FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. SharpSpring

SharpSpring

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does SharpSpring (Constant Contact Lead Gen and CRM) do?

SharpSpring is a marketing automation and CRM platform now branded as Constant Contact Lead Gen and CRM. It tracks website visitors, captures form submissions and runs lead scoring, setting persistent identification cookies that require prior consent under GDPR and the ePrivacy Directive.

What SharpSpring is and what it does on your website

SharpSpring is a B2B marketing automation platform acquired by Constant Contact in 2021 and rebranded as Constant Contact Lead Gen and CRM. On a website it operates through an asynchronous JavaScript tracker (__ss.js), embedded form snippets and optional landing page builders. The tracker identifies anonymous visitors with persistent cookies, observes page views, button clicks and form submissions, and feeds the data into a CRM workspace that runs lead scoring, dynamic emails, drip campaigns and reporting.

Cookies and data collected by SharpSpring

SharpSpring writes first party cookies such as __ss (anonymous tracker identifier, up to 10 years), __ss_tk (session identifier) and koitk (Koi tracking subdomain). It also calls subdomains hosted under koi.com to record events. When a known prospect submits a form, the platform stitches the cookie identifier to the email address and starts processing personal data: name, email, phone, IP, page history and any custom fields collected through forms or imports.

GDPR, ePrivacy and consent

Under Article 5(3) of the ePrivacy Directive, the SharpSpring tracker can only be loaded after a valid opt in: it sets non strictly necessary cookies and triggers profiling. Under the GDPR the website operator is controller and Constant Contact is processor. A Data Processing Agreement under Article 28 is mandatory, with a sub processor list and clear retention rules.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International transfers to the United States

SharpSpring runs on US infrastructure. EU controllers must put Standard Contractual Clauses in place under Article 46(2)(c) GDPR and, where Constant Contact is certified, rely additionally on the EU US Data Privacy Framework. A transfer impact assessment should document government access risks and the additional safeguards (encryption, role based access, audit logs).

Compliance checklist for EU operators

Block the SharpSpring tracker by default and load it after marketing consent. Sign the Constant Contact DPA, store the consent record alongside the lead in the CRM, expire visitor cookies after 13 months at most and document retention for CRM records. Provide a clear path for visitors to withdraw consent, exercise access and erasure rights, and opt out of email communications.

GDPR consent category

Marketing

Websites using SharpSpring (Constant Contact Lead Gen and CRM) must obtain user consent under GDPR regulations.

Legal basisArt. 6(1)(a) GDPR (consent) for marketing automation tracking and profiling cookies, in combination with Art. 5(3) ePrivacy Directive (and national transpositions such as TTDSG in Germany or article 82 Loi Informatique et Libertés in France). Art. 6(1)(f) GDPR (legitimate interest) may apply only to strictly aggregated security logs.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, TTDSG, LOPDGDD, CNIL guidelines on trackers, EDPB Guidelines 03/2022 on consent, Schrems II ruling, EU US Data Privacy Framework, Standard Contractual Clauses

DPIA considerations

A DPIA is recommended because SharpSpring combines behavioural tracking, lead scoring and large scale email automation with US hosting. Document the consent mechanism, the data processing agreement with Constant Contact, international transfers and data minimisation measures.

Sample consent text

We use SharpSpring (Constant Contact Lead Gen and CRM) to measure your browsing, attribute your enquiries and automate sales follow ups. SharpSpring sets tracking cookies and transfers data to the United States. By clicking Accept, you authorise these operations. You can withdraw your consent at any time.

Technical details

Tracking methodcookies, JavaScript tracking pixel, form capture and IP logging
Server locationUnited States (Constant Contact, Inc., Massachusetts and AWS US regions)
Data transferred outside the EUPersonal data including visitor identifiers, email addresses, browsing activity and form submissions is transferred from the EU to the United States where Constant Contact, Inc. (parent company of SharpSpring, now Constant Contact Lead Gen and CRM) operates its production infrastructure. Transfers rely on the EU US Data Privacy Framework certification combined with Standard Contractual Clauses and supplementary technical measures.

Third-party domains contacted

sharpspring.commarketingautomation.serviceshsforms.sharpspring.comapp.sharpspring.comkoi.comapp.sharpspring.comkoi-3QNHL3VG3O.marketingautomation.servicessharpspringmail.comconstantcontact.com

Cookies placed

NameTypeDurationPurpose
__ssHTTP10 yearsSharpSpring anonymous tracker identifier used to link visits, sessions and form submissions to a persistent profile.
__ssfirst_party1 yearPersistent SharpSpring visitor identifier used to recognise returning users and link sessions to a lead profile.
__ss_tkfirst_party1 yearTracking token used to associate page views and form submissions with a SharpSpring contact record.
__ss_tkHTTPSessionSharpSpring session token used for in session correlation of events.
koitkHTTP1 yearIdentifier set by the SharpSpring Koi tracking subdomain to support cross subdomain attribution.
__ss_referrerfirst_partySessionStores the original referrer URL of the visitor for marketing attribution within SharpSpring.
_pk_idHTTP13 monthsStores a hashed prospect identifier when the user has been recognised via a previous form submission.
_ss_okafirst_party1 yearStores attribution and source information used by the SharpSpring campaign tracking engine.
_ss_ubfirst_party1 yearBehavioural identifier used by SharpSpring for visitor scoring and segmentation.
hubspotutkthird_party6 monthsSet when SharpSpring forms are embedded via the HubSpot derived hsforms endpoint to identify visitors.

