Industries · SaaS

Does a SaaS app need a cookie banner?

Usually the marketing site does, and the app behind the login needs the same honesty about what it loads. The answer turns on what your stack sets before anyone agrees to anything — which is a question of evidence, not opinion.

The short answer

Yes — if anything non-essential fires before consent, and on a SaaS marketing site something almost always does.

The obligation does not attach to “being a SaaS company.” It attaches to storage and access on a visitor’s device, and to whether personal information is being sold or shared. A product-analytics SDK, a session-replay tool, a support widget and an ad pixel all put something on the device, and most SaaS marketing sites run at least three of those.

The useful move is to stop guessing. UserGuard loads your site in a real browser with no consent given, captures every cookie set by header, by HTTP-only record, or by document.cookie, and files scripts, pixels and storage keys separately as what they are. You then decide with a list in front of you instead of a hunch.

What a SaaS stack usually sets

Four places the cookies actually come from.

Product analytics

Analytics SDKs are the single most common source of non-essential storage on a SaaS site, and they load on the marketing pages as often as inside the app. In EU and UK mode they are held until consent; in US mode they are the category most likely to count as a “sale or share” when the vendor gets something of value out of the data.

Session and behaviour tools

Session replay and heatmap tools set their own identifiers and record what visitors do. They belong in the analytics category, they belong in your disclosure, and they belong behind the same gate as everything else non-essential. Your inventory should name them; scanners that only count “cookies” often miss the storage keys entirely.

Support and chat widgets

Chat and help widgets are functional for the visitor and invisible in most audits. UserGuard’s default blocking rules already name the common ones, and the rule list is yours to edit: add patterns, recategorise, remove. First match wins, and nothing hides behind a black box.

Marketing automation and ad pixels

The pixels on your pricing and demo pages are what make a US opt-out non-theoretical. “Sharing” under California law covers ordinary cross-context advertising whether or not money changes hands, so a Do Not Sell or Share mechanism is usually the right call for a SaaS marketing site, alongside automatic Global Privacy Control honouring.

What it looks like in practice

One site, ten dollars, both obligations.

A SaaS team usually runs one production domain and a docs or blog subdomain. That is one billable site, $10 a month, with the full workflow: monthly scans plus manual rescans, the banner and preference center, region-aware behaviour, consent records tied to banner version, the accessibility widget, and generated cookie policy and accessibility statement drafts.

  • Region-aware: prior consent for EU/UK visitors, opt-out and GPC for US states
  • Google Consent Mode v2 signals default-denied before Google tags load
  • Consent records exportable as CSV when a security questionnaire asks
  • Cookies set behind your login can be added by hand, labelled as exactly that

Enterprise buyers will ask

Security reviews increasingly ask how consent is recorded. “We export a CSV tying each choice to a site, a banner version, a region, a language and a timestamp” is a better answer than a screenshot of a banner.

Your app is not your marketing site

Cookies set behind a login cannot be reached by a crawler that has no account. UserGuard lets you add them manually and labels them as manually added, so the inventory never pretends to evidence it does not have.

Accessibility, on the same script

The accessibility widget is a per-site toggle on the embed you already ship. Enterprise procurement asks about accessibility too, and a published statement beats an assurance.

Coverage

The rules a SaaS site actually answers to.

US-first, Europe-ready. UserGuard runs the visitor-facing machinery these regimes ask for, and keeps the records that show it.

This page is general information, not legal advice. Whether your site is in scope for any particular law depends on facts we cannot see from here. UserGuard helps you operate consent and opt-out management as part of your compliance program; configuration decisions and legal outcomes remain yours.

Get started $10 a site · 30-day money-back guarantee · cancel anytime

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started 30-day money-back guarantee · cancel anytime