Get Help Your Way

OR

Updated: Jul 17, 2025

Publication security settings for a legacy site

Warning: This article covers instructions for the Legacy Website Builder, only available to accounts created before July 15, 2025. If you are using the New Website Builder (available to all accounts), refer to our guide on security settings for your website. Be sure to follow the steps that match the builder version you're using.

You can manage your publication’s security settings in the Legacy Website Builder, including enabling GDPR and CCPA compliance and setting subscriber login preferences.

Where to enable GDPR & CCPA compliance

  1. From the left panel, go to Website > Builder (Legacy).
     
  2. The Website Builder will open on the Styles tab. Switch to the Settings tab, then scroll down and click on Security in the left panel.


     
  3. The Security section will open. From here you can enable or disable the following security compliance options. Changes will be saved automatically.

    Pro Tip:

    To ensure full GDPR and CCPA compliance, both the Cookie Banner and ToS/Privacy Policy options must be enabled..

    Cookie Banner: Displays a cookie consent banner when someone visits your site. Visitors can choose to opt out of certain cookies.
    Signup ToS and Privacy Policy: Displays your Terms of Service and Privacy Policy during signup. Enabling this means that subscribers must check a box to agree before signing up.

  4. (Optional) To customize your Terms of Service and Privacy Policy, click on Edit Signup ToS. Enter your content in the Terms of Service field and click Confirm to save.


Subscriber log in options

Below the compliance settings, you'll see the Log In options for your website. By default, One-Time Password Login is enabled. You also have the option to enable Subscriber Password Login.

To update either setting, toggle the option on or off. Changes are saved automatically.

One-time password (OTP) enabled subscriber view

This is what your subscriber will see if you have OTP enabled for your account:

Both OTP and password enabled subscriber view

This is what your subscriber will see if you have OTP and subscriber password enabled for your account:

Both OTP and password disabled subscriber view

If both OTP and subscriber password options are disabled, users will receive a magic link in their email to access your publication as a logged in subscriber.

Tech Note: For best results, enable OTP so subscribers can log in from any browser.

Related Articles

Want More Features?

Upgrade your plan to access more beehiiv tools and supercharge your growth

the one place to build
the one place to build
the one place to build
the one place to build
the one place to build
the one place to build
the one place to build
the one place to build
the one place to build
the one place to build
the one place to build
the one place to build