Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
PushEngage is a United States based web push notification platform. Visitors opt in through the browser permission prompt, and PushEngage stores a subscriber identifier and geolocation to deliver and measure notifications.
PushEngage is a United States based platform for browser web push notifications. Website owners add a script and a service worker, and visitors subscribe by accepting the browser permission prompt. PushEngage then delivers targeted notifications and reports on delivery and engagement.
PushEngage lets marketers build push subscriber lists and send broadcasts, drip campaigns and automated notifications. It relies on the browser push API and a service worker registered on your domain, plus a dashboard for segmentation and analytics.
PushEngage assigns a persistent subscriber identifier stored in the browser push subscription and records geolocation at opt in, typically country, region and city, along with engagement events such as notification clicks. The dashboard uses first party cookies for the account interface. Although PushEngage states it does not collect data that directly identifies an individual at subscription, persistent identifiers tied to behaviour are personal data under the GDPR.
Web push requires explicit consent. Under the ePrivacy Directive the storage of the push subscription on the device and any non essential script should follow consent, and the browser permission prompt alone is not always sufficient for a documented GDPR consent. Best practice is to obtain consent before the PushEngage script loads, separate from the native browser dialog.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because PushEngage operates from the United States, subscriber identifiers, geolocation and engagement data are transferred outside the EEA. Transfers should rely on Standard Contractual Clauses or the EU US Data Privacy Framework and be backed by a data processing agreement.
Present a clear opt in explaining what notifications you will send, load the PushEngage script only after consent, sign a data processing agreement, document the United States transfer safeguards and give subscribers an easy way to unsubscribe. Describe the service in your privacy and cookie policy.
Websites using PushEngage must obtain user consent under GDPR regulations.
DPIA considerations
A full data protection impact assessment is not usually mandatory for standard web push, but a documented assessment is recommended because PushEngage assigns persistent subscriber identifiers, captures geolocation and transfers data to the United States. Assess whether notification targeting amounts to behavioural profiling and document the lawful basis and transfer safeguards.
Sample consent text
We use PushEngage to send web push notifications. With your permission a subscriber identifier and approximate location are stored and data may be transferred to the United States. Click Allow to subscribe, or dismiss to decline.
Third-party domains contacted
pushengage.comclientcdn.pushengage.coma.pushengage.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Push subscriber identifier | Marketing | Persistent until unsubscribe | Persistent identifier stored in the browser push subscription so PushEngage can target and measure notifications. |
| Dashboard session cookie | Necessary | Session | Maintains the authenticated session in the PushEngage dashboard. |
| Analytics cookie | Analytics | Up to 2 years | Used in the PushEngage dashboard and website to measure usage and engagement. |
PushEngage places tracking cookies for advertising — comply with GDPR using FlowConsent.
PushEngage relies mainly on a persistent subscriber identifier stored in the browser push subscription rather than traditional cookies on the visitor side, and it captures geolocation at opt in. The PushEngage dashboard uses first party cookies for the account interface. Review what is actually stored and consult the current PushEngage documentation.
Yes. Web push subscriptions require explicit consent for EU users, and best practice is to obtain consent before the PushEngage script loads, in addition to the native browser permission prompt. The notification must be a clear, affirmative opt in.
Consent under Article 6(1)(a) of the GDPR is the appropriate basis for sending marketing push notifications, combined with consent under the ePrivacy Directive for storing the push subscription on the device. Legitimate interests is not a sound basis for marketing push to EU subscribers.
Yes. PushEngage is United States based, so subscriber identifiers, geolocation and engagement data are processed in the US. Transfers from the EEA should rely on Standard Contractual Clauses or the EU US Data Privacy Framework, backed by a data processing agreement.
A full data protection impact assessment is not always mandatory, but a documented assessment is advisable because of persistent identifiers, geolocation capture, possible behavioural targeting and the United States transfer. Record the categories of data, the purposes and the transfer safeguards.
Show a clear two step opt in explaining the notifications, load the script only after consent, sign a data processing agreement, document the United States transfer safeguards, offer an easy unsubscribe and describe the service in your privacy and cookie policy.
Alternatives include OneSignal, WonderPush, Firebase Cloud Messaging and various EU based push providers. Compare their hosting location, data retention, transfer safeguards and consent handling against your privacy requirements.
Add an entry explaining that you use web push via PushEngage, that a subscriber identifier and approximate location are stored, that data may be processed in the United States and that subscribers can unsubscribe at any time. Name PushEngage as a processor and link to its privacy notice.