Session Replay consent opt-in lets you require explicit visitor consent before Session Replay starts, without affecting behavioral analytics collection. When enabled on your project, the tracking tag collecting clicks, scrolls, and page journeys remains unchanged, but does not start Session Replay until the visitor grants consent.
This feature is suited to customers in regulated industries or markets where explicit consent for session replay is required, such as finance, healthcare, public sector, or markets with strict data protection and consent regulations. It removes the need to rely on the optout command, which stops all visitor data collected by Contentsquare, including analytics.
Before you begin
- Session Replay consent opt-in must be enabled on your project: contact your CSM to request activation.
- You are responsible for implementing a consent interface on your site. Contentsquare does not provide a consent management platform (CMP) or consent pop-up.
- Consent is session-scoped: it resets at the start of each new session. Visitors must re-express consent each session.There is no cross-session persistence.
- Granting consent does not guarantee a replay will be collected. Session Replay only starts if your project's sampling quota allows it.
- If the optout command is also active on your project, it takes precedence. A visitor who has opted out via optout will not be tracked regardless of their Session Replay consent state.
Step-by-step setup
Step 1: Implement your consent interface
Note
Session Replay consent opt-in requires a consent interface built and hosted on your site. Contentsquare does not provide a CMP or consent pop-up. The examples below show how to connect your interface to the tracking-tag API.
Your consent interface should display when the visitor has not yet made a consent decision (NOT_EXPRESSED state). Use the afterPageView command to check the visitor's consent state and trigger your interface.
Option A: Display the consent interface on every page view until consent is expressed
window._uxa = window._uxa || [];
window._uxa.push(['afterPageView', callback]);
function callback(context) {
if (context.recordingConsentState === 2) { // NOT_EXPRESSED
displayConsentPopUp();
}
}
Option B: Display the consent interface only on the first page view of the session:
window._uxa = window._uxa || [];
window._uxa.push(['afterPageView', callback]);
function callback(context) {
if (context.recordingConsentState === 2 && context.pageNumber === 1) {
displayConsentPopUp();
}
}
Note
displayConsentPopUp() is a placeholder for your own implementation. It is not a Contentsquare tracking-tag function. Replace it with the function that triggers your consent interface.
If you already use a CMP such as OneTrust, Axeptio, or Cookiebot, you can connect the Contentsquare commands directly to your existing consent event handlers instead of displaying a separate pop-up.
The possible consent state values are:
| Value | State | Description |
| 1 | NOT_NEEDED | The feature is not enabled on this project. |
| 2 | NOT_EXPRESSED | The visitor has not yet made a decision this session. Default state when the feature is enabled. |
| 3 | WITHDRAWN | The visitor has declined or withdrawn consent. Session Replay does not start. |
| 4 | GRANTED | The visitor has granted consent. Session Replay starts if quota is available. |
Step 2: Grant consent
When the visitor accepts Session Replay in your consent interface, push the following command:
window._uxa = window._uxa || [];
window._uxa.push(["replay:consent:startForSession:granted"]);
The consent state transitions to GRANTED. Session Replay starts for the current session, subject to your sampling quota.
Step 3: Withdraw consent
When the visitor declines or withdraws consent, push the following command:
window._uxa = window._uxa || [];
window._uxa.push(["replay:consent:startForSession:withdrawn"]);
The consent state transitions to WITHDRAWN. If a replay was already in progress, it stops immediately.
Testing the implementation
- Open your site in a browser with the Contentsquare tracking tag active.
- Open the browser developer console and check the recordingConsentState value returned in the afterPageView callback. Before any interaction with your consent interface, it should be 2 (NOT_EXPRESSED)
- Grant consent through your consent interface. The state should transition to 4 (GRANTED).
- In Console, confirm that Session Replay sessions are being collected for this project.