=== GL Consent ===
Contributors: gabbasovlabs
Tags: consent, privacy, cookies, analytics, marketing
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Lightweight consent management with built-in analytics and marketing integrations that load only after visitor consent.

== Description ==

GL Consent is a lightweight consent-management plugin for WordPress. It provides a compact consent banner, a preferences drawer, and built-in integrations for common analytics and advertising services.

Site administrators configure supported services using provider-specific IDs instead of pasting arbitrary JavaScript. An enabled integration is loaded only after the visitor grants consent for its matching category.

Supported Analytics integrations:

* Google Analytics 4
* Microsoft Clarity
* Yandex Metrica
* Hotjar

Supported Marketing integrations:

* Google Ads
* Meta Pixel
* TikTok Pixel
* Microsoft Advertising UET
* LinkedIn Insight Tag
* Pinterest Tag

Features include:

* Compact first-visit consent banner.
* Accept All, Reject All, and custom consent choices.
* Analytics and Marketing consent categories.
* Built-in provider integrations with structured ID-based configuration.
* No custom JavaScript editor and no arbitrary script execution field.
* Consent preference storage in browser localStorage with a first-party cookie fallback.
* 365-day consent lifetime before the visitor is asked again.
* Consent withdrawal handling with page reload when a previously granted optional category is disabled.
* Floating Preferences Button that can be enabled or disabled.
* Left or right Preferences Button positioning.
* Small or standard Preferences Button size.
* Cookie Settings Link trigger using `#gl-consent-settings`, so consent preferences can be reopened from a menu, footer, button, or text link.
* Automatic link to the WordPress Privacy Policy page when one is configured.
* Frontend `glconsent:changed` event for developers and integrations.
* Local plugin assets and locally bundled fonts for the GL Consent admin interface.

GL Consent itself does not send visitor consent state to Gabbasov Labs and does not require a Gabbasov Labs account or cloud service.

GL Consent has a deliberately defined scope. It controls only integrations configured and enabled inside GL Consent. Tracking or third-party services loaded independently by themes, other plugins, tag managers, or custom code are not automatically detected or blocked.

GL Consent is a technical consent-control tool. It does not provide legal advice and does not guarantee compliance with any particular privacy law or regulatory framework. Site owners are responsible for evaluating their own legal and regulatory requirements and for configuring the plugin appropriately.

== Installation ==

1. Upload the `gl-consent` folder to `/wp-content/plugins/`, or install GL Consent through WordPress.
2. Activate GL Consent.
3. Open **GL Consent** in the WordPress admin area.
4. Review the consent texts and general settings.
5. Open the **Integrations** tab and configure any supported analytics or marketing services you want GL Consent to control.
6. Enable each configured integration you want to use.
7. Enable GL Consent on the **Dashboard** tab and save the settings.
8. Test the banner and consent choices on the frontend before using the plugin on a production site.

The floating Preferences Button is enabled by default when GL Consent is enabled. You can disable it and instead place a Cookie Settings Link anywhere on your site using:

`#gl-consent-settings`

Example:

`<a href="#gl-consent-settings">Cookie Settings</a>`

== Frequently Asked Questions ==

= Does GL Consent automatically detect or block trackers already installed on my site? =

No. GL Consent controls only supported integrations that are configured and enabled inside the plugin. Scripts or trackers loaded independently by themes, other plugins, tag managers, or custom code are outside its automatic control.

= Does GL Consent allow me to paste arbitrary tracking scripts? =

No. GL Consent uses predefined provider integrations with structured configuration fields such as Measurement ID, Project ID, Pixel ID, Partner ID, or Tag ID. It does not provide a custom JavaScript execution field.

= When does an analytics or marketing integration load? =

A supported integration must first be configured and enabled by the site administrator. On the frontend, it is loaded only after the visitor grants consent for the matching Analytics or Marketing category.

= What happens when a visitor withdraws consent? =

GL Consent saves the new choice and reloads the page when a previously granted optional category is switched off. On the reloaded page, GL Consent does not initialize integrations belonging to the withdrawn category.

Some third-party services may send a final unload or beacon request from the already loaded page while it is closing. GL Consent prevents those integrations from being initialized again on the reloaded page unless consent is granted again.

= Where is the consent choice stored? =

The consent state is stored in browser localStorage with a first-party cookie fallback. The stored state expires after 365 days.

= How can visitors reopen their consent preferences? =

GL Consent provides two access methods for the same preferences drawer:

* The floating Preferences Button, which can be enabled or disabled and positioned on the left or right side of the screen.
* A Cookie Settings Link using `#gl-consent-settings`, which can be placed in a menu, footer, button, or text link.

