Cookie Consent That Is Actually Compliant
GDPR cookie consent setup that audits every cookie your site loads, blocks non-essential scripts until a visitor agrees, records each consent, and implements Google Consent Mode v2 correctly. Built for law firms, healthcare, and financial services, where a banner alone is not compliance.
Some of our direct clients
Why Regulated Businesses Work With Us
Cookie consent that is technically correct and genuinely compliant, built by people who understand both the code and the regulatory scrutiny your sector faces.
Full Cookie Audit
We scan and manually verify every cookie and tracking script your site loads, including third-party scripts you may not be aware of.
Correct Script Blocking
Analytics, marketing, and functional scripts are blocked until the visitor gives consent for that category. Not just a banner, actual technical enforcement.
Google Consent Mode v2
Proper Google Consent Mode v2 implementation preserves conversion tracking accuracy while fully respecting visitor consent choices.
Consent Records
We configure consent logging so you have a verifiable record of consent for each visitor, demonstrating compliance in any regulatory inquiry.
Easy Withdrawal of Consent
Visitors can change or withdraw consent at any time through an accessible preference centre, as required under UK GDPR.
Regulated Sector Experience
We understand the additional scrutiny that law firms, healthcare, and financial services businesses face and configure accordingly.
The Platforms We Make Genuinely Compliant
WordPress, WooCommerce and custom sites, set up with real script blocking, consent records and Google Consent Mode v2. We work across every major consent management platform rather than defaulting to one.
Laravel & Bespoke Platforms
For systems and platforms that require bespoke processes, data handling complex integrations or internal business platforms with security at the forefront of the build.
WordPress & WooCommerce
For fast, reliable and easy to manage brochure based websites built following best practice with a bespoke theme powered by ACF Pro and supporting custom built plugins.
Shopify & Shopify Plus
For eCommerce and retail brands looking to grow revenue significantly online. Built using a bespoke theme specific to your brand and with a full seamless migration from legacy platforms.
Recently Completed Projects
QualityHive
A Laravel platform that web agencies use to capture, assign and close website bugs, taken from wireframe to launch, then handed over as clean, documented code.
SaaS platform · Laravel · API integrations
Clintons Cards
A full migration from Magento 2 to Shopify Plus, with order, customer, product, stock and finance integrations kept live through the switch.
Ecommerce · Shopify Plus · Integrations
The Sauce Foundry
A brand, a WooCommerce store and product photography for an artisan hot sauce startup, launched to a 3.8% conversion rate from day one.
Ecommerce · Branding · WooCommerce
A Website QA Platform Built To Scale
QualityHive came to us with an idea and a waiting list. We built them a Laravel platform that web design and development agencies now use to capture bugs straight from a client's website, assign them to developers and close them off, and handed it over as clean, documented code.
The Brief
Agencies were collecting website feedback the hard way: long email threads, shared spreadsheets and screenshots pasted into documents. Nothing was assignable, nothing was searchable, and the same bug was often reported three times by three different people.
QualityHive needed a platform an agency could roll out to a client in minutes, with a browser extension that captures a bug straight from the page, complete with a screenshot, the exact URL and the browser and screen it happened on, and an API their clients' project tools could talk to.
What We Built
One platform, three jobs: capture a bug on the page, triage it with the team, prove it fixed to the client.
Point-And-Click Capture
A browser extension pins a bug straight onto the client's site, grabbing a screenshot, the exact URL and the browser, OS and screen size, so nobody has to describe where it happened.
Assignment And Triage
Every bug routes to a developer with a status, a due date and a full comment thread. Duplicates are caught as they are raised, on a board the whole team shares.
Client-Ready Reporting
Open bugs, resolution rates and project progress export as clean, branded reports, which is what QualityHive's own agency customers renew on.
Roles And Permissions
Agency, developer and client each see their own view of a project, with per-project access managed by the account owner.
Billing And Trials
Per-seat subscriptions, trial expiry and proration wired through Stripe, so the team can price without touching code.
A Documented API
A REST API with webhooks and written docs, so their customers' project tools can pull bug data without our involvement.
How We Ran It
Four stages, weekly demos, and direct access to the developer writing the code. No account managers in between.
Two workshops with real agency feedback in hand, then a written spec and a fixed quote.
Every screen agreed in grayscale before a line of Laravel, so changes cost minutes rather than sprints.
Fortnightly releases to a staging site the team could hand to pilot customers and comment on directly.
Repository, environment notes and API docs transferred, with a retained day a month for support.
The Result
QualityHive launched to their pilot agencies in week 14 and replaced the email-and-spreadsheet routine entirely. Feedback that used to take an evening to chase down is now captured in a click from the page it happened on, and the API means larger customers can pull bug data into their own reporting without asking anyone.
We still support the platform on a retained day a month, and the code sits in their repository, not ours.
