Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Wisepops is an on site marketing tool that displays pop ups, bars, and embeds and tracks how often they are shown and how visitors convert. A JavaScript script sets first party cookies to remember which campaigns a visitor has seen and to count visits. Wisepops hosts data in the European Union, which is favourable for transfers. The cookies are not strictly necessary, however, so prior consent is still required under the GDPR and the ePrivacy Directive.
Wisepops is an on site marketing and engagement tool that displays pop ups, notification bars, and embedded content on a website. A JavaScript script loads on each page, decides which campaign to show based on rules such as visit count, time on site, and behaviour, and measures impressions and conversions. Marketers use it to grow newsletter lists, announce promotions, and guide visitors towards key actions.
The script sets first party cookies including wisepops, which stores which pop ups have already been shown for about one year, wisepops-session, a session cookie, and wisepops-visits, which counts how many times the visitor has come to the site. Wisepops also processes IP addresses, device and browser information, page views, and any data entered into a form, such as an email address, which constitutes personal data under the GDPR.
Because these cookies are read from and written to the visitor terminal to support marketing rather than a strictly necessary function, Article 5(3) of the ePrivacy Directive requires prior consent even though Wisepops keeps data in the European Union. The display tracking and the collection of identifiable form data also qualify as personal data processing under the GDPR, so a lawful basis, a transparent privacy notice, and a record of processing activities are required, with Wisepops acting as a processor under a data processing agreement.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The Wisepops script and its cookies must not load before the visitor has actively accepted the marketing category in your consent banner. Pre ticked boxes, implied consent from continued browsing, and cookie walls do not meet the GDPR standard. Where a pop up captures an email address, the sign up must be a clear, affirmative opt in, and the consent you collect must be freely given, specific, informed, and as easy to withdraw as to give.
Wisepops hosts data in the European Union, so there is no routine transfer to a third country, which removes one of the main compliance burdens. You still need to sign the Wisepops data processing agreement, gate the script behind your consent management platform, use affirmative opt in on pop up forms, list the Wisepops cookies and their durations in your cookie policy, and set retention so that visitor and lead data is not kept longer than necessary.
Websites using Wisepops must obtain user consent under GDPR regulations.
DPIA considerations
Wisepops tracks which pop ups have been shown and counts visits using cookies that last about one year, and it hosts data in the European Union, so there is no routine third country transfer. A DPIA should still assess the scale of display tracking, the linkage with identifiable form submissions, and retention periods, together with mitigations such as consent gating, affirmative opt in, data minimisation, and shortened retention, even though the EU hosting lowers the overall risk.
Sample consent text
We use Wisepops to decide when to show you relevant messages and sign up forms and to avoid repeating ones you have already seen. Wisepops places cookies on your device to remember which pop ups you have viewed and to count your visits. These cookies load only after you accept the marketing category, and the data is hosted in the European Union. You can withdraw your consent at any time through our cookie settings.
Third-party domains contacted
wisepops.comapp.wisepops.netloader.wisepops.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| wisepops | marketing | 1 year | Stores which Wisepops pop ups and campaigns have already been shown to the visitor so they are displayed at the configured frequency rather than on every visit. |
| wisepops-session | marketing | Session | Session cookie used to manage the current browsing session and to apply session based campaign display rules. |
| wisepops-visits | marketing | 1 year | Counts how many times the visitor has come to the site so that visit based targeting rules can decide when to show a campaign. |
Wisepops places tracking cookies for advertising — comply with GDPR using FlowConsent.
Wisepops sets first party cookies including wisepops, which stores which pop ups have already been shown for about one year, wisepops-session, a session cookie, and wisepops-visits, which counts how many times the visitor has come to the site. Together they control display frequency and targeting rules.
Yes. Even though Wisepops keeps data in the European Union, its cookies are not strictly necessary, so under Article 5(3) of the ePrivacy Directive and the GDPR you must obtain prior, opt in consent before the script loads. Where a pop up captures an email address, the sign up must also be a clear, affirmative opt in.
The storage and reading of cookies relies on consent under the ePrivacy Directive, and the display tracking and form data processing rely on consent under Article 6(1)(a) of the GDPR. Legitimate interest is generally not available because consent is already required to place the cookies.
No. Wisepops is based in France and hosts data within the European Union, so there is no routine transfer to a third country. This favourable data residency removes one of the main compliance burdens, although consent is still required for the cookies.
A full DPIA is not always mandatory, but a short assessment is recommended because Wisepops tracks display and visit behaviour and can link it to identifiable email sign ups. The EU hosting lowers the risk, so document the purposes, data categories, retention, and safeguards, and reassess if you enable advanced behavioural targeting.
Load the Wisepops script only after the visitor accepts the marketing category in your consent management platform, and keep the cookies blocked until then. Use affirmative opt in on pop up forms, sign the data processing agreement, set sensible retention, and document the cookies in your cookie policy.
Other pop up and on site marketing tools include Sleeknote, Poptin, and OptinMonster, though some of these host data in the United States. Wisepops is itself often chosen as a privacy friendly option because of its European data residency, so the right choice depends on your feature and data location needs.
List each Wisepops cookie, its purpose, and its duration, name Wisepops as a recipient, and note that data is hosted in the European Union. Keep the entries in sync with a regular cookie scan so that new or renamed Wisepops cookies are reflected accurately.