Skip to content

Do I need a cookie banner for Crustat?

No. Crustat stores nothing on your visitors' devices, so it needs no consent. Here's why, and the one thing to check.

The short answer

No. Crustat doesn’t need a cookie banner or a consent pop-up.

Why not

Cookie banners exist because of one rule: in the EU and the UK, a website must ask before it stores something on a visitor’s device or reads something back from it (Article 5(3) of the ePrivacy Directive, the “cookie law”). That covers cookies, localStorage and anything similar.

Crustat leaves nothing on the device to read back:

  • No cookies. Not one, first-party or third-party.
  • Nothing written to localStorage, sessionStorage or similar on a visitor’s device. The script keeps no id of its own.
  • One flag, for site owners only. The script checks a single localStorage flag that a site owner can set on their own browser, at their own request, to leave out their own visits. For visitors it’s always empty, and Crustat never writes it on their devices.
  • Visitors are told apart on our server. Each visit gets an anonymous code built from that day’s random salt, the site, the IP address and the browser. Each salt is used for one day only and deleted about a day after that day ends.
  • The IP address is never stored. It goes into that code for a moment, then it’s dropped. The visitor’s country comes from Cloudflare’s network, not from keeping the address.

With nothing stored on the device, there’s nothing to ask permission for. See what we collect for the full list.

What about GDPR?

Crustat does handle an IP address for a moment, to make the daily code, so GDPR still applies, but it doesn’t call for a banner. The usual basis is legitimate interest: knowing how your own site is used, done in a way that keeps visitors anonymous and can’t follow them from day to day. We act as your processor, on the terms in our data processing agreement.

It’s still good practice to mention Crustat in your privacy policy, in a sentence or two: that you measure visits with Crustat, that it sets no cookies, and that it stores no IP addresses. You can link to how long your data is kept too.

For visitors in California, Crustat never sells or shares their data, so there’s nothing to opt out of under the CCPA because of it.

The one caveat

This answer is about Crustat only. If your site also runs other tools, like ad pixels, embedded videos, chat widgets or other analytics, those often set cookies of their own and may still need a banner. Check what else your site loads.

Still stuck? Write to hello@crustat.com.

All articles
The mascot waiting

Almost ready

We're opening to everyone soon.

Crustat is in its final checks before we open sign-ups. Leave your email and we'll write once, the day it opens, with your 14 days free waiting.

One email when we open. No newsletter. See our privacy page.