ConsentPixel – Privacy · Verified

Platform Guide · Squarespace · 2026

Squarespace Cookie Banner: Compliant Setup, Sizing & Placement

Getting the banner size for Squarespace right is where most people start — format, placement, text size — and Squarespace gives you real control over all three. But a well-sized banner isn't the same as a compliant one. This guide covers both: how to size and set up the cookie banner, and how to make sure it actually blocks trackers before consent.

By ConsentPixel TeamUpdated August 202613 min readInformation, not legal advice
4M+
Websites built on Squarespace — heavy on creators, shops, and service businesses
3 formats
Squarespace's cookie banner offers bar, framed, and pill layouts — each a different size
$5,000
Per-visitor exposure under California Penal Code §637.2 for pre-consent tracking
The short answer

To set the banner size for Squarespace: go to Settings → Cookies & Visitor Data → Cookie Banner, toggle it on, then choose your banner format (bar, framed, or pill), placement (top, bottom, or corner), and adjust the text size to fit your design. Those three controls determine the banner's on-screen size.

The bigger question is what the banner does. Squarespace's native banner can defer its own cookies, but it doesn't block the analytics and marketing scripts you add through Code Injection — which is where the real compliance risk lives. This guide covers both. It's general information, not legal advice.

If you searched "banner size for Squarespace," you're almost certainly trying to add a cookie banner that looks right on your site — not too big, not blocking your hero image, matching your clean Squarespace design. That's the correct instinct, and Squarespace genuinely does let you control the banner's size, format, and position. But sizing is the easy half. The half that actually matters legally is whether that banner stops trackers from firing before a visitor agrees. We'll do both — get it looking right, then get it working right.

Do you need a cookie banner on Squarespace?

For most sites, yes. Squarespace sets its own analytics cookies by default, and the moment you add Google Analytics, a Meta Pixel, a scheduling widget, or any marketing tool through Code Injection, your site is placing non-essential cookies on visitors. The EU's GDPR (and ePrivacy rules) require opt-in before those load; California's CCPA and other US state laws require a clear opt-out. A cookie banner is how you offer that choice — and increasingly, how you avoid both regulatory fines and the US lawsuit wave we'll get to below.

Squarespace has genuinely improved here: it recently updated its cookie-management system, making the banner easier to enable and style. So the "add a banner" part is quick. The nuance is that Squarespace's plans and its banner's blocking behavior vary — which is exactly why sizing and compliance are two separate conversations.

Banner size for Squarespace: format, placement & text size

Let's start where you started — the size. Squarespace doesn't give you a pixel-perfect width-and-height field; instead, the banner's size is controlled by three settings that, together, decide how much of the screen it takes up.

1. Banner format

Choose the layout — a full-width bar, a contained framed box, or a compact pill. This is the single biggest lever on perceived size: a bar spans the screen; a pill is a small tab.

2. Placement

Position it top, bottom, or in a corner. Bottom and corner placements feel smaller and less disruptive; top banners can interfere with navigation, so many designers avoid them.

3. Text size

Increase or decrease the banner's text size for readability and to match your site's type scale. Larger text makes the whole banner taller; smaller text keeps it compact.

There's also a cookie-preferences trigger — the persistent "Manage Cookies" control visitors use to change their choice later. Squarespace offers styles for this too (including a small pill-style button), so returning visitors can reopen preferences without a giant banner living on the page.

🎛️ The three banner formats, by size
Bar full-width · largest Framed contained box Pill compact · smallest Format is the biggest size lever; placement and text size fine-tune it. Size is a design choice — but a smaller banner must still offer a real, equal "reject" option.
Size has a compliance limit

Shrinking the banner for aesthetics is fine — but under GDPR, "reject" must be as easy as "accept." A pill or compact banner that hides the decline option behind extra clicks, or makes "accept" prominent while burying "reject," crosses from small into dark pattern. Keep the choice symmetric no matter which size you pick.

