The Digital Personal Data Protection Act is live. Fines go up to ₹250 crore. Drop one script tag on your site and get a compliant banner, tamper-proof audit trail, and DSAR queue — GDPR & CCPA included.
Free forever up to 1,000 consent events / month · No credit card · Made in India
Or grab the free 21-point DPDP checklist (PDF)
Trusted by 12 websites · 8,420 consent events logged
"DPDP was a scary email from our lawyer. ConsentHub was a 10-minute install."
Priya S. · Founder, D2C skincare (Mumbai)
"OneTrust quoted six figures. ConsentHub does 95% of it for ₹1,499/mo."
Rahul K. · CTO, B2B SaaS (Bengaluru)
"I install ConsentHub for every Indian merchant now. 2-minute theme snippet."
Aditi M. · Shopify Expert (Delhi)
"The DSAR queue alone is worth the price. No more deletion spreadsheets."
Neel R. · Solo indie hacker
"Auto-generated cookie policy passed our client's legal review first try."
Sana A. · Head of Growth, EdTech
One platform for consent banners, audit logs, DSAR workflows, and policy pages.
Built for India's DPDP Act 2023. GDPR and CCPA templates are included at no extra cost.
Paste one <script> tag in your <head>. Loads in under 50ms and works on any site or builder.
Every consent event is timestamped and stored with a hashed IP. Export CSV when a regulator asks.
Access, deletion, correction, and opt-out requests land in one inbox — no spreadsheets.
Detects trackers and third-party scripts on any page without manual cookie tagging.
Sends consent signals to Google Ads and Analytics automatically, right from the banner.
Live Privacy Policy and Cookie Policy pages generated for every site you add.
Host the banner on your own domain and remove ConsentHub branding on Pro plans.
Invite editors and viewers with role-based access. Owner controls billing and settings.
Start free forever. Upgrade at ₹1,499/mo. No calls, no contracts, no per-seat gotchas.
If your site takes an email, runs Google Analytics, uses Meta Pixel, or ships to Indian customers — the DPDP Act applies to you. Consent must be free, specific, informed, and withdrawable. You must respond to access & deletion requests. And you must be able to prove it.
Western tools like OneTrust and Cookiebot don't speak DPDP. They speak GDPR and translate. ConsentHub is built for DPDP first — the rest come free.
Skip the six-figure OneTrust contract. ConsentHub ships the 20% of compliance features that cover 100% of small businesses.
Paste one <script> tag. The banner loads in under 50ms and never blocks your page.
Every consent event is timestamped and stored with a hashed IP. Export the CSV when a regulator asks.
Access and deletion requests land in a queue you can action in seconds — not spreadsheets.
Small teams, big responsibilities.
D2C brands shipping to Indian customers. One-line install, banner matches your theme.
Small business sites, agencies, and blogs collecting emails and running ads.
You have paying customers before you have a legal team. We're that legal team's script tag.
No enterprise sales calls. No per-seat gotchas. Start free, upgrade when you outgrow it.
Roughly $18/mo. International customers pay in USD at checkout.
ConsentHub is a Consent Management Platform (CMP) and DSAR dashboard — software infrastructure, not legal advice. Compliance with GDPR, CCPA, and DPDP ultimately depends on your implementation, privacy policies, and business practices. See our Terms and DPA.
If you process the personal data of anyone in India — even just an email signup or an analytics cookie — yes. There is no small-business exemption. Rules apply from the day the government notifies them.
No. DPDP requires you to (1) get itemised consent, (2) let people withdraw it as easily, (3) respond to access & deletion requests, and (4) prove all of the above with logs. A static banner does none of that.
Those are GDPR-first tools starting at $50–$500+/mo. ConsentHub is DPDP-first, INR-priced, and designed for teams of 1–20 people. Same audit trail. 10% of the cost.
Sign up, create a site, paste one <script> tag in your <head>. Under 5 minutes. Works on Shopify, WordPress, Wix, Framer, Next.js — anywhere you can drop a script.
In secure managed Postgres. IPs are one-way hashed with a server-side salt before storage — we don't keep raw IPs. You can export or delete everything anytime.