FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. Convertful

Convertful

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Convertful do?

Convertful is a US, based onsite conversion optimisation tool that displays popups, slide, ins, gamified opt, ins and embedded forms to capture email leads. The widget tracks visitor behaviour with first, party cookies to optimise display timing and frequency, then synchronises captured emails to popular CRM and email platforms. Because Convertful both writes identifying cookies and processes lead data on US servers, it requires consent under EU rules.

What is Convertful?

Convertful is an onsite conversion optimisation platform launched in 2017 by Convertful Inc. and operated from the United States. It targets ecommerce stores, content publishers, and SaaS companies that want to convert anonymous traffic into newsletter subscribers, leads, or buyers. The product offers a drag, and, drop builder with templates for exit, intent popups, slide, ins, embedded inline forms, gamified opt, ins (spin, the, wheel, scratch cards), survey funnels, and announcement bars. Captured emails sync into 30, plus marketing platforms (Mailchimp, ActiveCampaign, ConvertKit, Klaviyo, HubSpot) through native integrations or webhooks. The widget loads from convertful.com or a CDN endpoint and is added with a single JavaScript snippet.

Cookies and data collected by Convertful

Convertful writes a first, party cookie called cnvf_visitor (typically 1 year) used to recognise returning visitors, enforce frequency caps, and attribute conversions to a popup. A second cookie cnvf_session captures the current session ID. The widget also writes a localStorage entry to remember which popups have been shown and dismissed. On the server side, Convertful logs visitor IP addresses, user agent strings, page URLs, scroll behaviour, and any data the visitor enters into a popup field (typically email, name, phone). When the email is forwarded to a downstream ESP, Convertful retains a copy of the lead in its dashboard for reporting purposes.

GDPR and ePrivacy implications

Convertful sits at the intersection of cookies and direct marketing, both of which are regulated under the ePrivacy Directive and GDPR. The cnvf_visitor cookie and the localStorage entry require prior consent under Article 5(3) ePrivacy because they go beyond strictly necessary functionality. The email address captured in the popup is personal data; processing it for marketing requires a separate, granular consent that meets the Article 7 GDPR requirements (freely given, specific, informed, unambiguous). Crucially, the same checkbox cannot bundle the cookie consent and the marketing consent, that practice has been sanctioned multiple times by the CNIL and the Spanish AEPD.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Two consents are typically needed. First, the Convertful widget must be loaded only after the visitor has accepted the Marketing or Functional category in the CMP, so the cookies and tracking script do not fire on refusal. Second, every popup that captures personal data must include a clear privacy notice and an explicit opt, in mechanism for the marketing communications that follow. Pre, ticked boxes are not valid consent. The opt, in record (timestamp, IP, exact wording shown) should be stored to demonstrate compliance under Article 7(1) GDPR.

International data transfers

All Convertful data is hosted in the United States on AWS. Convertful Inc. is not currently certified under the EU, US Data Privacy Framework, so the contractual basis for the transfer is the set of Standard Contractual Clauses included in the DPA, complemented by a Transfer Impact Assessment. The TIA must consider the type of data captured (email and name in most cases, but sometimes more sensitive answers in survey funnels), the volume of European visitors, and the additional sub, processors involved (the ESP that ultimately stores the email). For high, scale European deployments, EU, hosted alternatives are easier to defend.

Practical compliance steps

Sign a DPA with Convertful Inc., gate the widget script behind the Marketing or Functional category of your CMP, and never load it before the consent event. Configure each popup with an explicit double, opt, in for the email list (single, opt, in is allowed under GDPR but double, opt, in provides stronger evidence of consent). Set a reasonable retention period for the captured leads in both Convertful and the downstream ESP. Document the chain of sub, processors in the privacy policy. For European audiences sensitive to US transfers, consider EU, hosted alternatives such as Mailerlite Popups (Lithuania), Brevo Forms (France), or open source tools like Sumo replaced by Convert (Belgium).

GDPR consent category

Marketing

Websites using Convertful must obtain user consent under GDPR regulations.

Legal basisConsent (GDPR Article 6(1)(a)) for the cnvf_visitor identifier and the popup display tracking, since these go beyond strictly necessary functionality. Consent (Article 6(1)(a)) for any email opt-in collected through the popup, with a clear and granular description of the future processing. Legitimate interest is hard to defend because the visitor is profiled to optimise popup timing.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidelines, TTDSG (Germany), LOPDGDD (Spain), CCPA, EU, US Data Privacy Framework

DPIA considerations

A DPIA is recommended when Convertful is used at scale, when popups capture sensitive data (financial, health, vulnerability indicators), or when the email leads are passed into automated marketing flows for B2C customers. The combination of US storage and persistent visitor tracking elevates the risk profile. Document the DPA with Convertful Inc., the legal basis for both the cookies and the lead capture, the retention period of the leads, and the downstream sub, processors that receive the email addresses (CRM, ESP).