We built QualityHive because website QA was still being run through email threads and spreadsheets. Now an agency captures a bug in a click straight from the page, assigns it and closes it off, all in one place. It has become the tool teams open first thing in the morning, which is exactly what we set out to build.
Head of Product, QualityHive
From Magento To Shopify Plus
We had supported Clintons Cards on Magento 2 for years. When the platform started to hold the business back, we migrated the whole storefront to Shopify Plus, kept every integration running through the switch, and lifted both conversion and revenue in the process.
The Brief
Clintons Cards had been running on Magento 2 for years, a platform we knew inside out from supporting it day to day. It had become slow to change, expensive to host and awkward to extend, and every peak trading period turned into a stress test the business would rather not sit.
They wanted to move to Shopify Plus without losing a single order, customer record or product, and without breaking the integrations their operation depends on, including the stock and finance link into their internal financing platform.
What We Built
A clean Shopify Plus storefront, and the integration layer that kept the business running through the switch and after it.
Magento to Shopify Plus Migration
Every product, customer and historic order moved across to Shopify Plus, mapped and reconciled, so nothing was lost and customers noticed only a faster, cleaner store.
Order and Customer Sync
Orders and customer records flow between Shopify and the back office in real time, so the operation runs on one source of truth rather than nightly exports.
Product and Catalogue Integration
Product data, variants and pricing stay in step across systems, so the catalogue is managed once and is right everywhere it appears.
Stock and Finance Integration
A live link into their internal financing platform keeps stock levels and financials aligned, so what the store sells and what the business reports never drift apart.
A Resilient Peak
Shopify Plus takes the hosting and scaling worry off the table, so Christmas and Valentine's peaks are handled by the platform rather than a late night on call.
A Clean Handover
The store, the theme and the integration layer were documented and handed over, with us on hand through the first peak and beyond.
How We Ran It
A migration with no big-bang risk: mapped, staged, tested against real data, then switched over in a controlled cutover.
We mapped every Magento entity, integration and custom flow, using what we already knew from supporting the platform.
The Shopify Plus store and the integration layer were built and wired to a staging environment running real, anonymised data.
Products, customers and order history were moved and reconciled, with counts checked on both sides before anyone signed off.
A controlled switch with the integrations live from minute one, and us watching the first orders land.
The Result
Clintons Cards moved off Magento onto Shopify Plus with no lost data and no gap in trading. Conversion rate rose by over three percent and revenue was up fourteen percent, on a store that is faster to shop and far easier for the team to run.
The integrations that keep stock, finance, orders and customers in step came through the migration intact, and we still support the platform as the business grows.
Migrating a retailer the size of Clintons Cards is where these projects usually come unstuck. The volume of orders, customers and SKUs leaves nowhere to hide, but we moved the lot to Shopify Plus with the integrations live throughout, not a record out of place, and the store came out faster and trading better than it went in.
Development Director, Zestcode
A Hot Sauce Brand Launched To Sell
The Sauce Foundry came to us as a startup with a great product and not much else. We built the brand, designed and built the store, sorted the product photography, and launched them to a 3.8% conversion rate from day one.
The Brief
The Sauce Foundry is an artisan hot sauce maker that arrived as a startup: a strong product, a founder with a vision, and no brand or store to sell it through. They needed the lot building from scratch, and they needed it to convert from launch, not eventually.
That meant more than a website. It meant an identity that looked established on day one, product photography good enough to sell a flavour through a screen, and a store built around the buy rather than bolted on after.
What We Built
A brand, a store and the photography to sell it, delivered together so nothing looked stitched from separate suppliers.
A Brand From Scratch
We shaped The Sauce Foundry's identity from the name outward, the logo, palette and voice, so a new maker turned up to market looking like it had been there for years.
A Store Built To Convert
A clean, fast storefront designed around the product and the buy, which is why it launched at a 3.8% conversion rate rather than slowly growing into one.
Product Photography, Sorted
Great sauce needs great photography, so we put them in touch with a photographer we trust and art directed the shots the store was built around.
Ready For Launch Day
Payments, shipping and stock were set up and tested so the very first order could land the moment the doors opened, not a week later.
Fast And Cached
Hosting tuned with server-level caching, so a small team is not paying enterprise bills and the store stays quick even when a new sauce takes off.
Room To Grow
Built on WooCommerce, so The Sauce Foundry owns the store outright and can add products, wholesale and subscriptions as the range expands.
How We Ran It
Brand first, then a store built around it, then a launch that was ready to sell from the first click.
We got to know the range, the maker and the customer, then agreed the brand direction and the shape of the store.
Identity, packaging cues and tone of voice, so the look was locked before a single page was designed.
The WooCommerce store designed and built around the products, with the photography we art directed dropped straight in.
Payments, shipping and analytics tested, then a clean launch, live and selling from day one.
The Result
The Sauce Foundry launched to a 3.8% conversion rate from day one, a figure plenty of established stores work years to reach. A brand new maker arrived at market looking the part, with a store that sold from the first visit.