How to set up the Squarespace cookie banner

Here's the current path to enable and configure the native banner. It takes a couple of minutes.

🍪 Enable & size the native Squarespace banner
  1. From your Squarespace dashboard, go to Settings → Cookies & Visitor Data.
  2. Toggle Cookie Banner on. Two new options appear: banner type and banner format.
  3. For banner type, choose Opt-in & Out (not just Opt-in). For a GDPR-minded setup you want visitors to be able to both accept and decline. Selecting a type also controls whether Squarespace suppresses its own analytics cookies until consent.
  4. Set your banner format (bar / framed / pill), placement, and text size — this is where you control the banner's size and look.
  5. Add links to your privacy policy and cookie policy in the banner text, then save. Squarespace applies it to the live site immediately.
  6. Confirm on a fresh incognito visit: only essential cookies should load until the visitor chooses. If you use Squarespace's built-in Google Analytics connection with opt-in mode, it should wait for consent.
A plan note worth knowing

The banner toggle is broadly available, but the deeper controls — and the Code Injection you'll need for third-party consent tools — require a Business plan or higher. On the Personal plan, Code Injection isn't available, which also limits how much third-party tracking (and therefore exposure) you can add in the first place.

Before you trust the banner

See which trackers fire before consent on your Squarespace site

A well-sized banner that's showing isn't proof anything is blocked. Run a free scan to see every tracker and cookie firing before a visitor opts in — including your Code Injection scripts — in about 10 seconds. No account needed.

No account needed for the scan · no credit card · information, not legal advice

What the native Squarespace cookie banner doesn't block

Here's the part sizing tutorials skip, and it's the part that matters most: Squarespace's native banner can defer its own cookies — but it does not block scripts you add through Code Injection. And on a real Squarespace site, that's where nearly all the tracking lives.

When you paste a Google Tag Manager container, a Meta Pixel, a Hotjar snippet, or an email-marketing tag into Settings → Advanced → Code Injection (header, footer, or per-page), those scripts fire on page load regardless of what your visitor clicked on the banner. The banner never had a hook into them. So a visitor can decline — and still be tracked by:

  • Google Analytics 4 & Google Tag Manager — the most common Squarespace trackers; every tag in a GTM container fires on load.
  • Meta / LinkedIn / TikTok Pixels — load from external CDNs and transmit on page render.
  • Hotjar / Microsoft Clarity — session-replay snippets that record behavior (and carry specific US legal risk — see below).
  • Embedded content & iframes — a YouTube or Vimeo embed, a Google Map, or any iframe in Squarespace can set third-party cookies when the page renders, not when the visitor presses play.

This isn't a knock on Squarespace — it's how a closed, hosted platform works. But it means "a banner is showing" and "trackers are blocked" are two different things. Closing that gap needs a consent layer that intercepts injected scripts before they run. We built the deeper, Squarespace-specific version of this — including the exact Code Injection order and a native-vs-ConsentPixel breakdown — into our Squarespace platform guide.

Why a sized banner isn't the same as a blocking one Visitor clicks "Decline" Squarespace-native cookies Banner can defer these ✓ Code Injection scripts GA4 · GTM · Meta · Hotjar · iframes — fire anyway ✕ A consent layer that blocks injected scripts before consent The banner controls the green path; the red path — where your marketing stack lives — needs a layer that blocks before consent.
On Squarespace, almost all marketing tags are added via Code Injection — the exact scripts the native banner can't reach.

Your 3 options for a compliant Squarespace cookie banner

Once you know the gap exists, there are three realistic routes — honestly compared, strongest coverage first.

Most coverage

1. An independent consent tool (e.g. ConsentPixel)

Best for: any Squarespace site running GA4, GTM, a Meta Pixel, embeds, or session-replay — especially with US visitors.

A dedicated consent layer added with a single Code Injection snippet that blocks trackers before consent regardless of how they were injected, passes all four Google Consent Mode v2 parameters, detects the Global Privacy Control (GPC) signal, and keeps a timestamped consent log. Among independent tools, ConsentPixel — Privacy · Verified is built prevention-first: it blocks the injected scripts rather than just showing a notice over them.

