
Part of Web Wisdom
Why I Don’t Have Cookies…
A banner is not consent.
A cookie banner and a working consent system are not the same thing. Why Cahillbrand skips Google Analytics by default, prefers cookie-free analytics, and what small businesses should actually check.
Web Wisdom is for the longer, more strategic reads — the ones that outgrew Micro Myth-busters. Straight-talking articles on privacy, analytics, consent, and the quieter decisions that shape how a small business website behaves online.
This piece covers an absolute pet peeve of mine.
I promise I’m not a total grump. But there are moments at my desk when I notice hundreds of websites making the same mistake – and they sit with me.
I get wound up whenever I visit a website and see a polite little cookie banner peeping at me from the bottom of the screen.
Why?
Because, on some sites, the tracking started before I had even found the reject button.
A cookie banner and a working consent system are not necessarily the same thing. Sometimes, the banner might as well be decorative.
Let’s get into it.
First, why do businesses use website analytics?
Most business owners understandably want to know whether their website is working.
- Are people visiting it?
- Where did they come from?
- Which pages are they reading?
- Did they disappear after three seconds, or did they stick around long enough to discover what the business actually does?
Website analytics tools collect and organise this kind of information.
The best-known is Google Analytics, which can show business owners information about visitor numbers, sessions, approximate locations, devices and behaviour across a website.
It is widely used by small businesses partly because it is powerful, available without a standard subscription fee and attached to one of the most recognisable technology brands in the world.
That familiarity can create a sense of reassurance.
It is Google. Everyone uses Google. Therefore, we assume it must be the obvious choice.
But recognisable does not automatically mean simple, proportionate or right for every small business.
And this may surprise you: I do not add Google Analytics to the websites I build as standard.
Why not?
Because, in its usual configuration, Google Analytics uses technologies that require careful privacy and consent management.
Google Analytics commonly uses a first-party cookie called `_ga` to distinguish visitors and sessions. It can also process information about sessions, devices, browsers and approximate locations.
Google says that it does not log or store individual IP addresses from visitors in the UK, EU or Switzerland. It uses the IP address briefly to derive coarse location information before discarding it.
However, that does not mean a standard Google Analytics setup is automatically exempt from the UK rules on storage, access and personal information.
That does not make Google Analytics inherently evil.
It does mean, though, that you cannot simply install it, add a vague banner saying “We use cookies” and carry on as though the legal fairies have approved everything overnight.
For many small businesses, I think there is a simpler choice: collect less information in the first place.
But before I put you off internet cookies for life, let’s quickly establish what one actually is.
What ingredients make up an internet cookie?
Sadly, there is no delicious butter involved.
A website cookie is a small piece of information stored on your device when you visit a website.
Imagine visiting a bakery.
A useful cookie is the assistant remembering that you have already placed two cinnamon buns in your basket while you continue browsing.
In this magical bakery, without that memory, your basket would empty every time you looked at another shelf.
Another useful cookie might remember that you are logged into your account.
No, I don’t have a bakery analogy for that one.
These are examples of cookies that may be essential to providing a service you have requested.
However, other cookies behave less like a helpful bakery assistant and more like someone silently stalking you around the shop with a clipboard.
This unwanted shadow figure records which shelves you visit, what you look at, how long you linger and whether you later visit another branch – all while you merrily sweep around, browsing and whistling.
Some of that information may be used for analytics. Some may be used for advertising, profiling or tracking people across services.
This distinction matters.
Under the UK’s Privacy and Electronic Communications Regulations, storing information on someone’s device – or accessing information already stored there – is generally prohibited unless the user has consented or a specific exception applies.
The Information Commissioner’s Office (ICO) says organisations must provide clear information about what they are doing and obtain appropriate consent for non-exempt technologies.
A banner is not enough
Here is the important bit.
A banner is only the visible part of a consent system.
What matters is what is happening behind it.
A compliant-looking box does not help if analytics, advertising scripts or other non-essential technologies have already started running before the visitor makes a choice.
The ICO is the UK’s independent regulator for data protection and information rights.
Its guidance says that, where consent is required, it must be freely given, specific, informed and indicated through a clear positive action. Simply continuing to browse a website does not amount to valid consent for non-essential technologies.
A good consent mechanism should therefore:
- Make rejecting non-essential technologies as straightforward as accepting them.
- Offer clear information about what each category does.
- Provide more detailed choices where relevant.
- Leave non-exempt options off until the visitor actively agrees.
- Make it possible for visitors to change their preferences later.
- Genuinely prevent the relevant technologies from running before consent.