SharpSpring (Constant Contact Lead Gen and CRM) places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does SharpSpring set on my website?

SharpSpring deposits several first party cookies including __ss, __ss_tk, __ss_referrer, _ss_oka and _ss_ub. They are persistent visitor identifiers used to track behaviour across sessions and to link anonymous activity to a known contact once a form has been submitted.

What cookies does SharpSpring set?

SharpSpring sets first party cookies including __ss (anonymous tracker identifier, up to 10 years), __ss_tk (session token), koitk (Koi subdomain tracker, 1 year) and may store a hashed prospect identifier. It also calls Koi tracking subdomains to record events.

Is user consent required before loading SharpSpring?

Yes. SharpSpring deposits non essential cookies and performs profiling, so prior, freely given, specific, informed and unambiguous consent is required under Art. 5(3) of the ePrivacy Directive and Art. 6(1)(a) GDPR. The script must remain blocked until the user accepts.

Does SharpSpring require user consent?

Yes. SharpSpring loads behavioural tracking and persistent cookies, so under Article 5(3) of the ePrivacy Directive the loader must wait for an explicit opt in. EU regulators treat marketing automation pixels as non strictly necessary.

What is the legal basis for processing data with SharpSpring?

The primary legal basis is consent under Art. 6(1)(a) GDPR for marketing tracking and profiling. Once the user becomes a customer, contractual necessity under Art. 6(1)(b) GDPR can support transactional emails, while legitimate interest under Art. 6(1)(f) only covers narrow technical logs.

What is the legal basis for processing under SharpSpring?

Consent (Art. 6(1)(a) GDPR) is required for the tracking pixel and cookies. Legitimate interest (Art. 6(1)(f) GDPR) can support internal back office lead management once consent is collected and a balancing test is documented.

Does SharpSpring transfer my data to the United States?

Yes. SharpSpring is operated by Constant Contact, Inc. in the United States, and visitor profiles, IP addresses and form submissions are processed on US infrastructure. Transfers rely on the EU US Data Privacy Framework and Standard Contractual Clauses with supplementary measures.

Does SharpSpring transfer data outside the EU (especially to the US)?

Yes. SharpSpring runs on US infrastructure operated by Constant Contact. Use Standard Contractual Clauses under Article 46(2)(c) GDPR and rely on the EU US Data Privacy Framework once the entity is certified. Perform a transfer impact assessment.

Do I need to run a DPIA for SharpSpring?

A DPIA is strongly recommended. The combination of persistent identifiers, profiling, lead scoring and international transfers triggers Art. 35(3)(a) GDPR criteria. The DPIA should evaluate Schrems II risks, retention, automated decisioning and consent quality.

Do I need a DPIA for SharpSpring?

Yes, because SharpSpring combines large scale behavioural tracking with lead scoring and email automation across US infrastructure. Document the data flows, the actors, transfers and safeguards.

How do I implement SharpSpring compliantly in the EU?

Block the script by default, integrate it with a Consent Management Platform, fire it only after explicit opt in, sign a Data Processing Agreement with Constant Contact, configure retention inside SharpSpring and disclose the US transfer in your privacy policy.

How do I implement SharpSpring GDPR compliantly?

Block the tracker by default, load it after marketing consent, sign the Constant Contact DPA, log the consent record alongside the lead, expire cookies after 13 months at most, document retention and offer a clear consent withdrawal and rights exercise path.

What are alternatives to SharpSpring?

For EU friendly marketing automation consider Brevo (France), Mailerlite, ActiveCampaign (with SCC), Plezi (France) for B2B, or HubSpot Starter combined with a CMP that controls tracker loading.

Are there EU based alternatives to SharpSpring?

Yes. Brevo (France), Plezi (France), Webmecanik (France) and Salesmanago (Poland) provide marketing automation hosted in the European Union, which reduces Schrems II exposure compared with US based platforms.

How do I update my cookie policy for SharpSpring?

List each SharpSpring cookie (__ss, __ss_tk, __ss_referrer, _ss_oka, _ss_ub) with purpose, type and duration, mention Constant Contact, Inc. as recipient, disclose the US transfer, and provide a working link to withdraw consent through your CMP.

How do I update my cookie policy to include SharpSpring?

List the controller, the processor (Constant Contact), the purposes (marketing tracking, automation), the cookies, the koi.com sub processor domains, the US transfers and their legal basis, and the rights and withdrawal mechanism.