Timberdocs

Using Timber

Privacy & cookies

Timber ships a consent banner you can restyle and re-word completely (Privacy → Cookie consent).

  • Categories: Strictly necessary (always on), Analytics, Marketing, Functional. Choose which are offered and describe the cookies in each.
  • Layout: several banner and settings-panel layouts and positions, a floating re-open button, and accept / necessary-only / customise buttons.
  • Re-consent: bump the revision number to ask everyone again.
  • Bots: hidden from crawlers; essential behaviour is unaffected.

With it on, Timber sets consent defaults to denied before any Google tag loads, then updates them when the visitor chooses — and restores a returning visitor's choice immediately, in the browser, so cached pages never leak one visitor's consent to another. Options include URL passthrough, ads data redaction and the wait time.

Any script added as a Block can be tagged with a consent category. It stays inert (type="text/plain") until the visitor allows that category. You can also hold your own <script data-consent="analytics"> tags in page content.

Turn on Record consents to keep a log of choices (an anonymous id, no IP address) for your compliance records.

Data requests#

A Privacy data request form lives at /privacy/data-request for access, deletion, correction and opt-out requests (GDPR, UK GDPR, CCPA/CPRA). Requests land in the inbox with a 30-day reminder.

Policy templates#

Privacy → Legal pages can generate starter text for a privacy policy that you then edit. A sample Privacy Policy page is created on install.

Privacy by default#

Starter themes make no third-party requests. Google Analytics only loads if you add an ID, and only after consent when the banner is on. The admin makes none either (the optional Monaco code editor loads from a CDN only when you open it).

Timber is open source. Built by indies, for indies. © 2026