Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Branch is a mobile deep linking, attribution, and measurement platform. It builds links that route people between the web and native apps and measures installs, clicks, and conversions across channels and devices. To attribute these journeys it processes device identifiers, IP addresses, and device characteristics, often through probabilistic fingerprinting. For European websites and apps this makes Branch a marketing technology that requires prior consent.
Branch Metrics provides deep linking and mobile measurement. Its links open the right screen inside a native app when the app is installed and fall back to the web or an app store when it is not. On top of this routing, Branch attributes installs, re engagements, and conversions to the campaign, channel, or partner that produced them, giving marketing teams a unified view across web and mobile.
To match a click on one device or channel with a later install or conversion, Branch processes mobile advertising identifiers such as the Apple IDFA and the Google Advertising ID when they are available, the IP address, and a range of device characteristics including operating system, model, language, and screen attributes. When deterministic identifiers are missing, Branch can combine these signals into a probabilistic fingerprint. It also records the events your application sends, such as opens, purchases, and custom conversions.
On websites that use the Branch Web SDK or Journeys banners, Branch writes values to browser storage and cookies to keep a session consistent and to remember the originating link. These entries are not strictly necessary for the page to function, because they exist to support attribution and marketing measurement rather than the core content the visitor requested.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Device identifiers, IP addresses, and fingerprints are personal data under the GDPR, and reading or writing information on a user device is regulated by the ePrivacy Directive. Because Branch is used for marketing attribution and can build cross device profiles, both frameworks apply. The controller must be able to demonstrate a valid legal basis and must inform users clearly about the processing in its privacy notice.
For attribution and fingerprinting the appropriate legal basis is consent. Consent must be requested before the SDK loads or sets any identifier, it must be freely given, specific, and informed, and it must be as easy to withdraw as to give. A consent management platform should gate the Branch SDK so that it initialises only after the visitor accepts the marketing category.
Branch processes data in the United States, so transfers outside the European Economic Area must be covered by the EU US Data Privacy Framework or by Standard Contractual Clauses, and an EU data residency option can reduce exposure. In practice you should sign a data processing agreement with Branch, document the processing in your records, configure the SDK to defer until consent, set retention limits, and keep your cookie policy and privacy notice aligned with what Branch actually collects.
Websites using Branch must obtain user consent under GDPR regulations.
DPIA considerations
Branch performs cross device and cross channel tracking and can use device fingerprinting for probabilistic attribution, so a data protection impact assessment is strongly recommended. Assess the scale of identifier collection, the combination of web and app data, the retention periods, and the transfers to the United States.
Sample consent text
We use Branch to understand how our links and campaigns lead to app installs and conversions. Branch may read device information and store identifiers for attribution. These technologies run only after you accept marketing cookies.
Third-party domains contacted
api2.branch.iocdn.branch.ioapp.linkbnc.ltCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _branch_session | Marketing | Session | Maintains the Branch attribution session for the current visit so a click can be linked to later actions. |
| _branch_session_first | Marketing | 1 year | Stores the first attribution session so the originating link can be matched to installs and conversions over time. |
| branch_journeys_shown | Marketing | 1 year | Records that a Branch Journeys smart banner has been displayed to avoid showing it repeatedly. |
Branch collects user analytics data — you legally need a consent banner. Try FlowConsent free.
On the web, Branch can store session values in cookies and browser storage to keep attribution consistent and remember the link a visitor arrived from. In mobile apps it reads advertising identifiers and device characteristics. None of these are strictly necessary, so they belong in the marketing category of your consent banner.
Yes. Branch is used for marketing attribution and can rely on device fingerprinting, which requires prior informed consent under the ePrivacy Directive and the GDPR. The SDK should load only after the visitor accepts marketing cookies.
Consent under Article 6(1)(a) of the GDPR is the appropriate basis, because the processing serves marketing measurement rather than a strictly necessary purpose. Legitimate interest is generally not sufficient for cross device attribution that involves fingerprinting.
Yes. Branch Metrics is based in the United States and processes data there by default, so transfers must be covered by the EU US Data Privacy Framework or Standard Contractual Clauses. An EU data residency option is available to keep data within the region.
A data protection impact assessment is recommended because Branch performs systematic cross device tracking and may use fingerprinting. Document the categories of data, the scale, the retention, and the safeguards for international transfers.
Gate the Branch SDK behind your consent management platform so it initialises only after marketing consent, sign a data processing agreement, limit retention, and disable any optional fingerprinting you do not need. Make sure your privacy notice describes the attribution clearly.
Alternatives include AppsFlyer, Adjust, Singular, and Kochava for attribution, as well as the first party measurement offered natively by Apple and Google. Each still processes device data, so the same consent rules apply.
List the Branch cookies and storage entries with their purpose and duration, state that they are used for marketing attribution, name Branch Metrics as the recipient, and mention the United States transfer. Keep the entry in sync whenever you change your Branch configuration.