Proje vitrini hazırlanıyorPreparing project showcaseПодготавливаем витрину проекта

CRM Basics

Cookie policy & privacy notice

A general, plain-language guide to informing website visitors lawfully: the difference between a cookie policy and a privacy notice, a good banner, and practical setup steps.

Rocketly · 2026-07-19

The moment a visitor lands on your site, before they read a single line, their browser may already be collecting cookies. That little box at the bottom of the screen — the one most people dismiss without reading — sits where trust and transparency meet. A clear cookie policy and privacy notice lives there, giving the visitor an honest answer to a simple question: what are you collecting from me, why, and for how long?

This article walks through, in general terms, how a small business can inform its website visitors lawfully and transparently: what a cookie is, how a consent banner should behave, what belongs in each document, where to start, and where people slip up. One note up front — this is general guidance, not legal advice. Rules change over time and differ by country, so for anything important, check current sources and ask a professional.

A cookie policy and a privacy notice are not the same thing

Most site owners blur the two and hope a single page covers everything. They do different jobs. The privacy notice is the wide frame: who processes your personal data, for what purpose, on what legal basis, how long it is kept, who it is shared with, and what rights the person has. The cookie policy is the narrower, technical slice focused on the cookies and similar trackers on your site.

A simple analogy: the privacy notice is the floor plan of the whole house; the cookie policy is the small sign explaining what the camera at the door records. One never replaces the other.

  • The privacy notice covers every point where you collect data: a contact form, an order, a newsletter sign-up, even the first message someone sends you on WhatsApp.
  • The cookie policy explains only cookies, pixels and similar browser-storage technologies, listing each one's name, purpose and lifespan.

So what exactly is a cookie?

A cookie is a small text file your site leaves in a visitor's browser. Some are essential — they keep a cart full or a login session open. Others track a visitor across sites to serve ads. Treating them all as one category is the most common mistake.

They fall roughly into four groups, and that split decides how your banner should behave:

  • Strictly necessary cookies keep the site working — cart, login, security. They usually do not need separate consent, but are still disclosed.
  • Functional cookies remember comfort settings such as language, region or text size.
  • Analytics cookies measure how many people arrive and which pages they linger on.
  • Marketing cookies profile the visitor for retargeting and advertising — the most sensitive of the four.

There is also origin: first-party cookies set by your own domain, versus third-party cookies from an ad network, a social button or an external analytics tool. Third-party ones usually need more explanation and, in many places, explicit consent.

How a good cookie banner behaves

A bad banner corners the visitor: a huge "Accept All" button, and to refuse, a link buried three menus deep. That "dark pattern" erodes trust and, in many jurisdictions, does not count as valid consent at all.

A good banner follows a few principles. The most important: non-essential cookies should not fire before the visitor makes a choice. Analytics and marketing cookies wait until someone actually clicks "Accept." In places like the EU, rules along the lines of the GDPR expect that explicit consent — but the detail depends on where your visitors sit, so check what applies to you.

Accepting should be no harder than refusing — same screen, same size, one click.

In practice, a good banner says plainly what it collects, offers "Accept all" and "Reject all" with equal weight, allows choice by category, and links to the full cookie policy. Withdrawing consent later should be just as easy as giving it.

1Visit2Banner3Choice4Cookies
Non-essential cookies wait until the visitor has made a choice.

What goes into a cookie policy

A cookie policy is technical but should still be readable. A visitor ought to see, in a clear table, what each cookie does. It usually contains:

  • A cookie inventory and purposes: the name of each cookie, what it is used for, and which category it falls into.
  • Retention period: how long the cookie stays in the browser — a single session, or months.
  • Third parties: who you share data with, such as measurement, advertising or chat tools.
  • Ways to control it: how the visitor can change consent or clear cookies from their browser.

Keeping that list current matters. Every time you add a new chat widget or ad pixel, new cookies usually arrive with it — and the policy needs to reflect that.

What a privacy notice contains

The privacy notice is a broader promise: it tells a person, in plain language, what happens to their data. Its contents come down to a handful of headings, which the diagram below brings together.

