Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Bambuser is a Swedish live and shoppable video platform used by retailers and brands to broadcast interactive shopping shows, one to one video calls and shoppable on demand clips. Its embedded player loads third party JavaScript, sets bambuser_session and bm_uid cookies and forwards viewing, click and basket events to Bambuser servers, which makes it a third party tracker requiring prior consent under the GDPR and ePrivacy Directive.
Bambuser is a Swedish live and shoppable video SaaS founded in 2007. It powers live shopping shows, one to one consultative video calls and shoppable on demand clips for retailers and luxury brands. The platform integrates with Shopify, Magento, Salesforce Commerce Cloud, SFCC and BigCommerce, and the player is embedded on the merchant site through a small JavaScript snippet.
The Bambuser player writes bambuser_session and bm_uid cookies on the embed.bambuser.com domain and stores a player state in local storage. View events, click events and add to cart events are forwarded to Bambuser servers, attached to the viewer identifier. When a one to one video call is launched, voice and video streams are processed in real time.
Loading the player drops third party cookies and JavaScript that are not strictly necessary, so prior consent is required under Article 5(3) ePrivacy. The behavioural processing for analytics and personalisation requires a GDPR legal basis, typically consent. One to one video calls additionally process voice and video, which are personal data and may include images of children or vulnerable users.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Block embed.bambuser.com through your CMP until consent is granted. A click to play pattern (a poster image with a play button that loads the player on click) is a frequent compliance shortcut for live shows and on demand clips. For one to one video calls, capture explicit consent with a recorded checkbox before starting the call.
Bambuser AB is headquartered in Stockholm and runs production on AWS in EU regions (Ireland and Frankfurt) by default, with US regions available for global plans. US transfers, when present, rely on the EU U.S. Data Privacy Framework or Standard Contractual Clauses listed in the Bambuser DPA.
Sign the Bambuser DPA, gate the player on a CMP signal or a click to play, request EU only data residency where available, document Bambuser AB and its sub processors in your records of processing, set retention policies on viewing events and recordings, and disclose the integration in the privacy policy.
Websites using Bambuser must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA can be relevant when Bambuser is integrated with the merchant CRM, when one to one video calls capture audio and video of consumers, or when behavioural data is used for personalisation and audience targeting beyond the live show.
Sample consent text
We use Bambuser to broadcast live and shoppable video on this site. With your consent, the Bambuser player will load on your device, store viewing cookies and forward your interactions to Bambuser AB and its sub processors. You can refuse or withdraw your consent at any time from the cookie settings.
Third-party domains contacted
embed.bambuser.comcdn.bambuser.comlcx-cdn.bambuser.comlive.bambuser.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| bambuser_session | third_party | session | Maintains the player session and viewer state during a live show or on demand video on embed.bambuser.com. |
| bm_uid | third_party | 1 year | Anonymous viewer identifier used by Bambuser to attribute viewing events, clicks and basket interactions to the right session. |
| __cf_bm | third_party | 30 minutes | Cloudflare bot management cookie set on Bambuser endpoints to mitigate automated traffic during live broadcasts. |
Bambuser places tracking cookies for advertising — comply with GDPR using FlowConsent.
The Bambuser player writes bambuser_session and bm_uid third party cookies on embed.bambuser.com and stores a player state in local storage. Additional cookies may be set when integrating with the merchant analytics or CRM.
Yes. Loading the player drops third party cookies and JavaScript that are not strictly necessary, so prior consent is required under Article 5(3) ePrivacy. One to one video calls additionally need explicit consent for voice and video processing.
Consent for cookies and behavioural processing. Contract performance for completing a purchase started during a live show. Consent for processing voice and video in one to one calls.
Bambuser AB hosts on AWS, EU regions by default. Some plans, sub processors or fallback regions may involve US transfers, covered by the EU U.S. Data Privacy Framework or Standard Contractual Clauses in the DPA.
A DPIA is recommended when one to one video calls are recorded, when behavioural data feeds personalisation across the merchant, or when the audience includes children or sensitive consumers.
Sign the DPA, gate the player on a CMP or click to play, request EU only data residency, set retention on events and recordings, document Bambuser AB and its sub processors and disclose the integration in the privacy policy.
EU friendly live shopping platforms include Caast.tv (France), Spockee (France), LiSA (Italy) or self hosted live streaming via OBS plus a custom shoppable overlay.
Add a section that names Bambuser, lists the cookies (bambuser_session, bm_uid) with purpose and duration, mentions the live shopping integration and discloses any US sub processor when applicable.