What the banner costs

Cookie banners are increasingly hard to refuse, so visitors dismiss them and your website analytics never counts them. Cabin doesn't need one.
by Nic Mulvaney, Sat, 14 Feb 2026
What the banner costs

Accepting a cookie usually takes one click. Refusing often takes a second screen, a list of switches for things like "legitimate interest", a scroll to the bottom to find the ones already turned on, and then a Confirm button.

Most people don't bother. They accept to make it disappear, or they hit the X, or just leave it visible while they browse.

In one US study, 61% of people believed that closing a banner rejects cookies. On many sites it does the opposite. So a good share of your visitors have no idea if they agreed or not, and neither do you.

What cookies do to your analytics

Analytics that needs consent should only record the visitors who explicitly said yes. Everyone else is invisible to it: the ones who dismissed the banner, the ones who ignored it, the ones who genuinely refused.

After the GDPR deadline, a study of 1,084 companies using Adobe Analytics counted 12% fewer European pageviews. The visitors still came, but they just weren't recorded.

Move the reject button off the first screen, and ask later - consent climbs by more than a fifth of all visitors. Same site, same visitors, one layout change.

Do banners even work?

A team at ETH Zurich scanned 29,398 websites and found 94.7% had at least one potential privacy violation. Two thirds assumed consent before anyone had given it. One in five set cookies after the visitor had actively refused.

So the banner may be confusing your visitors and thinning your data while still setting the cookies it promised not to. What is it actually buying you?

Cabin doesn't use cookies

Cabin sets no cookies, builds no fingerprint and creates no identifier of any kind. There's nothing to ask permission for, so it needs no consent under GDPR, CCPA, ePrivacy or PECR. Every visitor gets counted, whatever they click or don't click. There's a longer explanation of how that works.

Remember, if you run other ad pixels or embed video that set their own cookies, you may still want a short notice for those. But your analytics stops depending on it.

Ad blockers take another bite

Consent isn't the only thing between you and your own numbers. Ad blockers block analytics scripts by domain, so some visitors go uncounted even with no banner in sight.

These block lists rightly draw a very hard line on anything even resembling tracking. Cabin is on most block lists, and that's fine by us. Everyone has the right to block any browser request they like.

Cabin has a feature (on Plus and above) where you can easily serve the script and visitor ingestion from your own domain, using a single CNAME record, so it reads as analytics.yoursite.com rather than a domain on a blocklist. The request goes through and those visits get counted.

Nothing changes for the visitor. Cabin still sets no cookies and still cannot identify anyone, whichever domain the script came from. You just get to see a little more of the traffic you already had.

Compare Cabin with your current analytics

Cabin's free plan covers 10,000 pageviews a month across 10 sites. Try it and run it alongside your current analytics for a fortnight. The two numbers probably won't match exactly. The difference is the visitors you weren't seeing.

Footnotes

  • The 61% figure: Farronato, Fradkin & Lin, "Designing Consent", NBER 34025. A field experiment with 563 US participants, so treat it as US rather than European behaviour. The same study found 22% of people close the banner without choosing anything, on top of the 14% who actively reject.
  • The 12% figure: Goldberg, Johnson & Shriver, "Regulating Privacy Online", American Economic Journal: Economic Policy 16(1), 2024. 1,084 firms, Adobe Analytics data, European pageviews "recorded by the platform".
  • The 20-point swing: Nouwens et al., "Dark Patterns after the GDPR", CHI 2020. 680 popular UK websites, plus an experiment with 40 people. The same paper found only 11.8% of sites met the minimum requirements it drew from European law.
  • The 94.7% figure: Bollinger, Kubicek, Cotrini & Basin (ETH Zurich), USENIX Security 2022. 29,398 sites; 69.7% assumed consent before it was given, 21.3% set cookies despite explicit refusal.