Blocks Code Injection scripts (GA4, GTM, Meta, Hotjar) before consent
GCM v2 + GPC detection + CIPA session-replay blocking + exportable audit log; works on 7.0 & 7.1
Header Code Injection needs a Business plan or higher (per-page code works on lower plans)
Popular

2. A general third-party CMP (CookieYes, Termly, Iubenda, Cookiebot)

Best for: sites that want a no-frills banner and policy generator bundle.

These consent-management platforms install via Code Injection and add granular consent categories the native banner lacks. They're capable and widely used. The difference is emphasis: most are built banner-and-policy-first, with script-blocking and US-litigation coverage (CIPA, GPC) varying by plan — so check that the tier you pick actually blocks injected scripts before consent, not just displays categories.

Granular categories + bundled cookie/privacy policy generators
Free tiers available; familiar, widely documented
Prior-blocking, GPC, and CIPA coverage vary by plan — verify what your tier actually blocks
Baseline

3. Squarespace's native cookie banner alone

Best for: simple sites using only Squarespace-native features and no injected trackers.

The built-in banner is easy, free, and now nicely customizable for size and format. For a site that adds no Code Injection tracking, it's a reasonable baseline. But on its own it can't block injected scripts, set GCM v2, or detect GPC — so it's rarely sufficient once you've added a marketing stack.

Free, native, and now easy to size and style
Doesn't block Code Injection scripts; no GCM v2 or GPC; basic logging

Native vs third-party CMPs vs ConsentPixel: an honest comparison

Here's the category-level view — where each route genuinely lands on the things privacy law cares about. (For the tool-by-tool product breakdown, see the Squarespace platform page.)

CapabilitySquarespace nativeGeneral CMP (CookieYes / Termly)ConsentPixel
Size / format / placement controlYesYesYes
Defers Squarespace-native cookiesYesYesYes
Blocks Code Injection scripts before consentNoVaries by planYes
Google Consent Mode v2 (all 4 params)NoSome plansYes
Global Privacy Control (GPC) detectionNoVariesYes
CIPA session-replay blockingNoVariesYes
Timestamped, exportable consent logBasicVariesFull
Prevention-first design (blocks vs notifies)NoticeMixedBlocks

The pattern: sizing and native-cookie handling are table stakes everyone does. Coverage diverges on the thing that actually creates risk — blocking the injected scripts before consent. For a bare Squarespace site, native is fine; for a site with a marketing stack, an independent prevention-first layer is what closes the gap the others leave partly open.

The US angle most Squarespace guides skip: CIPA

Nearly every "Squarespace cookie banner" tutorial focuses on GDPR. It matters — but if any of your visitors are in the United States, the more urgent 2026 risk is often the California Invasion of Privacy Act (CIPA). Plaintiffs' firms have built a sustained wave of "wiretapping" lawsuits arguing that session-replay tools, tracking pixels, and chat widgets capturing a visitor's activity before consent amount to unlawful interception. Under California Penal Code §637.2, a plaintiff can seek statutory damages of $5,000 per violation — often read per affected visitor — with no proof of harm required.

Why this hits Squarespace sites specifically: the highest-risk category — session-replay tools like Hotjar and Clarity — is exactly what gets added via Code Injection, which the native banner can't control. A Squarespace shop or booking site running Hotjar on its checkout and serving California visitors can carry real exposure even with a perfectly sized banner on screen. The fix is to hard-block those scripts until consent, not merely display a notice over them. You can follow the trend on our CIPA Lawsuit Tracker.

The one thing to check today

If your Squarespace site uses any session-replay or heatmap tool via Code Injection and gets US traffic, confirm it does not fire before consent. It's the single highest-value privacy fix on most Squarespace sites — and the one a banner's size setting has nothing to do with.

