FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. Spotify pixel

Spotify pixel

Marketing

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Spotify Pixel do?

The Spotify Pixel is the advertising conversion tracking solution of Spotify Ad Services, used by advertisers to measure the impact of audio, video and display campaigns on the Spotify platform. It sets cookies on the advertiser website, captures conversion events, links them to Spotify users, and supports a server side Conversions API. Because the pixel involves cross context behavioural advertising and data transfers to the United States, explicit consent is required under the GDPR and the ePrivacy Directive.

What is the Spotify Pixel

The Spotify Pixel is the conversion measurement and audience building technology of Spotify Ad Services. Advertisers integrate it on their website to attribute conversions (purchases, sign ups, app installs) back to audio, video or display campaigns on Spotify. The pixel is paired with the Spotify Conversions API for server side first party measurement, similar to Meta CAPI or Google Enhanced Conversions. Spotify is incorporated in Sweden but the advertising backend is operated from the United States.

What data does the pixel collect

The pixel collects conversion events, page URLs, referrers, user agents, IP addresses, click identifiers (when arriving from a Spotify ad) and an anonymous Spotify cookie identifier. Advertisers may optionally send first party data through the Conversions API: hashed email addresses, phone numbers and customer identifiers. Spotify matches these signals to logged in Spotify users for cross device attribution and lookalike audience generation.

GDPR and ePrivacy implications

The Spotify Pixel is a third party advertising tracker. Its cookies are not strictly necessary, so they require prior consent under Art. 5(3) of the ePrivacy Directive. The processing of personal data for cross context behavioural advertising must be based on consent under Art. 6(1)(a) and Art. 7 GDPR. The European Data Protection Board has reaffirmed in 2024 and 2025 that legitimate interest cannot justify behavioural advertising.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Configure your Consent Management Platform to block the Spotify Pixel until consent for marketing is granted. The CMP must offer Accept and Reject with equal prominence, granular purposes, and easy withdrawal. When using the Conversions API server side, only send first party data after the user has consented to advertising, and apply hashing in transit as required by the Spotify integration guide.

Data transfers outside the EU

Spotify USA Inc. is certified under the EU US Data Privacy Framework, which provides an adequacy mechanism for transfers between the EU and the United States. Operators must still document a Transfer Impact Assessment, sign Spotify Standard Contractual Clauses and monitor the validity of the DPF following any legal challenge after Schrems II.

Practical compliance steps

Document Spotify Ad Services in your Article 30 register, sign the Spotify Ads Data Processing Addendum, configure your CMP to gate the pixel and the Conversions API, hash first party identifiers before transmission, disclose the US transfer in your privacy notice, and offer an opt out mechanism that propagates a deletion request to Spotify when required.

GDPR consent category

Marketing

Websites using Spotify Pixel must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) is required because the Spotify Pixel sets non essential cookies and processes personal data for cross context behavioural advertising. Storage on a visitor device also triggers Art. 5(3) of the ePrivacy Directive.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, TDDDG, LSSI CE, Swedish Data Protection Act, EU US Data Privacy Framework, Schrems II, IAB TCF 2.2

DPIA considerations

A DPIA is recommended when the Spotify Pixel is used at scale for behavioural advertising, audience targeting or combined with first party CRM data uploaded via the Conversions API. The CJEU Schrems II ruling requires a Transfer Impact Assessment for the US transfer.

Sample consent text

We use the Spotify Pixel, the conversion tracking technology of Spotify Ad Services, to measure the performance of our advertising on Spotify and to build audiences for future campaigns. This involves transferring your personal data to the United States.

Technical details

Tracking methodClient side JavaScript pixel installed on advertiser websites. Captures conversion events (purchase, lead, registration), forwards them to Spotify Ads, links them to a Spotify user via cookies and device identifiers, and supports server side Conversions API for first party data integration.
Server locationUnited States (primary). Spotify is incorporated in Sweden but operates its advertising infrastructure on cloud providers based in the United States, with edge points worldwide.
Data transferred outside the EUPersonal data is transferred to the United States. Spotify Ad Services relies on the EU US Data Privacy Framework for European transfers, supplemented by Standard Contractual Clauses with operators who remain controllers of the data they upload.

Third-party domains contacted

ads.spotify.compixel.spotify.compartner.spotify.com

Cookies placed

NameTypeDurationPurpose
_spotify_idMarketing1 yearSpotify advertising identifier used to link a website visitor with a Spotify user for cross device attribution and lookalike audiences.
_spotify_sessionMarketingSessionTracks the current advertising session, including page views and conversion events captured by the pixel.
_spotify_matchMarketing30 daysStores click identifier when the visitor arrives from a Spotify ad, used for attribution against the Spotify Ads dashboard.

Spotify Pixel places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does the Spotify Pixel set?

The pixel sets first party tracking cookies on the advertiser domain to store an anonymous Spotify identifier, the active advertising session and click identifiers from incoming Spotify ad traffic. These cookies are not strictly necessary and require consent before being set.

Is consent required to use the Spotify Pixel in Europe?

Yes. The pixel is a third party advertising tracker. Art. 5(3) of the ePrivacy Directive requires consent for non essential cookies, and Art. 6 GDPR requires consent for cross context behavioural advertising. Consent must be granular and as easy to withdraw as to grant.

What is the legal basis for processing data through the Spotify Pixel?

Consent (Art. 6(1)(a) GDPR). Legitimate interest cannot justify cross context behavioural advertising per the EDPB Guidelines 8/2020 and 2/2023, and recent decisions against Meta and TikTok have reinforced that position.

Does the Spotify Pixel transfer data to the United States?

Yes. Spotify USA Inc. operates the advertising infrastructure and is certified under the EU US Data Privacy Framework. Standard Contractual Clauses and a Transfer Impact Assessment remain advisable for operators who export EU personal data to Spotify Ads.

Is a DPIA required when integrating the Spotify Pixel?

A DPIA is recommended when the pixel is integrated with first party CRM data through the Conversions API, when used at scale for retargeting, or when combined with other advertising trackers. The combined risk to data subjects often crosses the Art. 35 GDPR threshold.

How do I implement the Spotify Pixel in a GDPR compliant way?

Gate the pixel behind a Consent Management Platform, only fire on consent for marketing, sign the Spotify Ads Data Processing Addendum, hash first party identifiers before sending them through the Conversions API, disclose the US transfer in your privacy notice and offer easy withdrawal of consent.

Are there European alternatives for audio advertising attribution?

Yes. Acast (Sweden), Audion (France), Targetspot (Belgium), Triton Digital (US but with EU partners) and major European broadcasters' digital ad networks offer audio campaign attribution. None replaces Spotify reach, but they reduce exposure to US transfers when EU audience focus is dominant.

How do I update my cookie policy when activating the Spotify Pixel?

Add a Spotify Pixel section listing the cookies (_spotify_id, _spotify_session, _spotify_match), their duration and purpose. Mention Spotify USA Inc. as the processor and the US transfer covered by the EU US DPF. Re trigger the consent banner so existing visitors can review the new vendor.