Web SDK · consent and datastreams
The journey of an event
Laura opens the product page for a pair of trainers and the cookie banner appears. What happens to her events depends on the Web SDK defaultConsent before she answers, and on what the CMP passes to setConsent afterwards. Once an event goes out, the datastream decides which services it reaches.
Example assumptions
Example visit, events and set-up. Datastream changes can take up to 35 minutes to apply across the Edge Network.
The visit
What happens to each event
The visit's events in order, with Laura's decision in between and the services that receive each event sent.
Reading
What to check
The consequences of the chosen set-up, for Laura's privacy and for the services.
Architecture
Where it fits in the platform
Sequence diagram of one Web SDK request, with seven participants: the page, a product page; the Web SDK, alloy.js; the Edge Network with its datastream; Journey Optimizer, deciding at the Edge Network; Experience Platform, with a dataset and Profile; Customer Journey Analytics with its connection; and event forwarding to the Meta Conversions API. Out: the page passes consent in from the CMP to the Web SDK with setConsent, then calls sendEvent with commerce.productViews. The Web SDK sends a POST to the interact endpoint with the XDM event. Decision: the Edge Network requests propositions from Journey Optimizer, which returns a banner. The Edge Network responds to the Web SDK with the propositions and the ECID, which the Web SDK reuses, and the Web SDK renders the banner without a second call. Only the Journey Optimizer proposition travels in that response, and it needs an Active-On-Edge merge policy. Fan-out: the Edge Network sends the XDM event to the dataset and Profile, the Customer Journey Analytics connection reads that dataset, and the Edge Network applies the product view rule to forward it to CAPI. Measurement: after rendering, the Web SDK sends the display notification. With consent set to out, the event never leaves the browser, and with no event at the Edge Network there is nothing to forward.
The recommendation
defaultConsent set to pending where the law requires it, setConsent as early as possible and a lean datastream
The Web SDK does what it is configured to do. The problems come from not deciding what happens before the user answers and from connecting services just in case.
- 01
defaultConsent set to pending where consent is required
No ECID or identity cookies are created until the user decides, and events wait in a queue. With in as the default, data is collected before asking.
- 02
setConsent as soon as it is known
On page load with the decision stored in the CMP, and right when the banner is answered. The pending queue lives in memory: if the user changes page first, those events are lost.
- 03
A lean datastream
Every enabled service receives the events. Adding Target, Analytics or event forwarding just in case sends data where it is not needed. One datastream per environment.
- 04
Consent in the profile too
With a profile dataset in the datastream and the consent field group in the schema, the preference reaches Real-Time Customer Profile and AJO can respect it.