Squarespace privacy housekeeping worth doing

While you're in this corner of your Squarespace settings, a few adjacent tasks come up constantly. Quick, honest pointers:

  • Squarespace privacy policy — generator, template, or custom? Every Squarespace site needs a privacy policy, and your cookie banner should link to it. A Squarespace privacy policy generator or privacy policy template is a fine starting point, but a policy is only accurate if it names the trackers actually on your site. The stronger approach is to build the privacy policy for your Squarespace website from a real scan of what fires, so it lists GA4, Meta, and any Code Injection tools as data recipients rather than using generic boilerplate.
  • Terms of service. Alongside the privacy policy, add clear terms of service (a terms of service Squarespace page is easy to create as a standard page). Together they're the baseline legal pair every site should link in the footer.
  • How to link pages on Squarespace. To wire your policy and terms into the banner and footer: highlight the text, click the link icon, and point it to the page — how to link pages on Squarespace is the same flow whether you're linking a policy, a product page, or an internal section. Keep both policy links reachable from every page.
  • iframes & embeds. An iframe in Squarespace (embedded video, map, booking widget, or a Code Block iframe) can set third-party cookies on load. Treat every embed as a tracker to consent-gate, not just your analytics tags.
  • Product pages & SMS. If you run Squarespace Commerce, remember a product page in Squarespace and its checkout often carry the most trackers (conversion pixels, session-replay). And if you use a Squarespace SMS integration for order or marketing texts, that's consent of a different kind — SMS marketing has its own opt-in rules separate from cookies.
  • Squarespace reports & analytics. Your Squarespace reports (traffic and sales analytics) rely on Squarespace's own cookies, which the native banner can defer — but any third-party analytics you added for richer reporting sits in Code Injection and needs consent-gating separately.

Key takeaways

  • Banner size for Squarespace is set by three controls: format (bar / framed / pill), placement (top / bottom / corner), and text size — found under Settings → Cookies & Visitor Data.
  • Small is fine; buried "reject" is not. Whatever size you choose, GDPR requires the decline option to be as easy as accept.
  • Choose "Opt-in & Out" as the banner type so visitors can both accept and decline.
  • The native banner doesn't block Code Injection scripts — GA4, GTM, Meta Pixel, Hotjar, and iframes fire regardless, which is where the real risk is.
  • Coverage improves toward a prevention-first consent layer that blocks injected scripts before consent; general CMPs vary by plan.
  • Don't skip CIPA: session-replay firing before consent creates $5,000-per-visitor exposure under §637.2 — unrelated to how your banner is sized.

The bottom line

Sizing your Squarespace cookie banner is genuinely quick — pick a format, a placement, a text size under Settings → Cookies & Visitor Data, and it'll look right on your site. The harder, more important question is what it's actually blocking. In 2026, with US wiretapping litigation targeting ordinary small businesses and creators, "a nicely sized banner is showing" is no longer the finish line. "Nothing non-essential fires before consent" is.

Get the size right for your design, then verify the substance: choose native only if you run no injected trackers, and a prevention-first consent layer if you've added a real marketing stack — especially with US visitors. The only banner that protects you is one you've confirmed is doing its job.

See exactly what fires on your Squarespace site before consent

Run the same scan a plaintiff's firm would: every tracker and cookie loading before opt-in on your Squarespace site — Code Injection scripts and embeds included — in about 10 seconds. Then, if it's your site, close the gap with one Code Injection snippet.

Scan your Squarespace site free →
No account for the scan · then a 14-day free trial, no credit card, from $8.99/mo · or read the full Squarespace setup guide · information, not legal advice
CP
The ConsentPixel Team

ConsentPixel — Privacy · Verified helps Squarespace site owners and agencies make consent real — blocking the GA4, GTM, Meta Pixel, and session-replay scripts added through Code Injection until a visitor genuinely consents, passing all four Google Consent Mode v2 parameters, detecting GPC, and logging every consent decision as proof. This article is general educational information, not legal advice. ConsentPixel is not a law firm.