= Can I use the Cookie Settings Link without the floating Preferences Button? =

Yes. You can disable the floating Preferences Button and continue to use `#gl-consent-settings` anywhere on the site to reopen the consent preferences drawer.

= Does GL Consent send consent data to Gabbasov Labs? =

No. GL Consent itself does not transmit the visitor's consent state to Gabbasov Labs.

= Does GL Consent require an external GL Consent account or API key? =

No. GL Consent does not require a Gabbasov Labs account, subscription, license server, or cloud API to operate.

= Is GL Consent a legal compliance service? =

No. GL Consent is a technical tool for consent-based loading of supported integrations. Site owners remain responsible for assessing their own legal and regulatory requirements.

== External Services ==

GL Consent can load third-party analytics and marketing services when all of the following are true:

1. The site administrator configures the service in GL Consent.
2. The integration is enabled in GL Consent.
3. The visitor grants consent for the matching Analytics or Marketing category.

GL Consent does not contact these services merely because the plugin is installed or activated. Each integration below is optional. The listed services are independent third parties and may collect or process visitor data according to their own terms and privacy policies after the relevant integration is loaded.

= Google Analytics 4 =

Service provider: Google.

Purpose: Website analytics and measurement.

Runtime domain used by GL Consent: `www.googletagmanager.com`.

When it connects: Only when Google Analytics 4 is configured and enabled by the site administrator and the visitor has granted Analytics consent.

Data that may be sent: Page views, interaction events, device and browser information, approximate location, online identifiers, and other analytics-related usage data, depending on the site owner's Google Analytics configuration.

Privacy Policy: https://policies.google.com/privacy

Terms of Service: https://www.google.com/analytics/terms/

= Microsoft Clarity =

Service provider: Microsoft.

Purpose: Website analytics, heatmaps, and session playback.

Runtime domain used by GL Consent: `www.clarity.ms`.

When it connects: Only when Microsoft Clarity is configured and enabled by the site administrator and the visitor has granted Analytics consent.

Data that may be sent: Page and session information, interaction events, device and browser information, DOM-related information, online identifiers, and other usage data used for analytics and session playback.

Privacy Statement: https://www.microsoft.com/en-us/privacy/privacystatement

Terms of Use: https://clarity.microsoft.com/terms

= Yandex Metrica =

Service provider: Yandex.

Purpose: Website analytics and visitor-behavior measurement.

Runtime domain used by GL Consent: `mc.yandex.ru`.

When it connects: Only when Yandex Metrica is configured and enabled by the site administrator and the visitor has granted Analytics consent.

Data that may be sent: Page and session information, interaction events, device and browser information, cookies and online identifiers, and other analytics-related usage data, depending on the site owner's Yandex Metrica configuration.

Privacy Policy: https://yandex.com/legal/confidential/

Terms of Service: https://yandex.com/legal/metrica_termsofuse/en/

= Hotjar =

Service provider: Hotjar.

Purpose: Behavioral analytics, heatmaps, and related visitor-experience analysis.

Runtime domain used by GL Consent: `static.hotjar.com`.

When it connects: Only when Hotjar is configured and enabled by the site administrator and the visitor has granted Analytics consent.

Data that may be sent: Page and session information, interaction events, device and browser information, online identifiers, and other usage data used for behavioral analytics.

Privacy Policy: https://www.hotjar.com/legal/policies/privacy/

Terms of Service: https://www.hotjar.com/legal/policies/terms-of-service/

= Google Ads =

Service provider: Google.

Purpose: Advertising measurement, conversion tracking, and remarketing.

Runtime domain used by GL Consent: `www.googletagmanager.com`.

When it connects: Only when Google Ads is configured and enabled by the site administrator and the visitor has granted Marketing consent.

Data that may be sent: Page activity, advertising and conversion-related information, device and browser information, online identifiers, and other data used for advertising measurement and remarketing, depending on the site owner's Google Ads configuration.

Privacy Policy: https://policies.google.com/privacy

Terms of Service information: https://support.google.com/google-ads/answer/16875158?hl=en

= Meta Pixel =

Service provider: Meta.

Purpose: Advertising measurement, conversion tracking, audience building, and remarketing for Meta advertising products.

Runtime domain used by GL Consent: `connect.facebook.net`.

When it connects: Only when Meta Pixel is configured and enabled by the site administrator and the visitor has granted Marketing consent.

