Free PDPL + GDPR cookie consent banner for Saudi, UAE, and GCC WordPress sites. Native Arabic RTL. Live in 60 seconds. No code, no developer, no credit card.
The free tier covers what most stores need: a compliant banner with PDPL, GDPR, and UAE PDPA detection, native Arabic, Google Consent Mode v2, GPC support, a bilingual cookie declaration page, 1 domain, and 10,000 pageviews per month — forever. Upgrade when you’re ready for the Cookie Scanner, DSAR portal, server-side event forwarding, audience activation, custom banner branding, or multi-domain support.
Key Features:
Works with WooCommerce and any WordPress site.
The plugin loads its script in the document <head>, before any other script
WordPress prints, so the Google Consent Mode v2 “denied” default is set before
your tags read it.
There is one case it cannot control. If your Google Tag Manager or GA4 snippet
is pasted directly into your theme’s header.php above the wp_head()
call, that snippet runs before anything WordPress outputs, including this
plugin — and it will read no consent state.
Two ways to be sure:
wp_head() in your theme, orIf you manage tags entirely inside a GTM container loaded via a plugin or
wp_head, no action is needed.
Most sites have no CSP and need nothing here. If yours sends one — directly, or
through a security plugin — the widget needs three allowances, and it fails
silently without them: the browser blocks the script and no banner appears,
which looks like the plugin is broken rather than like a policy is doing its job.
script-src https://cdn.arqam360.com — the banner script itself.connect-src https://api.arqam360.com — fetching your widget configurationstyle-src 'unsafe-inline' — the banner builds its stylesheet at runtime soThe widget contacts no other host. It loads no external fonts and no
third-party resources.
If you embed the Arqam360 dashboard inside wp-admin, that page additionally
needs frame-src https://app.arqam360.com. That applies only to the wp-admin
screen, never to your public pages.
The plugin uses two credentials from your Arqam360 dashboard, in the same way
Stripe uses a publishable key and a secret key:
ciq_live_...) — public. It appears in your page source andciq_sk_live_...) — secret. It opens your Arqam360 dashboardThe two are not interchangeable and the settings page will refuse a credential
pasted into the wrong field.
This plugin connects to the Arqam360 service to function:
Arqam360 CDN (cdn.arqam360.com) — The consent banner JavaScript is loaded from Arqam360’s CDN. This script renders the cookie consent banner on your site and handles consent collection. No personal visitor data is sent to the CDN; it only serves the static JavaScript file.
Arqam360 API (api.arqam360.com) — When a Widget Key is configured, the plugin fetches your widget configuration (colors, text, position, compliance settings) from the Arqam360 API. Consent records are also sent to this API for storage and analytics. Your Widget Key authenticates these requests. If a Site Token is also configured, it is used only to open the dashboard inside wp-admin, and is sent from your server to api.arqam360.com over HTTPS — never to a visitor’s browser.
A free Arqam360 account is required (free forever for the consent banner, no credit card). Sign up at arqam360.com.
If you build WordPress or WooCommerce sites for clients, Arqam360 runs a partner
programme. Your client subscribes to Arqam360 directly and you earn 20% of what
they actually pay, for 12 months from their first paid invoice.
You install nothing extra and support nothing — we handle the consent side. A
client who stays on the free plan earns you nothing, so this is worth it where
you are already recommending a paid tool.
Terms, including how referrals are attributed and how payouts work:
https://arqam360.com/partners