Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
FlowTrack is a US based all in one sales and marketing automation platform combining funnels, email campaigns, SMS, payment processing, sales pipeline tracking and a members area. Coaches, consultants, info product sellers and small e commerce brands use FlowTrack to consolidate their marketing and sales stack. Because FlowTrack hosts visitor data in the United States and adds tracking cookies, GDPR compliance requires explicit consent and a documented transfer chain.
FlowTrack is an all in one sales and marketing automation platform operated from the United States. It bundles funnel building, hosted landing pages, email and SMS campaigns, payment processing, members areas, sales pipeline tracking and webinar replays in a single subscription. Coaches, consultants, info product sellers and small e commerce brands use FlowTrack to replace multiple tools by a unified stack.
FlowTrack collects contact details, behavioural data on funnels, opens and clicks on emails and SMS, payment data (processed via integrated payment gateways), webinar attendance and behaviour, and audit logs of staff interactions. IP addresses, user agents and UTM parameters are stored for attribution and fraud prevention.
FlowTrack is a third party processor and, for some marketing features, may act as joint controller. Tracking cookies and email open pixels are not strictly necessary and require consent under Art. 5(3) ePrivacy. Behavioural profiling and marketing automation must rely on consent under Art. 6(1)(a) GDPR. Payment data must be processed with PCI DSS aligned security.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Add a Consent Management Platform on FlowTrack pages, block analytics and marketing tags until consent is granted, configure double opt in on lead capture forms, and ensure that every commercial email and SMS includes an easy opt out option.
FlowTrack hosts data in the United States. Operators rely on the EU US Data Privacy Framework, complemented by Standard Contractual Clauses with the controller and a Transfer Impact Assessment per Schrems II. Document data minimisation measures such as IP truncation and hashing of email identifiers.
Sign the FlowTrack DPA and SCCs, integrate a CMP, configure double opt in, set retention rules for inactive contacts and orders, restrict admin access with MFA, and document FlowTrack in your Article 30 register. Review every funnel to disable retargeting pixels on regulated content.
Websites using FlowTrack must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is recommended when FlowTrack is used at scale to score prospects, when sensitive content (health, finance) is sold through funnels, or when retargeting pixels and payment data are combined for advertising.
Sample consent text
We use FlowTrack, a US based sales and marketing automation platform, to track your interactions with our funnels, send follow up emails and SMS and process orders. This involves transferring your personal data to the United States.
Third-party domains contacted
flowtrack.coapp.flowtrack.cocdn.flowtrack.coCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ft_uid | Marketing | 1 year | Anonymous FlowTrack visitor identifier used for funnel attribution and lead scoring. |
| ft_funnel | Marketing | 30 days | Stores the current funnel step and the click identifier for incoming marketing campaigns. |
| ft_session | Strictly Necessary | Session | Maintains the editor and member area session for FlowTrack users. |
| ft_cart | Strictly Necessary | 30 days | Persists the order content during the FlowTrack checkout phase. |
FlowTrack places tracking cookies for advertising — comply with GDPR using FlowConsent.
FlowTrack sets a marketing visitor identifier for attribution, a funnel cookie that stores the current step and incoming click identifier, a strictly necessary session cookie for editor and member areas, and a strictly necessary cart cookie during checkout.
Strictly necessary cookies for cart and member areas are exempt. Marketing and behavioural cookies require prior consent under Art. 5(3) ePrivacy and Art. 6 GDPR.
Consent (Art. 6(1)(a) GDPR) for marketing tracking, lead scoring and email or SMS marketing. Performance of a contract (Art. 6(1)(b)) for orders and memberships sold through FlowTrack funnels. Legitimate interest (Art. 6(1)(f)) for fraud prevention with a documented balancing test.
Yes. FlowTrack hosts data in the United States. Transfers rely on the EU US Data Privacy Framework, supplemented by SCCs and a Transfer Impact Assessment.
A DPIA is recommended when FlowTrack handles sensitive content, when large scale behavioural profiling is used or when payment data is combined with retargeting pixels.
Sign the FlowTrack DPA and SCCs, integrate a CMP that gates marketing tags, configure double opt in on lead capture, document FlowTrack in your Article 30 register, and update your privacy notice to disclose the US transfer and integrations enabled.
Yes. Systeme.io (France), Builderall (Brazil with EU options), Brevo (France), GetResponse (Poland) and Plezi (France) offer comparable sales and marketing automation features with EU data residency.
List ft_uid, ft_funnel as marketing cookies and ft_session, ft_cart as strictly necessary. Disclose FlowTrack as a sub processor in the United States and re trigger the consent banner.