GDPR · CCPA · DPDP — one banner, every market

GDPR, CCPA & DPDP compliance made simple. In 5 minutes.

Selling to shoppers in the EU, UK, US, Canada, Australia or India? Privacy law follows your customers, not your address. Drop one script tag on your store and get a compliant banner, tamper-proof audit trail, and DSAR queue — GDPR, CCPA and DPDP included.

Free forever up to 1,000 consent events / month · No credit card · Works in every market

Live demo — no signup needed

yourstore.com — live demo, nothing is saved
Interactive

We value your privacy

We use cookies to run this store and, with your consent, to measure and personalise. You can withdraw consent any time under the DPDP Act.

Try it: accept, customise toggles, or open a data request.

Check your site free — GDPR, CCPA & DPDP score in 10 seconds

No signup for the score. Takes about 10 seconds. We only read your homepage.

Or grab the free 21-point DPDP checklist (PDF)

Trusted by 12 websites · 8,420 consent events logged

Shopify WordPress React / Next / any site <50ms load Hashed IPs, no PII

Loved by lean teams worldwide

Shopify merchants, agencies and SaaS teams across the EU, UK, US, Canada and India.

"GDPR was a scary email from our lawyer. AssentRepo was a 10-minute install."

Emma L. · Founder, D2C skincare (London)

"OneTrust quoted six figures. AssentRepo does 95% of it for $19/mo."

Rahul K. · CTO, B2B SaaS (Bengaluru)

"I install AssentRepo for every store I build. Two clicks in the theme editor."

Aditi M. · Shopify Expert (Delhi)

"One banner covers our EU, California and Canadian shoppers. No lawyer needed."

Marc D. · Shopify merchant (Toronto)

"Auto-generated cookie policy passed our client's legal review first try."

Sana A. · Head of Growth, EdTech

Everything you need to stay compliant

One platform for consent banners, audit logs, DSAR workflows, and policy pages.

GDPR, CCPA & DPDP in one banner

One consent banner that satisfies EU/UK GDPR, US state privacy laws and India's DPDP Act — no add-ons.

2KB drop-in script

Paste one <script> tag in your <head>. Loads in under 50ms and works on any site or builder.

Tamper-proof audit trail

Every consent event is timestamped and stored with a hashed IP. Export CSV when a regulator asks.

DSAR request queue

Access, deletion, correction, and opt-out requests land in one inbox — no spreadsheets.

Auto cookie scanner

Detects trackers and third-party scripts on any page without manual cookie tagging.

Google Consent Mode v2

Sends consent signals to Google Ads and Analytics automatically, right from the banner.

Auto-generated policies

Live Privacy Policy and Cookie Policy pages generated for every site you add.

Custom domain + white-label

Remove AssentRepo branding from Starter, and host the banner on your own domain on Pro.

Team seats

Invite editors and viewers with role-based access. Owner controls billing and settings.

Simple pricing, no enterprise sales

Start free forever. Upgrade from $9/mo. No calls, no contracts, no per-seat gotchas.

DPDP Act, 2023

Every Indian website that collects personal data now needs this.

If your site takes an email, runs Google Analytics, uses Meta Pixel, or ships to Indian customers — the DPDP Act applies to you. Consent must be free, specific, informed, and withdrawable. You must respond to access & deletion requests. And you must be able to prove it.

Western tools like OneTrust and Cookiebot don't speak DPDP. They speak GDPR and translate. AssentRepo is built for DPDP first — the rest come free.

DPDP compliance checklist

  • Explicit consent banner before any tracking cookie fires
  • Per-category consent (analytics, marketing, functional)
  • Withdraw consent as easily as it was given
  • Tamper-proof, timestamped audit log per visitor
  • Data Principal (DSAR) request queue with response SLA
  • Privacy notice in clear, plain language
Penalties: up to ₹250 crore per violation under Section 33 of the DPDP Act.

Built for the people OneTrust ignored.

Small teams, big responsibilities.

Shopify merchants

D2C brands shipping to Indian customers. One-line install, banner matches your theme.

WordPress & marketing sites

Small business sites, agencies, and blogs collecting emails and running ads.

Indie SaaS & startups

You have paying customers before you have a legal team. We're that legal team's script tag.

Simple, fair pricing for every store.

No enterprise sales calls. No per-seat gotchas. Start free, upgrade when you outgrow it.

Free

$0Forever
  • 1 site
  • 1,000 consent events / month
  • DSAR queue
  • DPDP + GDPR + CCPA templates
  • Audit-ready logs (CSV export)

Starter

$9/ month · billed monthly
  • Unlimited sites
  • 10,000 consent events / month
  • Custom banner branding
  • Remove AssentRepo badge
  • Cookie auto-scanner

Pro

Most popular
$19/ month · billed monthly
  • Everything in Starter
  • 50,000 consent events / month
  • Custom domain + white-label
  • Priority email support

All prices in USD, billed by Paddle. Business plan at $59/mo adds team seats and webhooks.

AssentRepo is a Consent Management Platform (CMP) and DSAR dashboard — software infrastructure, not legal advice. Compliance with GDPR, CCPA, and DPDP ultimately depends on your implementation, privacy policies, and business practices. See our Terms and DPA.

DPDP, in plain English.

Does the DPDP Act actually apply to my small site?

If you process the personal data of anyone in India — even just an email signup or an analytics cookie — yes. There is no small-business exemption. Rules apply from the day the government notifies them.

Isn't a cookie banner enough?

No. DPDP requires you to (1) get itemised consent, (2) let people withdraw it as easily, (3) respond to access & deletion requests, and (4) prove all of the above with logs. A static banner does none of that.

How is this different from Cookiebot or OneTrust?

Those are GDPR-first tools starting at $50–$500+/mo. AssentRepo is DPDP-first, starts at $9/mo, and is designed for teams of 1–20 people. Same audit trail, a fraction of the cost.

How fast can I install it?

Sign up and create a site. On Shopify, install our app and switch on the app embed in the theme editor — no code editing. On WordPress use our plugin; anywhere else, add one script tag. Under 5 minutes.

Where is the data stored?

In secure managed Postgres. IPs are one-way hashed with a server-side salt before storage — we don't keep raw IPs. You can export or delete everything anytime.