Handshake
Consent before the click. We block trackers until your visitor says yes.
A wave of privacy lawsuits is hitting ordinary business websites for tracking people before they agree to it. We built Handshake to close that gap. It holds every ad and analytics tracker until a visitor opts in, honors their privacy choices, and keeps the receipt. We run it on every client site we manage, and we can put it on yours too.
Your cookie banner might not be
doing its job.
Most consent banners ask politely while the trackers fire anyway. Google Analytics, the Meta pixel, ad tags, and chat widgets load the moment the page opens, long before anyone clicks "accept." That gap, tracking before consent, is exactly what a growing wave of privacy lawsuits is built on.
Handshake works the other way around. Nothing non-essential runs until your visitor opts in. The banner is not decoration. It is the gate, and on the other side of it the trackers are actually held.
Statutory damages: California Penal Code § 637.2(a). Privacy-law thresholds: California Civil Code § 1798.140(d)(1), as adjusted January 2025. Handshake is a technical control, not legal advice. Whether any law applies to your business is a question for your attorney.
- ✕ Google Analytics fired
- ✕ Meta Pixel fired
- ✕ Google Ads tag fired
- ✕ Session recorder fired
It holds the trackers, then honors the choice.
Handshake sits in front of every non-essential tracker on your site and keeps it switched off until a visitor agrees. When they choose, it remembers, it respects privacy signals their browser already sends, and it keeps a timestamped record of what was agreed. Built once, working on every page.
Blocks Until Opt-In
Known trackers are switched off until consent, by neutralizing their scripts so the browser will not run them. Nothing fires first and asks later.
Catches the Big Ones
Google Analytics, Google Ads, Meta, LinkedIn, X, AdRoll, the common WordPress analytics plugins, and our own Trace, however they were added to the site.
Consent Mode v2
Runs Google Consent Mode v2 in default-deny: ad and analytics storage start denied and are upgraded only when a visitor opts in.
Honors Global Privacy Control
If a visitor's browser is already sending the GPC privacy signal, Handshake reads it and treats it as an opt-out, automatically.
Do Not Sell or Share
A clear "Do Not Sell or Share My Personal Information" opt-out, the control California shoppers are entitled to ask for.
Proof of Consent
Every decision is logged with a timestamp, what was agreed, and a truncated IP for privacy. If anyone asks what a visitor chose, you have the receipt.
We did not wait to be asked.
When the lawsuit wave reached our clients, we built Handshake and put it on their sites the same day. These are real numbers from that rollout.
Every site we run is serving Handshake and holding trackers until consent. Live on standandstretch.ai and standandstretch.com too.
Block. Ask. Honor. Keep the receipt.
Handshake is four moves working together, from the first byte of the page to the record you can pull months later. Each one is real, and each one is on by default.
1. Block first
Before any tracker can load, Handshake neutralizes the known ones and tells Google's tags to stay denied. Default is off.
2. Ask clearly
The visitor gets a clean, on-brand banner. Accept, reject, or choose by category. No dark patterns, no pre-checked boxes.
3. Honor the choice
On opt-in, the right trackers turn on. If their browser sends GPC, that is respected as an opt-out without them lifting a finger.
4. Keep the receipt
Every decision is logged with a timestamp and a truncated IP, to a private store, so there is a record of what was agreed.
We built it. We run it. We do not rent it.
Most agencies bolt on a monthly consent subscription and hope it is configured right. We built Handshake on a trusted open-source core and added the layer that actually matters, the blocking, the privacy signals, the record. It is our own product, and it is open source.
A banner that only asks
- Trackers fire on page load anyway
- Consent is recorded after the fact
- No real block, just a popup
- Carries another company's branding
- A monthly fee for a checkbox
A generic plugin
- Set-and-forget, rarely verified
- One-size config across every site
- Misses trackers added by the theme
- No proof-of-consent you can pull
- You are on your own to tune it
Handshake
- Trackers held until a real opt-in
- Consent Mode v2 default-deny
- Honors GPC and Do Not Sell
- Proof-of-consent, logged and kept
- We install it, run it, and watch it
Built on the MIT-licensed CookieConsent engine, with our own prior-blocking, Consent Mode, privacy-signal, and logging layer on top. Open source under GPL-2.0.
See what your site is doing before consent.
Give us your URL and we will scan it for trackers that fire before a visitor agrees, the gap the lawsuits are built on. We send you exactly what we find, in plain English. No obligation. If you want it closed, we will install Handshake for you and run it.
Handshake gives you technical controls, not legal advice. For a privacy program, we recommend your counsel review the configuration.
Handshake is one part of how we work.
Handshake is the consent layer of our in-house marketing intelligence model, the same system that audits sites, tracks behavior with permission, and keeps your work moving. Each tool does one job well, and they all talk to each other.
The Platform
The intelligence model behind your reporting, data, and client work.
Trace
See what visitors do on your site, only after they have opted in through Handshake.
Packet
Hyper-targeted direct mail that puts a researched postcard in the right hands.
Ping
Your marketing, one text away. Pull a report or send a request in plain words.
Route
One brief becomes native posts across your channels, with you approving each one.
Find out what your site is doing behind the banner.
We will scan your site for trackers firing before consent and send you what we find. If you want it fixed, we will install Handshake and run it for you, the same way we protect every client site we run.