Release Notes

Product News: Per-Event Consent, Privacy Requests, and Global Privacy Control

Consent is recorded with every event and applied at collection, deletion and export requests run end to end, and Global Privacy Control is honored automatically.

Published: Fri Sep 11 2026

Product News: Per-Event Consent, Privacy Requests, and Global Privacy Control

Logspot builds consent and privacy requests into the analytics pipeline itself, instead of handling them beside it.

Every event carries the visitor's consent at the moment it was collected, across three categories: Analytics, Functional, and Marketing (Advertising). The record includes where the decision came from, so a choice made in your consent banner can be told apart from a browser signal.

Logspot picks up consent from Concord, OneTrust, Usercentrics, Cookiebot, and Google Consent Mode, or you can send it through the API. When sources disagree, a fixed priority decides, and Settings → Privacy → Consent Sources shows the order.

Logspot handles privacy differently from some privacy-focused analytics tools because it does a different job. Those tools deserve credit for making privacy a first-class concern in analytics. Some avoid cookies by building a short-lived identifier from each visitor's IP address, hashed with a salt that changes daily, and collecting as little as possible is a sensible fit for aggregate, short-term trend reporting. Whether it removes the need for consent is still contested. The ePrivacy Directive covers accessing information from a visitor's device, not only personal data, so it can apply even when the data is later anonymized. The European Data Protection Board's Guidelines 2/2023 on the directive's scope include fingerprinting and tracking based on an IP address that comes from the visitor's device, and national regulators apply the rules differently.

Logspot's job is acting on accounts, not only reporting trends. Signals, enrichment, and outreach work with data about specific visitors and companies over time, and that needs a clear basis. So Logspot records consent with each event: what a visitor agreed to travels with their data, and each action checks it before it runs. An opt-out is honored from that point on, and consented history stays available for analysis over long time ranges.

Choose What Happens to Declined Events

Under Settings → Privacy → User Consent, choose whether events from visitors who declined analytics are dropped or kept with nothing identifying. You can override this per project under Project Settings → Consent, along with the consent model (Not Required, Implied, Express, or Custom) and how server-side events are treated. By default, revenue sent from your server is exempt from the analytics consent gate.

Privacy Requests That Complete

Raise deletion and export requests under Settings → Privacy → Privacy Requests, or file them through the API with an organization token. Each request records its regulation (GDPR or CCPA), and an export can cover all history or the trailing 12 months.

Before a deletion runs, you see how many records match and confirm. The deletion then erases the person's events, consent history, and identity rather than hiding them, and the request reports complete only once that has happened. A failed deletion retries on its own. Exports arrive as a download link that expires after 7 days, and a failed export is not retried automatically.

Global Privacy Control

Logspot reads the Global Privacy Control signal that some browsers send. Until your consent banner or another consent source has recorded a choice, GPC turns off selling and sharing and the Marketing category. Once a source has recorded a choice, that choice governs and the GPC signal is kept on record. GPC does not switch off analytics collection.

Get Started

Consent recording is on by default. Set your consent model and declined-event handling under Settings → Privacy, and raise requests under Settings → Privacy → Privacy Requests. See Consent Management and Privacy Requests.