FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. Flowbox

Flowbox

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Flowbox do?

Flowbox is a Swedish user generated content and influencer marketing platform used by 1000+ brands across 40 markets. It collects, moderates and publishes social content from Instagram, TikTok, Facebook, Pinterest, YouTube and Twitter into product pages, lookbooks, emails and ads. Flowbox is hosted in the European Union and offers a cookieless mode via the allowCookies parameter, but its analytics tracking is still subject to the GDPR and the ePrivacy Directive.

What is Flowbox and how does it work

Flowbox is a Swedish SaaS platform dedicated to user generated content and influencer marketing. It lets brands aggregate social content from Instagram (hashtags, mentions, stories), TikTok, Facebook, Pinterest, YouTube and Twitter, moderate it, secure media rights from the authors, link it to products, and publish it across product pages, category pages, lookbooks, email widgets, mobile apps, in store screens and dynamic product ads.

Flowbox is integrated through a small JavaScript snippet that loads the chosen flow into a container on the merchant page. Each widget can run with cookies enabled or disabled via the allowCookies parameter, which is unusual for this category of tool and a valuable feature for compliance heavy markets.

What data and cookies Flowbox collects

With cookies enabled, Flowbox sets first party cookies on the merchant domain to recognise returning visitors, group engagement events (impressions, clicks, conversions on linked products) and feed the analytics dashboard. With allowCookies set to false, the widget runs without persistent identifiers and only logs aggregated, non identifying signals.

Beyond visitor data, Flowbox processes the personal data of the original content authors: names, profile pictures, social handles, captions and photos pulled from social platforms. The platform also runs a Visual Search engine, which can apply image recognition to the UGC pool.

GDPR and ePrivacy implications

When Flowbox is configured with cookies, the analytics tracking is not strictly necessary under Article 5(3) of the ePrivacy Directive and prior consent is required. When Flowbox runs in cookieless mode, the consent banner can fall back to a simple notice in the privacy policy, provided no other identifier is set client side.

For UGC ingested from third party platforms, the merchant becomes a data controller for the new processing activity (display on the storefront, use in newsletters, in ads). The Flowbox media rights workflow helps document author consent for that re publication.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data location and transfers

Flowbox is headquartered in Stockholm with offices in Barcelona, Amsterdam and Copenhagen. The core processing infrastructure is hosted in the European Union, which means the visitor and UGC data does not leave the EU under the default configuration. This is a meaningful compliance advantage compared with US based UGC vendors.

Onward transfers can still happen when the UGC DPA feature is used to feed Meta or TikTok dynamic product ads, since those platforms operate globally. That secondary flow must be assessed under Chapter V of the GDPR, with the appropriate safeguards.

How to deploy Flowbox in a compliant way

To use Flowbox on a website that targets EU or UK visitors, you should: decide upfront whether you need analytics tracking or whether the cookieless mode is enough, gate the widget behind consent with a CMP such as FlowConsent when cookies are enabled, name Flowbox in your cookie and privacy policies, sign the Data Processing Addendum, run a DPIA when the UGC DPA retargeting feed is activated, and document the rights granted by each UGC author through the Flowbox media rights workflow.

Alternatives and risk mitigation

For brands looking for an EU hosted UGC stack, Flowbox is one of the strongest options on paper. Comparable vendors include Photoslurp (now part of Flowbox), Stackla and Bazaarvoice for the high end, and Avis Verifies or Trusted Shops when the focus is on reviews rather than visual UGC. To reduce the risk further, run Flowbox with allowCookies set to false on regions where you do not need analytics tracking, and only enable UGC DPA on segments where the social retargeting transfer is documented in your privacy notice.

GDPR consent category

Marketing

Websites using Flowbox must obtain user consent under GDPR regulations.

Legal basisConsent under Article 6(1)(a) GDPR for analytics cookies and engagement tracking. For the UGC pulled from social platforms, the merchant relies on the original platform terms combined with the rights granted by the author or, when needed, on legitimate interests under Article 6(1)(f) with a documented balancing test.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, French Data Protection Act, CNIL cookie guidelines, Swedish Data Protection Authority (IMY) guidance, UK GDPR

DPIA considerations

A Data Protection Impact Assessment is recommended when Flowbox is used at scale, especially with the UGC DPA retargeting feature that pushes UGC into Meta and TikTok ad platforms. Key risks: indirect collection of personal data from third party authors (names, photos, social handles), engagement tracking of EU visitors, and onward transfer to social platforms when UGC DPA is enabled. Document the lawful basis, the necessity test and the rights of the original content authors, including their ability to request removal.