The ICO has previously taken action against banners that failed to provide an equally prominent way to refuse advertising cookies. Its current guidance also gives examples of mechanisms that allow people to accept, refuse or customise their choices. See their own website as an example.
So this: “By continuing to use this website, you agree to cookies.”
…is not a meaningful choice where consent is required.
And this: “We use cookies. Accept.”
…is not much of a choice either.
It’s the website equivalent of asking, “Would you like a biscuit or cake?” and then offering a biscuit or a slightly smaller biscuit.
The cake option didn’t exist.
Not the greatest offer.
Is a cookie wall required?
People often use the phrase cookie wall to describe a pop-up or consent layer that appears before someone interacts fully with a website.
But the important legal point is not whether you call it a banner, panel, pop-up, consent manager or wall.
The important point is whether it:
- Gives people a genuine choice
- And prevents non-exempt technologies from being used before that choice is made.
A website does not necessarily need to block all access until a visitor accepts cookies.
In fact, forcing someone to accept unnecessary tracking as the price of entering a website could raise its own concerns about whether consent is freely given.
What you need is a consent mechanism that works.
Visitors should be able to accept, reject or customise non-essential technologies without being nudged, tricked or exhausted into surrender.
What about Google Analytics, then?
This is where the detail matters.
Google Analytics receives an IP address as part of handling a web request.
Google says that, for people in the UK, EU and Switzerland, it uses that address only to derive approximate location information before immediately discarding it. It says individual IP addresses are not logged or stored.
However, Google Analytics can still use cookies and collect other information about visitors, sessions, devices and approximate locations.
Its configuration can also change what is collected and how the data is used. Consent Mode, advertising features, linked Google services, user IDs and custom dimensions can all affect the privacy picture.
For a small business owner, one practical question remains:
Has your website been configured so that technologies requiring consent do not start before the visitor has made a valid choice?
If you do not know the answer, it is worth checking.
Google Tag Manager can complicate matters too
Google Tag Manager is another tool used to load and manage pieces of website code, often called tags.
It can be incredibly useful.
It can also become a well-organised but neglected cupboard full of tracking scripts you forget about.
Again, the problem is not Tag Manager itself. The problem is what it has been configured to trigger.
If analytics, advertising pixels, or other non-exempt tools fire before consent, adding a cookie banner afterwards does not undo that collection.
Your consent platform and your tags need to speak to each other properly.
Otherwise, the banner effectively saying, “Nothing will happen until you choose” is still hosting a little data party backstage.
Are any cookies allowed without consent?
Yes.
Some technologies are strictly necessary for a service the visitor has requested. Examples may include:
- Remembering items in an online shopping basket.
- Maintaining an essential login session.
- Providing necessary security.
- Distributing website traffic so the site functions reliably.
The ICO explains that strictly necessary technologies can fall within an exception to the consent requirement.
But something is not “necessary” simply because it is useful, convenient or commercially valuable to the website owner.
The Data (Use and Access) Act 2025 also introduced further exceptions for certain low-risk purposes, including some statistical analysis and functionality.
Yet these are not blanket permissions to track people however you like.
Each exception has conditions. For example, statistical information must meet the relevant requirements, people must receive clear information, and appropriate safeguards and opt-out arrangements may be needed.
The ICO published updated guidance in April 2026 to reflect these changes.
That is one reason your cookie setup should be reviewed in context rather than copied wholesale from another website.
Why I prefer a simpler browsing experience
I don’t know about you, but as an internet user, I am frankly tired of pop-ups.
Cookie boxes. Newsletter boxes. Those discount wheels. Chat widgets, paywalls and video adverts that begin playing just as I have found the paragraph I wanted to read.
Sometimes visiting a website feels like trying to enter that magical bakery while six people stand in the doorway asking me different questions.
Would you like to subscribe?
Would you like 10% off?
Would you like to enable personalised content?
Would you like to tell us why you rejected personalised content?
No.
I would like to find out what time you close.
That is why I prefer to build websites that collect less data and need fewer interruptions.
Privacy-friendly design is not only about compliance. In my experience, it can also make a website feel calmer, faster and more respectful.
How we keep analytics cookie-free
As I mentioned earlier, the websites I build do not use Google Analytics as standard.
Instead, I use Plausible Analytics to understand broad website trends.
Plausible is designed to measure things such as page views, popular pages, referral sources, devices and countries without using cookies or persistent identifiers.
Plausible says it does not use cookies, browser cache or local storage for analytics. It uses information from a request to create a short-lived daily identifier, but says raw IP addresses and user-agent information are never stored.
