Proper Ad Tracking + Privacy · Set Up Together for Small Businesses

Your website is tracking visitors.

Is it accurate & compliant?

Ad tracking configured correctly. Privacy consent deployed properly.

Policies drafted to match your tracking practices.

One team. Everything aligned. Done for you.

✓ Fixed-price, no hourly billing

✓ Deployed in 3–5 business days

✓ Bundle, or buy what's needed

✓ Docs matched to your real setup

WHY THIS MATTERS

Three problems.One solution.

Most small businesses treat privacy consent, proper ad tracking, and policy documents as three separate concerns. They aren't. They're three pieces of one solution that either work together or break together.

The Myth vs. The Reality: Privacy and ad performance aren't enemies.

The myth is that privacy compliance hurts your ads. The reality: done right, you can respect your visitors' choices and keep accurate measurement of the traffic you're entitled to measure. A clean setup recovers real conversion data that broken setups lose. It does that without pretending that bypassing privacy controls is the same as protecting privacy.

THE CONSENT PROBLEM

A cookie banner is decoration, not compliance.

Tracking pixels loading with no way for visitors to opt out (CCPA) or opt in (GDPR), and banners that show a pop-up but don't actually block anything. And it's rarely just pixels: session replay, chat widgets, and search fields capture what visitors actually type, which carries different exposure than a pixel does. No record of who consented to what. The pieces that should make consent function aren't there.

THE AD PLATFORM PROBLEM

Conversions never reach your ad platforms.

Often 20–40% of conversions never reach platforms like Meta or Google. Ad blockers and iOS and Safari privacy settings stop the browser pixel from reporting the sale at all. The platform never learns the ad worked, so it keeps optimizing toward whatever it can still see, which is how ad costs drift up.

THE DOCUMENTATION PROBLEM

A privacy policy that doesn't match your site.

A generic template that doesn't reflect your actual tracking, consent setup, or third parties is worse than no policy at all. The mismatch between what your policy says and what your site does becomes its own kind of liability, and it signals that the technical setup underneath isn't right either.

These three problems compound each other. Broken consent leaks the signal your ads need. Missing signal makes your ads cost more. Mismatched policies reveal the broken setup underneath. That's why Iron Consent treats consent, tracking, and documentation as one integrated solution, fixed together so each piece reinforces the others.

A NOTE ABOUT CCPA vs. CIPA, and the demand letters

Most of these letters don't cite CCPA. They cite CIPA, a 1967 California wiretapping law that plaintiffs' firms have been applying to websites. The argument is about timing: if a tracker transmits before a visitor makes a choice, an opt-out link added afterward doesn't undo it.


Two things make it land on small businesses. CIPA has no revenue or size threshold, unlike CCPA, which exempts plenty of small sites outright. CIPA isn't limited to California companies, either. What matters is where your visitors are.


The theory is contested, and courts have gone both ways. We're not going to tell you a lawsuit is coming. But the setup that answers it is the same one that makes your tracking honest: nothing fires until someone chooses, and you keep a record of what they chose.

WHO IT'S FOR

Any small business running analytics or ads.

E-commerce, newsletters & media operators, local service businesses, coaches and course creators, membership sites, and the agencies that serve them. If your website has a Meta pixel, Google Analytics, Microsoft Clarity, Google Ads tracking, a TikTok pixel, or any other marketing technology installed, this is for you. PixelOath works on any website; ConsentProof is currently available for WordPress. And this isn't only for California businesses. What matters is where your visitors are, not where you're registered. If Californians can reach your site, you're in scope.

Our Products. Done For You.

PixelOath

Works on any website.

We configure your ad tracking correctly so your Meta and Google ads, etc. actually have the signal they need to optimize. Proper GTM configuration, server-side event tracking, and clean conversion data. Signals recovered.

ConsentProof

Currently available for WordPress sites.

We install and configure a real consent management platform on your WordPress site, one that actually blocks tracking until visitors consent (GDPR) or removes cookies when they opt out (CCPA). Includes consent logging, Google and Microsoft Clarity consent modes, and custom rules if needed.

Most sites don't need the strictest setting everywhere. We can apply block-until-consent to California visitors specifically and leave the rest of your traffic as-is, so you take the measurement trade-off only where the exposure actually is. We also honor Global Privacy Control, the browser-level signal some visitors send automatically.

DocShield

Accurate to your real setup

Our Privacy Policy and Terms of Service are built on documents developed by experienced compliance counsel, then matched by our team to the actual tracking and consent setup on your site. The documents are the foundation; the matching is the technical work reflecting what we found running on your site. Not a generic template.

HOW IT WORKS

From intake to deployed in under a week.

No sales calls. No custom scoping. No hourly billing. Just a straightforward process.

1: Choose Your Service

Compliance, tracking, legal documents, or the complete bundle. Clear pricing, no surprises.

2: Complete Intake

A short intake form captures your site platform, ad channels, current tracking tools, and access, then we audit what's actually live.

