Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Truepush is a free web and app push notification service that lets sites and apps re engage users with browser and device notifications. It collects push subscription tokens, browser and device information, and segmentation data to target messages. Because it sets cookies and relies on the browser push opt in, it requires consent under the GDPR and the ePrivacy Directive.
Truepush is a free web and app push notification service that helps websites and applications re engage their users with timely notifications. Site owners add a script that registers visitors as push subscribers and then send campaigns or automated messages from the Truepush dashboard. It supports segmentation so that different groups of subscribers receive different messages.
Truepush collects a push subscription token that identifies the subscriber browser or device, together with browser and device information and segmentation data used to target notifications. It also sets cookies to recognise subscribers and store segmentation attributes. These identifiers and cookies relate to identifiable users and are therefore personal data under the GDPR.
Push notifications involve a double step under European law. First, the ePrivacy Directive requires consent before non essential cookies and the subscription identifier are stored on the device, and second, the browser itself shows a native permission prompt that the user must accept. Both steps must be freely given, so you should not trigger the browser prompt until the visitor has agreed through your own consent layer. The lawful basis for the whole flow is consent.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Use a clear opt in that explains what notifications the user will receive before the native browser prompt appears, and avoid prompting on the first page load without context. Record when and how each subscriber opted in, and make it easy to unsubscribe at any time. Treat the browser permission and your cookie consent as linked, since removing one should effectively end the messaging.
Truepush processes subscriber and device data outside the European Economic Area, including in the United States and India. These transfers rely on Standard Contractual Clauses, and you should confirm that supplementary measures are in place where needed. Document the transfer mechanism in your privacy notice and records of processing so subscribers understand where their data goes.
Gate the Truepush script and the browser prompt behind explicit consent, declare its cookies and the subscription identifier in your cookie policy, and sign a data processing agreement that includes Standard Contractual Clauses. Add Truepush to your records of processing, explain the international transfers in your privacy notice, and give subscribers a simple way to unsubscribe. Review retention so subscription data is not kept longer than needed.
Websites using Truepush must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment should be considered where Truepush is used for large scale push messaging and behavioural segmentation. Consider (1) the collection of push subscription tokens and device information that single out identifiable users; (2) the legal basis, which is consent for both the cookie or identifier and the browser push opt in, and the need to keep these freely given; (3) the segmentation and targeting logic, since profiling subscribers can shape the messages they receive; (4) the international transfers to the United States and India, the reliance on Standard Contractual Clauses, and any supplementary measures required; and (5) data subject rights, retention of subscription data, and how unsubscribe requests and consent withdrawals are handled.
Sample consent text
We would like to send you push notifications and use cookies to manage your subscription. Your data may be processed outside the EEA under appropriate safeguards. Allow to subscribe, or decline to continue without notifications. You can unsubscribe at any time.
Third-party domains contacted
truepush.comcdn.truepush.comapp.truepush.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| truepush_subscriber_id | Functional | 1 year | Stores the push subscriber identifier so the browser or device can be recognised and notifications delivered. |
| truepush_segment | Marketing | 1 year | Holds segmentation attributes used to target push notifications to specific subscriber groups. |
| truepush_analytics | Analytics | 1 year | Measures notification delivery, clicks, and engagement to report on campaign performance. |
| truepush_session | Functional | Session | Maintains the subscriber session and keeps the push opt in flow working during a visit. |
Truepush places tracking cookies for advertising — comply with GDPR using FlowConsent.
Truepush sets cookies to recognise subscribers and store segmentation attributes, and it collects a push subscription token together with browser and device information. The token uniquely identifies the subscriber browser or device so notifications can be delivered. These identifiers are non essential and should be listed in your cookie policy.
Yes. Truepush requires a double step of consent, first for the cookies and subscription identifier under the ePrivacy Directive, and then for the native browser push permission prompt. You should obtain agreement through your own consent layer before triggering the browser prompt, and never enable notifications by default.
The lawful basis is consent under GDPR Article 6(1)(a) and ePrivacy Article 5(3), covering both the cookie or subscription identifier and the browser push opt in. Because there is no realistic legitimate interest alternative for push messaging, consent must be freely given and easy to withdraw. Document this basis in your records of processing.
Yes. Truepush processes subscriber and device data outside the EEA, including in the United States and India, and these transfers rely on Standard Contractual Clauses. You should confirm that supplementary measures are in place where needed and explain the transfers in your privacy notice. Subscribers should be told where their data is processed.
A DPIA should be considered where Truepush is used for large scale messaging and behavioural segmentation, especially given the transfers outside the EEA. Assess the subscription identifiers, the segmentation logic, the international transfers and their safeguards, and how consent and unsubscribe requests are handled. A formal DPIA may be required if the processing is high risk.
Gate the Truepush script and the browser prompt behind explicit consent, and present a clear opt in that explains the notifications before the native prompt appears. Declare the cookies and subscription identifier in your cookie policy, sign a data processing agreement with Standard Contractual Clauses, and add Truepush to your records of processing. Make unsubscribing easy and set sensible retention.
Yes, other web and app push providers such as OneSignal, PushEngage, or Firebase Cloud Messaging offer similar subscription and segmentation features. All of them rely on the browser push opt in and set identifiers, so the same double consent obligations apply. Compare their hosting locations and data transfer practices when choosing.
List the Truepush cookies and the push subscription identifier with their purpose and retention, and explain that notifications require both cookie consent and the browser permission. Disclose that subscriber data may be processed in the United States and India under Standard Contractual Clauses. Describe how users can unsubscribe and withdraw consent.