That means I can still answer useful questions:
- Is anybody visiting the website?
- Which pages are being read?
- Where is the traffic coming from?
- Did that article, directory listing or campaign bring people in?
What I do not need is a detailed diary of one person’s movements around the internet.
For the majority of small business websites, broad patterns are often enough.
The bad news
The thing that sucks a bit: Plausible is not free.
And no, I have not been paid to say nice things about it.
Google Analytics offers an enormous amount of data without a standard subscription charge.
Plausible charges a subscription and positions itself as a privacy-focused analytics business rather than an advertising platform.
There is a trade-off.
For clients who choose our managed hosting with Plausible Analytics, we manage the platform on their behalf, so they don't need to create or maintain their own account.
They receive the information that is useful without all of us having to buy our own tiny analytics empire.
If Google Analytics is genuinely right for your business, you can use it.
But please make sure it is configured responsibly.
What should you check?
Start by asking:
- Does my website use Google Analytics?
- Does it use Google Tag Manager?
- Are any advertising pixels installed?
- Which cookies or similar technologies appear before someone consents?
- Which technologies are being treated as exempt, and why?
- Is “reject all” as clear and easy as “accept all” where consent is required?
- Can visitors choose between categories?
- Can they change their minds later?
- Does my cookie policy describe what the website actually does today?
- Does my privacy policy explain how personal information is collected, used, shared and retained?
The last two questions matter because many privacy and cookie policies have been copied from another business, generated years ago, or left untouched while the website or business changed around them.
A policy is not protective simply because it is long. It needs to be accurate.
A privacy policy does not have to be a creative-writing exercise
Your privacy information should explain, in plain English:
- Who operates the website
- How people can contact you
- The personal information you collect
- Why you collect it
- Your lawful basis where applicable
- Which services and suppliers process information
- Whether information is transferred internationally
- How long you keep their information
- How you protect it
- What rights people have and how they can complain
- The date when the information was last reviewed
Depending on the business, this might include your website host, email platform, contact forms, payment providers, analytics service, course platform, customer database and any other third parties involved in handling information.
It should describe your actual systems.
Not the systems used by the business whose policy you found during an increasingly frantic Google search approaching midnight.
Our cookie-policy example
Here is a simplified example based on the approach we used for the Responsible Business Directory.
Cookies
The Responsible Business Directory does not use cookies when visitors browse the directory, search for members or view member profiles.
Browser storage
To keep directory listings in a consistent order while a visitor moves between search or category pages, the website stores a small amount of information in the visitor’s browser.
This information remains on the device. It is not used for advertising, profiling or tracking visitors across other websites. It is replaced when a new search or category is opened.
Analytics
The website uses Plausible Analytics to understand broad patterns in how the directory is used.
Plausible does not use cookies, browser cache or local storage for analytics. It provides aggregated information such as page views and referral sources without creating persistent profiles of individual visitors.
Other websites
Some services may be provided through separate websites. Those websites have their own privacy and cookie policies, which apply when visitors use them.
Changes
If the website’s use of cookies, browser storage or analytics changes, this policy will be updated.
A useful template but not a universal one
The example above can help you understand the sort of information a clear policy may contain.
But I would not recommend presenting any cookie or privacy policy as a copy-and-paste legal solution for every business.
A directory, online shop, membership platform, booking website and one-page brochure site may all collect and process information differently.
That is why we have created The Small Business Website Privacy Check: a practical workbook to help you investigate what your website is doing before you update your policies.
It includes:
- Questions to answer
- Headings to consider
- Example wording
- Common website suppliers to check
- Prompts for deciding how long information is retained
- A cookie and tracker audit
- Questions to send to your web developer
- Reminders to tailor your information and seek appropriate advice
It will not turn you into a data-protection solicitor over lunch.
But it will help you ask better questions and spot where your website, policies and actual practices may not match.
Run the Small Business Website Privacy CheckThe sugary solution
If you already have a cookie banner, you have at least recognised that privacy matters. That is a start.
The next step is to find out whether the banner is doing anything beyond occupying the bottom quarter of everybody’s mobile screen.
Check your setup.
Check what loads before consent.
Check your Google tags.
Check that rejecting is as straightforward as accepting where consent is needed.
Then read your cookie and privacy policies and ask one simple question:
Is this an honest description of what my website actually does?
If the answer is, “I have absolutely no idea,” you are not alone.
And you are only an email away from someone who enjoys detangling this stuff far more than is probably healthy.
So, hello. I’m Danny, the founder of Cahillbrand – and I don’t eat more cookies than are good for me.