We handled the brand, the build and the product photography together, and left them with a WooCommerce store they own outright and can grow into as the range and the business expand.
We came to Zestcode with a product and little else, and they handed us back a brand and a website we are genuinely pleased with. It looked the part from launch and, more to the point, it sold from launch.
The Sauce Foundry
Here's What Our
Clients Say
Consistently rated 5* on Google by our full build clients and retainer clients.
GDPR Cookie Consent FAQs
GDPR Cookie Consent Setup for Regulated UK Businesses
Most cookie banners look compliant and are not. If you work in a regulated sector, the questions worth asking are whether scripts are genuinely blocked before consent, whether your consent records would stand up to scrutiny, and whether analytics still works once you do it properly. Here is how we handle each.
Why a cookie banner on its own is not compliance
Under UK GDPR and PECR, consent has to be given before non-essential cookies and tracking scripts run. A banner that sits on top of a page while Google Analytics, Meta Pixel, and various marketing tags have already fired is decorative, not compliant. The consent it collects is meaningless because the tracking happened regardless.
This is the single most common problem we find. The banner is present, it looks professional, and behind it nothing is being blocked. Regulators and complainants can see this in seconds using browser developer tools, and increasingly they do.
Compliance means the technical behaviour of the site matches what the banner claims. That is the difference between visually compliant and genuinely compliant, and it is the whole point of what we do.
What a cookie audit actually involves
We start by loading your site the way a regulator would and recording every cookie, script, and network request it makes, category by category. Automated scanners catch some of this, but they miss cookies set only after interaction, cookies dropped by embedded content, and third-party tags loaded by other tags. We verify manually as well.
The output is a full inventory: what each cookie is, who sets it, what it is for, how long it persists, and which consent category it belongs in. That inventory is the foundation for everything else, because you cannot block or document what you have not found.
Many sites are running scripts nobody remembers adding, left behind by an old campaign or a plugin. The audit surfaces those too, so you know exactly what is on your site.
Blocking scripts before consent, not just after
This is the part that makes a setup real. Analytics, marketing, and functional scripts are prevented from loading at all until the visitor consents to that specific category. If someone accepts analytics but declines marketing, only analytics runs. If they decline everything, only strictly necessary cookies remain.
Doing this correctly means intercepting scripts before the browser executes them, handling tags injected through Google Tag Manager, and dealing with the awkward cases like embedded videos and maps that set cookies of their own. It is closer to development work than configuration.
We test the result the same way a regulator would, by inspecting network activity before and after each consent choice, so we can show the blocking works rather than assume it does.
Not sure your banner is actually blocking anything?
Most sites we look at load analytics and marketing tags before anyone clicks accept. Send us the URL and we will tell you honestly what is firing early and what it would take to fix.
Google Consent Mode v2 done properly
Google Consent Mode v2 is now required for advertisers using Google services in the UK and EEA, and it changes how consent and tracking interact. Instead of simply blocking Google tags, the tags load in a restricted state and respect the visitor's choices, sending pings without cookies when consent is declined.
Configured correctly, this preserves a usable level of conversion and analytics data through Google's modelling while fully honouring consent. Configured badly, it either leaks data it should not or destroys your reporting entirely.
We wire the consent signals from your platform into Consent Mode so the two agree, then verify the correct default and update states are firing. If your setup also involves tracking that feeds a CRM or ad platform, that often overlaps with our API integrations and business automation work.
Consent records and documentation for your DPO
Collecting consent is not enough on its own. UK GDPR expects you to be able to demonstrate that consent was given, freely and for a specific purpose. We configure consent logging so each visitor's choice, the categories they agreed to, the timestamp, and the version of the policy in force are recorded and retrievable.
We also give you plain documentation of what was built: the cookie inventory, the categorisation decisions, and how blocking and Consent Mode are configured. If a complaint or an ICO enquiry lands, your DPO has an answer ready rather than a scramble.
For law firms, healthcare providers, and financial services businesses, this evidence trail is often the point. It is the difference between saying you are compliant and being able to prove it.
Choosing a platform and keeping it maintained
We are not tied to one consent management platform, but we do have a recommendation for most regulated sites, and our CookieYes setup and configuration work covers that in detail. The platform matters less than how it is implemented; a good CMP configured carelessly is still non-compliant.
Cookies change. New plugins, new marketing tags, a new embedded tool, and your inventory drifts out of date. A setup that was compliant in January can quietly stop being so by summer, without anyone touching the banner.
We leave you with a setup that is correct on the day and documented so it stays maintainable. If you would rather not track it yourself, ongoing checks fit naturally alongside our WordPress support retainers, so your consent setup is reviewed as the site evolves.
Partner with Zestcode for Industry Leading Quality and Reliability
Tell what you're looking for and we'll see you how we can help. Quotes are typically provided within 2 working days of the initial call.