Sample consent text

We use Convertful to display promotional popups and to collect email subscriptions on our website. Convertful sets a first, party cookie (cnvf_visitor) to manage popup display frequency and stores any data you submit on its servers in the United States. Do you accept the use of Convertful for marketing and personalisation purposes?

Technical details

Tracking methodJavaScript widget loaded from convertful.com / cdn.convertful.com that displays popups, slide-ins, embedded forms and gamified opt-ins (spin-the-wheel). Sets first-party cookies (cnvf_visitor, cnvf_session) plus a localStorage entry to track popup display rules, frequency capping, and conversion attribution. Form submissions are POSTed to Convertful's servers and synchronised with email marketing platforms via integrations (Mailchimp, ActiveCampaign, ConvertKit, HubSpot, etc.).
Server locationUnited States. Convertful Inc. operates the platform on AWS infrastructure in the US. CDN delivery uses Cloudflare's global edge. No EU data residency option is offered.
Data transferred outside the EUYes. All Convertful tracking traffic, popup configurations, and lead submissions are processed by Convertful Inc. in the United States. Visitor IPs, browser metadata, popup interactions and email addresses captured through opt-in forms are transmitted to and stored on US servers. Standard Contractual Clauses are signed in the DPA. A Transfer Impact Assessment is recommended.

Third-party domains contacted

convertful.comapp.convertful.comcdn.convertful.comstatic.convertful.com

Cookies placed

NameTypeDurationPurpose
cnvf_visitorfirst-party1 yearUnique visitor identifier set by the Convertful widget. Used to recognise returning visitors, enforce popup frequency caps and attribute conversions to a specific opt-in.
cnvf_sessionfirst-partySessionSession identifier used by Convertful to group page views and popup interactions during a single browsing session.

Convertful places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Convertful set?

Convertful writes a first, party cookie cnvf_visitor (typically 1 year) used to recognise returning visitors, enforce frequency caps and attribute conversions, and a session cookie cnvf_session for the current session. The widget also writes a localStorage entry to remember which popups have been shown and dismissed.

Is consent required to use Convertful?

Yes. Both the cnvf_visitor cookie and the localStorage entry go beyond strictly necessary functionality and require prior consent under Article 5(3) of the ePrivacy Directive. The Convertful widget script must be loaded only after the visitor has accepted the Marketing or Functional consent category in your CMP.

What is the legal basis for processing data with Convertful?

Consent (GDPR Article 6(1)(a)) for the cookies and the marketing email opt, in collected through the popup. The two consents must be granular and cannot be bundled into a single checkbox. Pre, ticked boxes are not valid. Keep an audit trail (timestamp, IP, exact wording) for each subscription.

Are data transferred to the United States?

Yes. Convertful Inc. processes all data on AWS infrastructure in the US. SCCs are signed in the DPA. Convertful is not currently certified under the EU, US Data Privacy Framework, so a Transfer Impact Assessment is recommended, especially for B2C deployments at scale.

Is a DPIA required for Convertful?

A DPIA is recommended when Convertful is used at scale, when popups capture sensitive data, or when leads are pushed into automated marketing flows targeting consumers. The combination of US storage, persistent cookies and direct marketing makes the residual risk medium, which often crosses the DPIA threshold.

How do I implement Convertful in a compliant way?

Sign a DPA with Convertful Inc., gate the widget behind the CMP, use a granular opt, in inside the popup with explicit privacy notice, prefer double opt, in for the email list, set retention periods in both Convertful and the downstream ESP, and document the SCCs plus a Transfer Impact Assessment for the US transfer.

Are there alternatives to Convertful?

EU, hosted alternatives include Mailerlite Popups (Lithuania), Brevo Forms (France), Klaviyo with EU residency, Convert (Belgium), Mautic (open source, self, hostable), and Optimonk (Hungary, EU). For minimal privacy footprint, simple HTML forms wired to your own backend are also viable.

How do I update the cookie policy for Convertful?

List Convertful as a sub, processor with the cookies cnvf_visitor (1 year) and cnvf_session (session), plus the localStorage entry. State that Convertful Inc. is the processor, the United States is the data location, and SCCs are the transfer safeguard. Mention the email lists or CRM systems that ultimately receive the leads.