Frequently asked questions

How do I change the banner size on Squarespace?

Squarespace doesn't use a fixed width/height field for the cookie banner — its size is controlled by three settings under Settings → Cookies & Visitor Data → Cookie Banner. First, the banner format: a full-width bar (largest), a contained framed box, or a compact pill (smallest). Second, placement: top, bottom, or corner. Third, text size, which you can increase or decrease for readability. Adjusting those three together determines how much of the screen the banner occupies. There's also a separate cookie-preferences trigger (including a small pill-style button) so returning visitors can reopen their choices without a large banner staying on the page.

Does Squarespace have a built-in cookie banner?

Yes. Squarespace includes a native cookie banner under Settings → Cookies & Visitor Data. You can toggle it on, choose a banner type (opt-in, or opt-in & out), and style its format, placement, and text size. With opt-in mode it can suppress Squarespace's own analytics cookies until a visitor consents. However, it does not block scripts you add through Code Injection — Google Analytics, GTM, Meta Pixel, Hotjar, and similar tags — which is where most tracking on a Squarespace site actually lives. For those, you need a consent tool that intercepts injected scripts before they run.

Is the Squarespace cookie banner GDPR compliant on its own?

Not by default. The native banner can display a notice and defer Squarespace's own cookies, but GDPR requires non-essential processing to wait for consent — and the banner does not block the third-party scripts you add via Code Injection. If a visitor declines and your Code Injection GA4, Meta Pixel, or Hotjar keep firing, you've met the notice requirement but not the consent requirement, which is the exact failure mode enforcement has focused on. To make a Squarespace site genuinely compliant, pair the banner with a tool that blocks injected scripts before consent, sets Google Consent Mode v2, and honors the GPC signal. This is general information, not legal advice.

Does my Squarespace site need a privacy policy and terms of service?

Yes. Every Squarespace site that collects any personal data — through analytics, contact forms, or a store — needs a privacy policy, and your cookie banner should link to it. A Squarespace privacy policy generator or template is a reasonable starting point, but it's only accurate if it names the trackers actually running on your site, so building it from a real scan is stronger than generic boilerplate. Alongside the privacy policy, add clear terms of service. Both are easy to create as standard Squarespace pages; link them in your footer and cookie banner so they're reachable from every page.

Do iframes and embeds on Squarespace need consent?

Often, yes. An iframe in Squarespace — an embedded YouTube or Vimeo video, a Google Map, a booking widget, or anything added through a Code Block — can set third-party cookies when the page renders, not when the visitor interacts with it. Under GDPR that means it should be consent-gated like any other non-essential tracker. The native cookie banner generally can't hold these embeds, so if your site relies on them you'll want a consent layer that blocks embedded third-party content until the visitor agrees. Treat every embed as a tracker to gate, not a neutral design element.

Does my Squarespace site have CIPA (US wiretapping) risk?

Potentially, yes — if your Squarespace site uses session-replay or heatmap tools (like Hotjar or Clarity), tracking pixels, or chat widgets that capture visitor activity before consent, and you receive visitors from California. Under California Penal Code §637.2, plaintiffs can seek statutory damages of $5,000 per violation, often read per affected visitor, with no proof of harm required. These tools are usually added via Code Injection, which the native banner can't control — so the banner's size or format makes no difference to this risk. The protective step is to hard-block session-replay and similar scripts until the visitor consents. This is general information, not legal advice.

Information, not legal advice. This article is general educational information about setting up and sizing a cookie banner on Squarespace and does not constitute legal advice or create an attorney–client relationship. Privacy laws — including GDPR, CCPA/CPRA, CIPA, and US state laws — apply differently depending on your business, data practices, and jurisdiction, and platform features change over time. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2; actual exposure varies by case. References to Squarespace, CookieYes, Termly, and other products describe documented capabilities, not any allegation of non-compliance. Verify your specific obligations with qualified counsel. ConsentPixel — Privacy · Verified is a consent-management and detection tool, not a law firm.
Scroll to Top