/embed/v1.js"
data-site-id="site_abc123"
data-api-base="http://localhost:3210"
data-privacy-url="/privacy"
data-platform="custom"
defer
></script>Use the dashboard-generated values
Gate optional scripts
A normal script or iframe can contact a vendor before the consent runtime makes a decision. Convert optional resources into inert declarations.
Declarative script gating
<script
type="text/plain"
data-strongprivacy-id="site-analytics"
data-strongprivacy-category="analytics"
data-strongprivacy-src="https://analytics.example.com/analytics.js"
></script>| Category | Use for |
|---|---|
| necessary | Core security and requested service functions. Never optional. |
| functional | Preferences, chat, and enhanced site features. |
| analytics | Analytics, performance measurement, and attribution. |
| marketing | Advertising, retargeting, and cross-site profiling. |
| media | Embedded video, maps, and third-party media players. |
For dynamic single-page applications, use StrongPrivacy.registerScript().
Consent-gated iframe
<iframe
title="Product video"
data-strongprivacy-category="media"
data-strongprivacy-src="https://www.youtube-nocookie.com/embed/VIDEO_ID"
width="560"
height="315"
></iframe>Do not use src on optional iframes
data-strongprivacy-src. A normal src can start a network request before the runtime has a chance to block it.Google Consent Mode v2
Tell Google's tags what the visitor chose, not just whether to load them.
The runtime sends Consent Mode updates on its own. Marketing consent drives ad_storage, ad_user_data and ad_personalization; analytics drives analytics_storage; the functional category drives functionality_storage and personalization_storage. security_storage is always granted, because it is not an optional purpose. There is nothing to configure, and a site with no Google tag gains a few unread entries in dataLayer.
What the runtime cannot do on its own is be first. It is loaded from this service and runs after the page is parsed, and a Google tag that runs before any default has been declared behaves as though it had consent. If you install Google tags directly in your HTML, paste this in the head above them. The WordPress plugin and the Shopify app already do it for you.
Consent Mode default
<script>
window.dataLayer = window.dataLayer || [];
window.gtag = window.gtag || function () { window.dataLayer.push(arguments); };
window.gtag('consent', 'default', {
ad_storage: 'denied',
ad_personalization: 'denied',
ad_user_data: 'denied',
analytics_storage: 'denied',
functionality_storage: 'denied',
personalization_storage: 'denied',
security_storage: 'granted',
wait_for_update: 500
});
</script>Put the default before your tags, not after
Add a permanent privacy control
Visitors must be able to revise or withdraw a choice as easily as they made it.
Add a visible Privacy choices control in the site footer or privacy page. The runtime connects this attribute automatically, including buttons added during client-side navigation. A built-in persistent control is also available after a choice.
<button type="button" data-strongprivacy-preferences>Privacy choices</button>In the configuration editor, add optional custom categories, complete reviewed language variants, and choose spacing and preferences text. Use the displayed custom_ key when assigning a script or media element. Set data-language on the runtime to use an explicit language; otherwise supported browser languages are matched.
Full installation acceptance checklist →Production checklist
Test a production-like page with storage cleared and the browser network panel open.
- The exact page origin is registered on the selected property.
- The runtime loads once and reports no origin or configuration error.
- Optional requests remain absent before an allowed choice.
- Reject optional does not load functional, analytics, marketing, or media resources.
- Reloading preserves the decision, and Privacy choices reopens the dialog.
- Your Content Security Policy permits the app origin and approved vendors.