Consent categories
setConsent() takes four booleans: analytics, marketing, preferences, and sale.
Call it before init(). The SDK stores the choice and applies it at initialization.
marketing or sale also stops Stripe link
decoration and unloads container iframes.
Until consent arrives, the SDK holds the anonymous ID in memory only. It writes no cookie
and no localStorage entry.
Browser privacy signals
A first-party tracking domain also suppresses the server
__dl_visitor_id cookie when the
request carries Sec-GPC: 1, DNT: 1, or X-DL-Consent: denied.
Opt-out
privacyMode: 'strict' forces Auto Identify off and stops email prefill on Stripe links.
Turn it on in Settings → Identity & Attribution with the Strict mode toggle.
What Datalyr stores
Erase one person’s data
A Shopifycustomers/redact or shop/redact webhook starts an erasure job. Datalyr also
accepts a manual request at [email protected].
An erasure never runs workspace-wide, so you can’t wipe a workspace by accident. Every
delete carries the workspace ID plus at least one identifier of that person.
Filter outgoing ad events
Turn on Filter health-related fields in Settings → Privacy & redaction. Existing and new rules inherit the setting; you do not need to recreate them. Eligible server conversions continue, while Datalyr-managed Meta, Google and TikTok browser pixels stay off. Use Advanced controls to pause sharing or record a platform notice. Filtering does not guarantee platform approval or change data already collected. Read the setup guide. To limit collection itself, use Filters.Verify your posture
- Open your site in a private window with consent denied.
- Open Live and confirm no event arrives.
- Grant consent.
- Reload and confirm the
pageviewarrives. - Turn on GPC in a test browser.
- Reload and confirm no event arrives.
- Call
datalyr.reset()and confirm Users shows a newdistinct id.
When it does not work
Next
- Health and wellness privacy controls: review sharing, pause delivery, and apply restrictions or filtering.
- Filters: stop collecting a page or an IP entirely.
- Web SDK: the full consent and opt-out method list.