Data that may be sent: Page views, interaction and conversion events, device and browser information, online identifiers, and other advertising-related usage data, depending on the site owner's Meta Pixel configuration.

Privacy Policy: https://www.facebook.com/privacy/policy/

Business Tools Terms: https://www.facebook.com/legal/terms/businesstools

= TikTok Pixel =

Service provider: TikTok.

Purpose: Advertising measurement, conversion tracking, campaign measurement, audience creation, and related advertising functionality.

Runtime domain used by GL Consent: `analytics.tiktok.com`.

When it connects: Only when TikTok Pixel is configured and enabled by the site administrator and the visitor has granted Marketing consent.

Data that may be sent: Page views, interaction and conversion events, device and browser information, online identifiers, and other advertising-related usage data, depending on the site owner's TikTok Pixel configuration.

Privacy Policy: https://www.tiktok.com/legal/page/row/privacy-policy/en

Terms / service information: https://ads.tiktok.com/resources/help/article/tiktok-advertiser-tools-and-related-terms

= Microsoft Advertising UET =

Service provider: Microsoft.

Purpose: Advertising measurement, conversion tracking, and remarketing through Microsoft Advertising Universal Event Tracking (UET).

Runtime domain used by GL Consent: `bat.bing.com`.

When it connects: Only when Microsoft Advertising UET is configured and enabled by the site administrator and the visitor has granted Marketing consent.

Data that may be sent: Page activity, conversion events, device and browser information, online identifiers, and other advertising-related usage data used for Microsoft Advertising measurement and remarketing.

Privacy Statement: https://www.microsoft.com/en-us/privacy/privacystatement

Microsoft Advertising Agreement: https://help.ads.microsoft.com/apex/index/3/en/60218

= LinkedIn Insight Tag =

Service provider: LinkedIn.

Purpose: Advertising measurement, conversion tracking, audience insights, and remarketing for LinkedIn advertising products.

Runtime domains used by the integration: `snap.licdn.com` and LinkedIn advertising endpoints such as `px.ads.linkedin.com`.

When it connects: Only when LinkedIn Insight Tag is configured and enabled by the site administrator and the visitor has granted Marketing consent.

Data that may be sent: Page activity, device and browser information, online identifiers, conversion-related information, and other advertising-related usage data, depending on the site owner's LinkedIn Insight Tag configuration.

Privacy Policy: https://www.linkedin.com/legal/privacy-policy

LinkedIn Ads Agreement: https://www.linkedin.com/legal/sas-terms

= Pinterest Tag =

Service provider: Pinterest.

Purpose: Advertising measurement, conversion tracking, audience building, and remarketing for Pinterest advertising products.

Runtime domains used by the integration: `s.pinimg.com` and Pinterest endpoints such as `ct.pinterest.com`.

When it connects: Only when Pinterest Tag is configured and enabled by the site administrator and the visitor has granted Marketing consent.

Data that may be sent: Page activity, interaction and conversion events, device and browser information, online identifiers, and other advertising-related usage data, depending on the site owner's Pinterest Tag configuration.

Privacy Policy: https://policy.pinterest.com/en/privacy-policy

Terms of Service: https://policy.pinterest.com/en/terms-of-service

== Screenshots ==

1. Dashboard with plugin status, Cookie Settings Access controls, and integration setup overview.
2. Consent Texts tab for the frontend banner and consent preferences drawer.
3. Integrations tab with supported Analytics and Marketing providers.
4. About GL Consent screen with product information, workflow, scope, and developer reference.
5. Compact frontend consent banner with Accept All, Reject All, and Customize actions.
6. Consent preferences drawer with Analytics and Marketing category controls.
7. Floating Preferences Button in standard and small sizes.

== Changelog ==

= 1.0.0 =
* Initial public release.
* Added a consent banner and preferences drawer with Accept All, Reject All, and custom category choices.
* Added structured Analytics integrations for Google Analytics 4, Microsoft Clarity, Yandex Metrica, and Hotjar.
* Added structured Marketing integrations for Google Ads, Meta Pixel, TikTok Pixel, Microsoft Advertising UET, LinkedIn Insight Tag, and Pinterest Tag.
* Added consent storage with localStorage and a first-party cookie fallback.
* Added 365-day consent expiration and consent withdrawal handling.
* Added an optional floating Preferences Button with left/right positioning and small/standard sizes.
* Added the `#gl-consent-settings` Cookie Settings Link trigger for reopening consent preferences from menus, footers, buttons, or text links.
* Added WordPress Privacy Policy integration and the frontend `glconsent:changed` event.
* Added an internationalization-ready admin interface.
