# OptinStack > OptinStack is a Consent Management Platform (CMP) for modern websites. OptinStack helps teams publish a consent banner and preferences center, maintain a tracker inventory, enforce visitor choices against known scripts and iframes, sync consent records, and integrate with Google Consent Mode v2 and Global Privacy Control (GPC). ## Status OptinStack is live. ## Key URLs - Marketing site: https://optinstack.com - Dashboard: https://app.optinstack.com - Documentation: https://docs.optinstack.com - Community and help center: https://community.optinstack.com - Pricing: https://optinstack.com/pricing - Integrations: https://optinstack.com/integrations - Blog: https://optinstack.com/blog - Contact: https://optinstack.com/contact - OptinStack-Bot identity: https://optinstack.com/bot (markdown: https://optinstack.com/llms.md/bot) - Legal terms: https://optinstack.com/legal/terms - Privacy policy: https://optinstack.com/legal/privacy ## OptinStack-Bot OptinStack-Bot is the authenticated customer-site scanner identity (not an open-web crawler). Full details: https://optinstack.com/bot or https://optinstack.com/llms.md/bot. ## Product Notes - Runtime enforcement is inventory-driven. Unknown untagged third-party resources are not universally blocked until scanned, classified, manually added, or tagged. - Webflow and Framer integrations provide platform-side configuration and preview. Customers still install the runtime snippet in their site head. - Individual proof PDFs are available on every plan. CSV consent exports are available on Pro and above. - Free can activate on each eligible hostname by default with a worldwide English opt-in banner, 50-page scans, a 24-hour cooldown, basic consent records, and proof PDFs. A paid entitlement may start on a builder hostname and move once to a registered verified production hostname. - Verified custom production domains can use Free (unlimited eligible Free hostnames by default), a paid hostname subscription, Enterprise, or Workspace coverage. Registration alone does not activate runtime, publishing, or consent-record collection. - Paid hostname subscriptions include one self-service move; the previous hostname becomes inactive and later paid changes use the reviewed Request update flow. ## Blog Posts - Consent banner modes: opt-in, opt-out, informational, and do-not-sell: https://optinstack.com/blog/consent-banner-modes-opt-in-opt-out-explained (markdown: https://optinstack.com/llms.md/blog/consent-banner-modes-opt-in-opt-out-explained) - The four consent banner modes, opt-in, opt-out, informational, and do-not-sell-or-share, what each means, and how to pick the right one by region. - Consent enforcement: blocking vs releasing scripts by category: https://optinstack.com/blog/consent-enforcement-blocking-vs-releasing-scripts (markdown: https://optinstack.com/llms.md/blog/consent-enforcement-blocking-vs-releasing-scripts) - What consent enforcement is, how trackers get gated by category, the common failure modes like load-order gaps, and how to verify the page actually obeys each visitor's choice. - Google Consent Mode v2, explained: https://optinstack.com/blog/google-consent-mode-v2-explained (markdown: https://optinstack.com/llms.md/blog/google-consent-mode-v2-explained) - What Consent Mode v2 is, the four consent signals, Basic vs Advanced mode, and how to verify your implementation. Sourced from Google's official Tag Platform and Ads documentation. - Consent records and audit trails: why you need them: https://optinstack.com/blog/consent-records-and-audit-trails (markdown: https://optinstack.com/llms.md/blog/consent-records-and-audit-trails) - What a consent record is, what it should capture, how long to keep it, and why an audit trail of every choice is the part teams most often skip. Sourced from GDPR Article 7 and ICO guidance. - First-party vs third-party trackers: https://optinstack.com/blog/first-party-vs-third-party-trackers (markdown: https://optinstack.com/llms.md/blog/first-party-vs-third-party-trackers) - The difference between first-party and third-party trackers, how the SameSite attribute ties in, why first-party proxying blurs the line, and what it means for consent. - What is Global Privacy Control (GPC) and how to respect it: https://optinstack.com/blog/what-is-global-privacy-control-gpc (markdown: https://optinstack.com/llms.md/blog/what-is-global-privacy-control-gpc) - What Global Privacy Control is, how the Sec-GPC header and navigator.globalPrivacyControl signal work, what California and Colorado require, and how to honor it before trackers run. - What is PII (personally identifiable information)?: https://optinstack.com/blog/what-is-pii-personally-identifiable-information (markdown: https://optinstack.com/llms.md/blog/what-is-pii-personally-identifiable-information) - What actually counts as PII, how it differs from personal data under the GDPR, and why the distinction matters for the trackers running on your site. - Tracker inventory: what is actually running on your site: https://optinstack.com/blog/tracker-inventory-what-is-running-on-your-site (markdown: https://optinstack.com/llms.md/blog/tracker-inventory-what-is-running-on-your-site) - What a tracker inventory is, why it matters, how trackers map to the four consent categories, and how to keep the inventory honest as your site changes. - What is a consent management platform (CMP), and do you need one?: https://optinstack.com/blog/what-is-a-consent-management-platform-cmp (markdown: https://optinstack.com/llms.md/blog/what-is-a-consent-management-platform-cmp) - What a consent management platform is, the components that make it work, the fixed consent categories, and how to tell whether your site needs one.