PrivacynoticeWho processesWhat dataPurposeLegal basisYour rights
A good notice answers all of these in plain language.

The notice works when it is written in the customer's language, not a lawyer's. Retention and who the data is shared with belong there too. The rights the person holds are the heart of it: to access their data, correct it, ask for it to be deleted, and a way to make that request — usually an email address or a form.

The honest caveat, again: which data rests on which legal basis varies from business to business — the most technical part of the rules. Rather than copying a generic template blind, adapt it to your own data flows — and if you are unsure, ask.

Collect customer data the right way from day one

Rocketly helps you keep data from forms and messages in one place, with the consent record beside it

Explore Rocketly

How a small business sets this up in practice

The good news: you do not need a legal department. A sensible sequence gets most small businesses started.

  1. Scan your site to see which cookies actually run. The surprises are usually trackers added years ago and long forgotten.
  2. Sort them into categories: label each cookie as necessary, functional, analytics or marketing.
  3. Install a consent tool: add a banner that offers a real choice, records the preference, and holds non-essential cookies until consent.
  4. Write the documents: prepare your cookie policy and privacy notice in plain language and put them somewhere easy to find.
  5. Review regularly: update the list and the text as you add new tools to the site.

This is not a one-time job. Ten minutes once a year, or whenever you add a new tool, solves most problems before they are born.

The most common mistakes

Let us be honest: the most common mistake is copying someone else's cookie policy and swapping in your own site name. That text describes their tools, not yours — so it is wrong from the first line.

  • Treating the banner as decoration: one that fires cookies before consent may look fine, but does not do the one job it exists for.
  • Hiding "Reject": making refusal hard looks like it wins data in the short term, but it loses trust and, in many places, validity.
  • Writing the text once and forgetting it: tools change, cookies change, and a policy that is never updated stops matching reality fast.
  • Cramming everything into one document: mixing the privacy notice and the cookie policy together blurs both.

Where the data goes after the banner

Transparency does not end at the banner. When a visitor fills in a form, writes on WhatsApp or asks for a quote, that data flows somewhere — for most businesses, a CRM. If your privacy notice promises "we keep your data for this purpose, for this long," you need to keep that promise on the back end too.

This is where the place your data rests matters. A data-protection-compliant CRM setup makes it easier to track who gave which consent and to delete data within the window you promised. The same logic runs through a data retention and deletion policy: decide up front how long you keep things, then stick to it.

A well-configured CRM earns its keep here. It gathers records from forms, WhatsApp, Instagram and email into one inbox, keeping each contact's consent record beside it. For the ground-level view, the guide on what a CRM does is a good place to start.

Frequently asked questions

Should the cookie policy and privacy notice be separate?

They are usually separate but linked documents: the privacy notice covers all data processing, the cookie policy only cookies. Check the current rules for your situation.

Do I need consent for strictly necessary cookies too?

Cookies required for the site to function generally do not need a separate "accept," but are still disclosed in the policy. Non-essential ones, like analytics and marketing, are treated differently — check current regulations for where that line sits.

Can I just use a ready-made template?

A template is a useful starting point, but not something to copy as is. The text must reflect the cookies and data flows you actually use; one carrying someone else's tool list is wrong from the start.

How often should I update these documents?

There is no fixed rule, but reviewing whenever you add a new tool, pixel or form — and at least once a year — is healthy. As the tools change, the text has to change with them.

In short, the cookie banner and privacy notice are not a formality; they are the most visible way to tell a customer "I take your data seriously." Say plainly what you collect, make the choice easy, and keep your promise on the back end. When you pick a CRM, make consent and data handling one of your criteria; a guide to choosing the right CRM makes that decision easier. A tool like Rocketly helps you keep that promise by holding data from forms and messaging together with its consent.

One last reminder: this is general information, not legal advice. For situations specific to your business, rely on the rules in force and, where needed, a professional's opinion — because the rules, and your site's cookies, change over time.