Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
WebEngage is a marketing automation and customer engagement platform that tracks visitor behaviour across web and mobile apps to build unified profiles and run personalised campaigns including web and app push. Its Web SDK assigns an anonymous unique identifier, sets cookies and uses browser storage to recognise visitors and trigger automated journeys. Because it performs extensive behavioural profiling, it requires prior consent under GDPR and the ePrivacy Directive. EU customer data is typically hosted in the United States, as there is no EU data centre.
WebEngage is a marketing automation and customer engagement platform used by online businesses to track visitors and run personalised campaigns across web, mobile apps, email, SMS, WhatsApp and push. It collects behavioural signals through a first party Web SDK and unifies them into a single customer profile. These profiles drive segmentation, automated journeys and triggered messaging. Marketing and retention teams use it to increase conversion, engagement and loyalty. Because it observes and predicts individual behaviour at scale, it processes large volumes of personal data. This places it firmly within the scope of European data protection and ePrivacy rules.
The Web SDK assigns each visitor an anonymous unique identifier and sets first party cookies, supported by localStorage, to recognise returning visitors. This identifier links page views, clicks, searches, events and conversions into a persistent behavioural profile. The platform also ingests attributes you send, such as email, phone number, purchase history and custom events. For web push it registers a service worker and stores a subscriber identifier and permission state. Identifiers commonly persist for up to a year, while session values are shorter lived. Together these data points allow WebEngage to track returning visitors and personalise messaging across channels.
Under the ePrivacy Directive, storing or reading cookies and similar identifiers that are not strictly necessary requires prior consent. The behavioural profiles WebEngage builds are personal data under the GDPR, and combining them across channels amounts to profiling. Where automated journeys produce significant effects, Article 22 on automated decision making may also apply. Controllers must therefore have a valid legal basis, provide transparent information and honour data subject rights. Supervisory authorities such as the CNIL have made clear that tracking for marketing cannot rely on legitimate interest alone. The Web SDK should never initialise before consent is captured.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Valid consent must be freely given, specific, informed and unambiguous, and it must be as easy to withdraw as to give. In practice the Web SDK should be gated behind a consent management platform so that it loads only after the visitor accepts marketing or personalisation cookies. Web push requires its own clear opt in that is separate from the browser permission prompt. You should record proof of consent and ensure the platform stops tracking when consent is withdrawn. WebEngage provides controls to manage user consent and to handle access and deletion requests. Regularly test that no identifiers are written before acceptance.
WebEngage offers data centres in the United States, India and Saudi Arabia, with the United States as the default and no European Union location. For European customers this means personal data is typically stored and processed in the United States, a third country. Transfers to third countries require an appropriate safeguard under Chapter V of the GDPR, typically Standard Contractual Clauses and, where the importer is certified, the EU US Data Privacy Framework. Controllers should carry out a transfer impact assessment and apply supplementary measures such as encryption and strict access controls. Document the data centre in use and disclose it in your privacy notice. Review the data processing agreement and its list of sub processors carefully.
Start by mapping every data point WebEngage collects and documenting the purpose and retention for each. Gate the Web SDK behind your consent management platform and verify with browser tools that nothing loads before consent. Conduct a data protection impact assessment given the scale of profiling involved. Sign the data processing agreement, review sub processors and confirm transfer safeguards for the United States. Update your privacy and cookie policies to name WebEngage, list its cookies and explain the personalisation and push features. Finally, establish a process to handle access, deletion and objection requests and to refresh consent when purposes change.
Websites using WebEngage must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is strongly recommended. WebEngage carries out large scale behavioural tracking across web and apps, cross channel profiling and automated engagement, which under GDPR Article 35 is likely to result in a high risk to data subjects. The DPIA should map all data flows including storage in the United States, assess the necessity and proportionality of profiling, document the legal basis and consent mechanism, evaluate web and app push, and define retention and minimisation measures.
Sample consent text
We use WebEngage to recognise you across our website and apps, analyse your behaviour and send you personalised messages and push notifications. This involves cookies, browser storage and profiling, and stores data in the United States. These tools load only after you give your consent, which you can withdraw at any time.
Third-party domains contacted
webengage.comssl.widgets.webengage.comc.webengage.comst.dummycdn.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| we_luid | first party | up to 1 year | Stores the anonymous unique visitor identifier (LUID) used to recognise returning visitors and link behaviour into a persistent profile for personalisation and engagement. |
| we_session | first party | session | Tracks the current session to group events and page views within a single visit. |
| we_storage | first party (localStorage) | persistent until cleared | Holds visitor attributes, events and push subscription state in browser storage to support automated journeys and web push. |
WebEngage places tracking cookies for advertising — comply with GDPR using FlowConsent.
The Web SDK assigns an anonymous unique identifier and sets first party cookies, supported by localStorage, to recognise returning visitors and link behaviour into a persistent profile, commonly lasting up to a year. For web push it registers a service worker and stores a subscriber identifier and permission state. The exact cookies depend on which WebEngage features you enable.
Yes. Because WebEngage performs behavioural tracking, cross channel profiling and personalisation, its cookies and identifiers are not strictly necessary and require prior consent under the ePrivacy Directive. The Web SDK should only initialise after the visitor accepts marketing or personalisation cookies through your consent banner. Web push notifications need a separate clear opt in.
The appropriate legal basis is consent under GDPR Article 6(1)(a), because the processing involves extensive profiling and automated engagement for marketing purposes. Legitimate interest is generally not sufficient given the scale and intrusiveness of the tracking. You must obtain consent before any tracking begins and keep a record of it.
Yes, in most cases. WebEngage offers data centres in the United States, India and Saudi Arabia, with the United States as the default and no EU location, so European customer data is typically stored in the United States. Such transfers rely on Standard Contractual Clauses and, where applicable, the EU US Data Privacy Framework, supported by supplementary measures.
In most cases yes. The large scale behavioural tracking, profiling and automated engagement that WebEngage enables are likely to result in a high risk to individuals, which triggers the requirement for a data protection impact assessment under GDPR Article 35. The DPIA should document data flows, US storage, the legal basis and mitigation measures.
Gate the Web SDK behind a consent management platform so it only initialises after consent, and verify with browser tools that no identifiers are written beforehand. Sign the data processing agreement, confirm transfer safeguards for the United States and complete a DPIA. Use a separate opt in for web push and disclose WebEngage in your privacy and cookie policies.
Alternatives include other customer engagement and marketing automation platforms such as Braze, MoEngage, CleverTap, Klaviyo and Emarsys, including some that offer EU data residency. When evaluating options, consider where data is stored, the depth of profiling, transparency of sub processors and the strength of consent controls. The right choice depends on your channels and risk appetite.
List the WebEngage cookies and browser storage entries with their names, purposes and durations, and explain the cross channel profiling and personalisation they enable. State that data is typically stored in the United States and describe the safeguards. Keep the policy in sync with your consent banner and review it whenever you enable new WebEngage features.