Private and compliant, by design.
In the default cookieless mode there is no personal data to leak, because none is collected, and no consent banner to maintain. Turn on cookie mode per site when you need cross-session identity, and then you do need consent. Encrypted in transit either way.
Safe by design.
No personal data by default
Cookieless out of the box, so there is nothing personal to leak. Cookie mode is a per-site opt-in.
Encrypted in transit
Every request is TLS, end to end, no exceptions.
Runs at the edge
Processed close to the visitor on Cloudflare's network.
Access controls
Per-site access and SSO on Business plans.
Daily backups
Your data is backed up and retained per your plan.
GDPR, CCPA, PECR
The default cookieless mode needs no consent banner. Cookie mode does.
Where your data lives.
Collected
A salted signal that rotates daily, or a first-party cookie if you turn cookie mode on.
Processed
At the edge, bots filtered, deduped.
Stored
Encrypted, retained only as long as your plan.
Yours
Exportable anytime, deletable on request.
Your first visitor is already here.
Drop in the script and watch them land. It takes about a minute.