3: We Deploy

A trained specialist configures everything on your live site. Your documents are generated from the real deployment data.

4: QA & Handoff

Every deployment is tested against our QA checklist and verified from the regions that matter. You're enrolled in Guardian for Year 1.

WHY IRONCONSENT

The technical setup and the legal documents,

done by the same team.

Your consent system, ad tracking, and privacy policy all match, because one team set up all of it.

Fixed price, no surprises

You know exactly what you're getting before you start. No hourly billing, no scope creep, no discovery calls. Pick your service, complete intake, and we deploy.

Deployed in days, not weeks

Most deployments are complete within 3–5 business days. We follow a proven playbook. We're not figuring it out as we go.

Consent logging creates your evidence trail

We don't just install a cookie banner. We enable consent logging that creates time-stamped records of every visitor's choice.

Your tracking gets better, not worse

A properly configured stack, with server-side tracking, Consent Mode v2, and clean event routing, recovers conversion data that technical blocking loses to browsers and devices, so the ad platforms can do their job. We recover the data you're entitled to, never the data someone asked you not to take.

Documents built by experienced compliance counsel

Your privacy policy and terms of service aren't spun up by a free online tool. They're built on documents developed by experienced compliance counsel, and our team matches them to the actual tracking and consent setup we find on your site. We're not a law firm and don't provide legal advice or representation.

We prove your setup works. We don't just flip switches.

A dashboard shows what's configured; the live site shows what's actually happening, and they aren't always the same. We test your site from the regions that matter, confirm tracking stops when someone declines, and save dated proof. That includes the tools people forget to check, like session replay and chat widgets. Some failures never show up in a browser, like tracking that keeps running after an opt-out, so we check those at a deeper level too.

FREQUENTLY ASKED QUESTIONS

Common questions, straight answers.

How is this different than just installing a cookie banner plugin?

A cookie banner plugin gives you software. We give you a correctly configured system. Most cookie banners are cosmetic: they show a pop-up but don't actually block tracking until consent (GDPR) or remove cookies on opt-out (CCPA). We install the consent platform, configure it to control your tracking through Google Tag Manager and Consent Mode v2, enable consent logging for proof, verify the blocking works from the regions that matter, and provide documents that match your setup. The plugin is one piece; we deploy and test the complete stack.

Do I really need this if I'm a small business?

If you run any digital advertising, it's worth getting right. You're likely losing conversion data you paid for, which drives up your costs. And there's a real backdrop: California law firms have been sending demand letters to small business sites that run tracking pixels without a working consent mechanism, and a $10,000 settlement demand isn't theoretical; it's what some newsletter operators and small business owners we know have received. A setup where nothing transmits without consent is the straightforward answer.

What platforms and ad channels do you support?

PixelOath (ad tracking setup) works with any website: WordPress, Shopify, Squarespace, custom-built, or anything else that supports Google Tag Manager. The base price includes one ad platform fully configured. You choose Meta, Google Ads, TikTok, Pinterest, or another platform. Each additional ad platform is a flat $179 one-time setup fee. ConsentProof (privacy compliance setup) is currently available for WordPress sites. If you're on a different platform and need tracking only, PixelOath has you covered.

How long does deployment take?

Most deployments are complete within 3–5 business days from when we receive your intake form and site access. Complex setups with many tracking tools or custom configurations may take a little longer. We'll set expectations during onboarding.

Will this affect ad performance?

In most cases it improves. If you run Meta ads without the Conversions API, you lose conversion data whenever an ad blocker or an iOS or Safari privacy setting blocks the browser pixel from reporting, and you lose some matching when Safari expires the cookie that ties a later sale back to its ad. Both happen even for customers who were fine being measured, and our server-side setup recovers much of it. What we don't do is override anyone who opted out. On the consent side, the honest answer depends on your setup and where your visitors are, and we'll walk you through the trade-offs rather than promising you can track everyone. The goal is accurate measurement of the traffic you're entitled to measure.

What is Google Consent Mode v2, and will it recover conversions I lose to opt-outs?

Consent Mode v2 is how Google's products respond to a visitor's consent choices, and it's required for EEA and UK traffic. It runs in two modes, and the difference matters. In Basic mode, Google's tags don't fire until consent: nothing is sent, and nothing is modeled. In Advanced mode, tags send anonymized, cookieless pings even before consent, and Google can model some of the conversions lost to opt-outs, but only above its minimum traffic thresholds, so many smaller sites won't see modeled conversions regardless. We'll tell you honestly which mode fits your traffic and your risk tolerance, since Advanced mode means anonymized data is still transmitted before consent.

What is server-side tracking, and is it more private?