Sample consent text

We use Flowbox to display user generated content and influencer photos on our website. The Flowbox widget can place a small first party cookie to measure engagement and conversion. Our platform supplier is based in Sweden, so the core data stays in the European Union. You can accept, refuse or customise these cookies and you can withdraw your consent at any time from our cookie preferences page.

Technical details

Tracking methodJavaScript widget embedded in product pages, listing pages and lookbooks, first party cookies for analytics and engagement tracking, optional cookieless mode via allowCookies parameter, integration with Instagram, TikTok, Facebook, Pinterest, YouTube and Twitter, UGC Dynamic Product Ads (UGC DPA) for retargeting on Meta
Server locationEuropean Union (Sweden), with regional CDN nodes
Cookieless tracking availableYes

Third-party domains contacted

getflowbox.comjs.getflowbox.comapi.getflowbox.comcdn.getflowbox.com

Cookies placed

NameTypeDurationPurpose
flowboxfirst_party1 yearFirst party visitor identifier set on the merchant domain when allowCookies is true, used to recognise returning visitors and group engagement events such as impressions, clicks and conversions on linked products
flowbox_sessionfirst_partysessionSession level identifier used to group widget interactions within a single visit, only set when allowCookies is true

Flowbox places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Flowbox set?

When the widget is loaded with allowCookies set to true, Flowbox places a small first party cookie on the merchant domain to recognise returning visitors and group engagement events such as impressions, clicks and conversions on linked products. When allowCookies is set to false, no persistent identifier is stored and only aggregated, non identifying signals are sent to the analytics dashboard.

Do I need consent before loading Flowbox?

It depends on the configuration. With cookies enabled, Flowbox is an analytics and engagement tool that falls outside the strictly necessary exemption of Article 5(3) of the ePrivacy Directive, so prior consent is required. With cookieless mode (allowCookies false) and no other identifier set, the consent banner can be lighter, but the privacy policy must still mention Flowbox and the UGC ingestion.

What is the legal basis for Flowbox under GDPR?

For visitor tracking with cookies, the lawful basis is consent under Article 6(1)(a). For the UGC pulled from social platforms, the merchant relies on the original platform terms combined with the rights granted by the author via the Flowbox media rights workflow and, when needed, on legitimate interests under Article 6(1)(f) with a documented balancing test.

Where does Flowbox store my data?

Flowbox is operated by a Swedish SaaS company and hosts its core processing infrastructure in the European Union. Visitor data and UGC do not leave the EU under the default configuration. Onward transfers can occur when the UGC DPA feature pushes content into Meta or TikTok ad platforms, in which case Chapter V GDPR safeguards apply on that secondary leg.

Do I need a DPIA before deploying Flowbox?

A DPIA is recommended when Flowbox is deployed at scale, especially with the UGC DPA retargeting feed enabled. The combination of engagement tracking, indirect collection of personal data from third party authors, and onward transfer to social ad platforms triggers several criteria from the EDPB DPIA list. Document the lawful basis, the data flows, the safeguards and the rights of all data subjects.

How do I make my Flowbox integration GDPR compliant?

Decide whether you need analytics tracking or whether the cookieless mode is enough. Block the widget behind consent through a CMP such as FlowConsent when cookies are enabled, classify it under analytics or marketing, name Flowbox in your privacy and cookie policies, sign the Data Processing Addendum, run a DPIA when UGC DPA is activated, and use the Flowbox media rights workflow to document author consent for republication.

Are there alternatives to Flowbox for European brands?

Flowbox is one of the strongest EU hosted UGC vendors on the market. Comparable options include Photoslurp (now part of Flowbox), Stackla and Bazaarvoice for the high end, and Avis Verifies or Trusted Shops when the focus is on reviews rather than visual UGC. For lighter use cases, native Shopify or PrestaShop reviews extensions can also work without third party tracking.

How do I update my cookie policy for Flowbox?

List Flowbox in your cookie policy under the analytics or marketing category when allowCookies is true. Specify the cookie name, the purpose (engagement tracking and conversion measurement), the duration, the controller and processor roles, and the fact that the data stays in the European Union by default. Mention Flowbox in your privacy policy regardless of the cookie configuration, since UGC ingestion involves processing of third party authors data.