Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Birdeye is a United States based customer experience platform used by businesses to collect online reviews, manage their reputation, run surveys and talk to customers through webchat and messaging. When its webchat and review widgets are added to a website they load from Birdeye servers, open a chat session, and collect the contact details a visitor enters such as name, email and phone number, so they read and write cookies and browser storage on the visitor device. Because this is non essential tracking and messaging, the Birdeye widgets must load only after the visitor has given consent.
Birdeye is a customer experience platform based in the United States. It helps businesses collect online reviews, manage their reputation, send surveys and talk to customers through webchat and messaging. On a website, the Birdeye webchat and review widgets run as embedded components that load their code from Birdeye servers and render inside the host page, where a visitor can start a live chat or leave a review.
When a visitor opens the webchat, Birdeye opens a chat session and collects the contact details the visitor enters, such as name, email address, phone number and the content of the messages. It stores a first party identifier in cookies and browser storage so an ongoing conversation and a returning visitor can be recognised and linked to a single record. The review and survey widgets collect the ratings, feedback and contact details a customer submits, and Birdeye can route these conversations and review invitations to the business inbox and connected tools.
The contact details, conversation content and identifiers that Birdeye processes are personal data under the GDPR, because they relate to an identifiable visitor. Storing and reading identifiers on the visitor device also falls within Article 5(3) of the ePrivacy Directive, which the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain all enforce as a strict prior consent obligation for non essential cookies.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before the Birdeye widgets load, because they are not strictly necessary for the visitor to receive the content of the page. That consent must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as to accept. Until the visitor accepts, the Birdeye script should not run and no cookies or browser storage entries should be written.
Birdeye processes data on United States infrastructure, so European visitor data is transferred outside the European Economic Area. Such transfers require the EU Standard Contractual Clauses within the Birdeye Data Processing Addendum and a documented Transfer Impact Assessment that considers United States surveillance law, in line with the Schrems II ruling and the guidance of the European Data Protection Board.
Gate the Birdeye widgets behind your consent management platform so they fire only after the relevant category is accepted. Provide clear information about Birdeye in your cookie policy, including the identifiers it sets and their lifetime. Sign the Birdeye Data Processing Addendum, complete a Transfer Impact Assessment and apply the shortest workable retention on visitor and message records. Where a feature such as review capture is not needed on a given page, disable it to minimise the personal data collected.
Websites using Birdeye must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is advisable when Birdeye is used at scale to handle webchat conversations, collect customer contact details and profile visitors across a website. Document the personal data collected through the webchat and review widgets, the first party identifiers stored in cookies and browser storage, the routing of conversations and review invitations into the Birdeye inbox and connected tools, the transfer of data to the United States and the retention period applied to visitor and message records. Configure the widgets so that they load only after consent and disable any collection that is not strictly necessary.
Sample consent text
We use Birdeye, a customer experience and webchat service operated by Birdeye Inc. (United States), to offer live chat and to request reviews. Birdeye stores identifiers in cookies and browser storage on your device and processes the contact details you enter. This data may be transferred to the United States under the EU Standard Contractual Clauses. Birdeye will only load if you click Accept.
Third-party domains contacted
birdeye.comcdn2.birdeye.comapi.birdeye.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| birdeye_visitor_id | HTTP cookie (first party) | 12 months | Stores a persistent identifier for the website visitor so Birdeye can recognise a returning visitor and link webchat conversations and review requests to a single record. |
| birdeye_session | HTTP cookie (first party) | Session | Holds the current webchat session so that messages and interactions during a single visit are grouped together. |
| birdeye_webchat_state | localStorage | Persistent (until cleared) | Stores the state of the webchat widget, such as whether the chat window is open and its last position, so the widget behaves consistently across page views. |
| birdeye_conversation | localStorage | Persistent (until cleared) | Stores the ongoing conversation identifier and buffered messages so an open webchat conversation can continue as the visitor navigates the site. |
Birdeye places tracking cookies for advertising — comply with GDPR using FlowConsent.
Birdeye sets a first party visitor identifier that persists for several months, a webchat session cookie, and browser storage entries that hold the state of the chat widget and the ongoing conversation. Together they let Birdeye recognise a returning visitor and keep a webchat conversation connected across page views.
Yes. The Birdeye webchat and review widgets perform non essential tracking and messaging and write identifiers to the visitor device, so under the ePrivacy rules you must obtain prior consent before they load. The Birdeye script should stay blocked until the visitor accepts.
The only valid legal basis is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. Legitimate interest cannot be used for this kind of non essential webchat and tracking.
Yes. Birdeye Inc. hosts its platform on United States infrastructure, so European visitor data, webchat conversations and contact details are transferred there. You need the EU Standard Contractual Clauses in the Birdeye Data Processing Addendum and a Transfer Impact Assessment to cover the transfer.
A Data Protection Impact Assessment is recommended when Birdeye is used at scale to run webchat, collect customer contact details and profile visitors. Assess the messaging and tracking, the identifiers stored on the device, the routing into connected tools and the United States transfer.
Load the widgets only through your consent management platform after the relevant category is accepted, describe Birdeye in your cookie policy, sign the Data Processing Addendum and complete a Transfer Impact Assessment. Disable any collection that is not needed and apply a short retention period to visitor and message records.
Alternatives include Podium, Yotpo, Trustpilot, Reputation and Tidio for webchat. They raise similar consent, cookie and transfer questions, so evaluate their hosting location and data processing terms before assuming any of them is lighter on privacy.
Add a dedicated entry that names Birdeye as the provider, lists the visitor and webchat session identifiers with their lifetimes, explains the contact details and conversation data collected, and discloses the United States transfer and its safeguard. Keep the entry in step with your consent categories.