Server-side tracking sends conversion events from your server to the ad platforms via APIs (Meta's Conversions API, Google's enhanced conversions, and equivalents) instead of relying only on browser pixels, which get blocked by ad blockers, Safari ITP, and iOS restrictions. So it recovers signal the browser loses. One honest clarification: personal data is hashed in transit, which is a security best practice, but hashed identifiers sent to a platform for matching are still personal data under most laws, so server-side tracking is a reliability and security gain, not a privacy exemption. Whether it's appropriate for your situation is part of what we assess, and either way we verify it respects opt-outs.

Does this cover session replay, chat widgets, and form inputs?

Yes, and they deserve separate attention. Most of the conversation about tracking risk focuses on pixels and analytics beacons, which send routing data like IP addresses. But tools that capture what a visitor actually types or does, session replay and heatmaps, chat widgets, and search or form fields that send input to a third party before submission, fall into a different legal category than a pixel does, and they're treated differently.


Practically, that means a tool like Microsoft Clarity or a live chat widget deserves more careful gating than a conversion pixel, not less. When we audit your site, we identify which category each tool falls into and configure the blocking accordingly.

Can I track California visitors by default?

Technically, yes: California's CCPA is an opt-out law, so tracking by default with a clear way to opt out is allowed, and many sites run it that way. But there's a trade-off worth understanding. The demand letters going around small businesses tend to rely on a different rule, a wiretapping theory (CIPA), that turns on data being transmitted in the first place, regardless of cookies. A track-by-default setup transmits before anyone opts out, which is the exposure those firms target. A block-until-consent setup avoids it but gives up some measurement on people who don't agree. Neither is automatically "right"; it depends on where your visitors are and how cautious you want to be. We'll lay out both plainly and set up whichever you choose, rather than quietly picking the riskier one for you.


Worth knowing: this theory is contested. Courts have gone both ways, and legislation moving through the California legislature could narrow part of it. We're not going to tell you a lawsuit is inevitable. What we can tell you is which configuration choices reduce your exposure and what each one costs you in measurement.

What should I do if I receive a demand letter?

Don't ignore it, and don't rush to settle because there's a deadline attached. Two things matter first. Preserve everything before you change anything: the letter, your current site configuration, what's running, and your consent logs. The state of your site when the letter arrived is what's relevant, and changing it first can make the picture harder to establish.


Then take it to an attorney who works in this specific area and let them direct the fact-finding, including whether the tracker named was actually running on your site and when it fired relative to consent. These claims rest on a legal theory courts are still split on. A letter is a private demand from a law firm, not a finding that you did anything wrong.


If you're an existing client, your consent logs give your attorney time-stamped records for the timeline they'll need. We're not a law firm and can't advise you on the letter itself, but we can help you document what your setup actually does.

Why don't my GA4 numbers match my Meta Ads Manager?

Because they measure different things by different rules. Meta uses a 7-day-click + 1-day-view window; GA4 defaults to data-driven attribution over a 90-day lookback with last-non-direct-click as the fallback. Meta deduplicates on its own cross-device user graph; GA4 relies on a user_id most sites haven't configured. And client-side analytics get blocked more than server-side APIs. None is "wrong"; the gaps are information. Optimize campaigns against the ad platform's number, measure revenue against your backend or GA4, and reconcile monthly. We rebuild the stack so each number is individually correct.

Are the Privacy Policies and Terms of Service real legal documents?

They're built on documents developed by experienced compliance counsel, and our team matches them to the specific tracking technologies, consent setup, and data flows we find on your site, not generated from a free online tool. The documents are the foundation; the per-site matching is technical work, reflecting what's actually running. We're not a law firm and don't provide legal advice or representation, and we always recommend you have your own attorney review any legal documents.

What is Guardian and what does it cover?

Guardian keeps your compliance and tracking current as the regulatory and ad landscape shifts. Your first year is included with every package. It covers semi-annual compliance and tracking checks plus hands-on platform updates whenever Google, Meta, or consent tools push changes that affect your configuration. After Year 1 it renews at $99/year per product, $149/year for either two-product pairing, or $199/year flat for the Complete Setup. Priority Guardian ($299/year) adds quarterly checks, written audit reports, priority change response, and emergency fixes. You cancel Guardian at any time so it doesn't renew for another year.

Can I just buy PixelOath without ConsentProof?

Absolutely: all three services are available individually. That said, when we set up your tracking through GTM, we're positioned to see whether your consent management is properly configured, and we'll tell you if it isn't. Some clients start with one service and add the others later.

Stop hoping your site is compliant.

Start knowing it is.

Fixed price. Deployed in days. Documents matched to your real setup. First year of Guardian included.

Iron Consent provides technical implementation services and documents built on templates developed by experienced compliance counsel. We are not a law firm, we do not provide legal advice or representation, and using this site or purchasing our services does not create an attorney-client relationship. The compliance counsel who developed our document templates does not represent our clients. Content on this site is for general information only and is not a substitute for advice from your own attorney regarding your specific situation. Privacy law is unsettled and evolving; we do not guarantee any legal or compliance outcome.


Copyright 2026 - Iron Consent