FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Analytics
  4. Caspio

Caspio

AnalyticsWebsite

Related services

34SP.com

34SP.com is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 34SP.com supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 34SP.com enables informed decisions that improve experience and drive results.

Analytics
5

51.LA

51.LA is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 51.LA supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 51.LA enables informed decisions that improve experience and drive results.

Analytics

52Degrees

52Degrees is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. 52Degrees offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, 52Degrees empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

a3 Lazy Load

a3 Lazy Load is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, a3 Lazy Load delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Analytics
A

Able CDP

Able CDP is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Able CDP supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Able CDP enables informed decisions that improve experience and drive results.

Analytics
A

Abralytics

Abralytics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Abralytics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Abralytics empowers organizations to optimize strategy and maximize return on investment.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Caspio do?

US based low code platform whose embedded DataPages set cookies and collect form data, often sensitive, with hosting mainly in the United States.

What Caspio is

Caspio is a United States based low code platform that lets organisations build online databases and applications without writing much code. The core building blocks are DataPages, embeddable components that display data and capture form submissions, and Flex apps that bundle these features into full applications. Site owners typically embed Caspio DataPages into their own websites, where they collect and display information from end users. Because forms frequently gather contact details, account data and sometimes sensitive information, Caspio sits squarely within the scope of data protection law whenever it is used with European visitors.

What data and cookies it collects

Caspio sets cookies that keep authenticated sessions secure and that support the operation of DataPages. Authenticated DataPages and externally deployed Flex apps require third party cookies, so logins and filtered views can break when cross site tracking prevention blocks them. Beyond cookies, the most significant processing happens through the form data that visitors submit, which can include names, email addresses, identifiers and, depending on the application, special category data. The combination of session cookies and rich form submissions means Caspio often processes substantial volumes of personal data on behalf of the site owner.

GDPR and ePrivacy implications

Under Art. 5(3) of the ePrivacy Directive, storing or reading any cookie that is not strictly necessary requires prior consent. Session and security cookies tied to a login the user actively requested can often be treated as essential, but any analytics or convenience cookies need consent. Processing of the personal data inside form submissions must rest on a valid legal basis under Art. 6(1) GDPR, and the site owner remains the controller responsible for transparency and data subject rights. Caspio normally acts as a processor, so a data processing agreement under Art. 28 GDPR is required.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Consent must be obtained before any non essential cookie is set, which means the consent banner should block such cookies until the visitor has actively agreed. Where form data is collected for purposes that go beyond performing a contract, for example marketing follow up, consent for that processing should also be captured clearly and separately. The request must be specific, informed and as easy to withdraw as it is to give. Pre ticked boxes and implied consent do not meet the GDPR standard.

International data transfers

On the standard editions, data submitted through Caspio is processed in AWS datacenters in the United States, which is a third country under the GDPR. Caspio relies on the EU to US Data Privacy Framework and on Standard Contractual Clauses for these transfers, and a transfer impact assessment should confirm that the safeguards are adequate. Organisations that want to avoid a third country transfer entirely can use the EU Compliance Edition, which keeps data in AWS datacenters in Ireland and Germany. Choosing the EU edition is the cleanest way to keep European personal data within the EEA.

Practical compliance steps

Start by mapping every DataPage, the data it collects and the cookies it sets, then sign a data processing agreement with Caspio. Configure a consent banner that blocks non essential cookies until consent is given and document the legal basis for each form. Evaluate whether the EU Compliance Edition is appropriate to remove the US transfer, and if you keep the standard edition record the Data Privacy Framework and Standard Contractual Clauses in your transfer documentation. Finally, update your privacy notice and cookie policy to name Caspio, describe the data flows and explain how visitors can exercise their rights.

GDPR consent category

Analytics

Websites using Caspio must obtain user consent under GDPR regulations.

Legal basisConsent under Art. 6(1)(a) GDPR for non essential cookies, combined with Art. 5(3) ePrivacy Directive for storing or reading cookies. Form data processing typically relies on consent or contract under Art. 6(1)(a) or (b) GDPR depending on the use case.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, EU-US Data Privacy Framework

DPIA considerations

A data protection impact assessment is strongly recommended when Caspio DataPages collect sensitive or special category data, when forms gather data on a large scale, or when default US hosting leads to transfers outside the EEA. The assessment should document the categories of data collected through forms, the cookies set, the legal basis, the transfer mechanism and the residual risk after safeguards. Using the EU Compliance Edition materially lowers the transfer risk and should be considered as a mitigation.

Sample consent text

We use Caspio to power forms and interactive applications on this site. Caspio sets cookies needed to keep your session secure and may process the information you submit on servers located in the United States. By selecting Accept you consent to these cookies and to this transfer of your data.

Technical details

Tracking methodEmbedded DataPages and Flex apps that set session and authentication cookies and collect form submissions, often including sensitive personal data
Server locationUnited States (AWS), with an optional EU Compliance Edition hosted in Ireland and Germany
Data transferred outside the EUOn the standard editions, personal data entered into DataPages and Flex apps is processed in AWS datacenters in the United States. Caspio relies on the EU to US Data Privacy Framework and Standard Contractual Clauses for these transfers. Customers needing EU data residency can use the EU Compliance Edition, which keeps data in Ireland and Germany and avoids a third country transfer.

Third-party domains contacted

caspio.comcaspio.appbridge.caspio.comc1.caspio.com

Cookies placed

NameTypeDurationPurpose
cbAppSessionthird partysessionMaintains the authenticated user session for DataPages and apps, expiring when the browser session ends
cb_tokenthird partysessionCarries the authentication token that secures access to authenticated DataPages and Flex apps
ASP.NET_SessionIdthird partysessionStandard server session identifier used by the Caspio platform to keep state during a visit
csrf_tokenfirst partysessionProtects forms and DataPage submissions against cross site request forgery

Caspio collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

What cookies does Caspio set?

Caspio sets cookies that keep authenticated user sessions secure and that support the operation of embedded DataPages. Authenticated DataPages and externally deployed Flex apps rely on third party cookies, which is why logins and filtered views can fail when cross site tracking prevention blocks them. Flex apps hosted on the caspio.app domain are designed not to require third party cookies.

Is consent required to use Caspio?

Yes, for any cookie that is not strictly necessary. Session and security cookies tied to a login the user actively requested can often be treated as essential, but analytics or convenience cookies require prior consent under Art. 5(3) ePrivacy. Where form data is used for purposes beyond a contract, such as marketing, consent for that processing is also needed.

What is the legal basis for processing?

Setting non essential cookies relies on consent under Art. 6(1)(a) GDPR together with Art. 5(3) ePrivacy. Processing the personal data in form submissions usually rests on consent under Art. 6(1)(a) or on the performance of a contract under Art. 6(1)(b), depending on the purpose. The site owner is the controller and Caspio is normally the processor under an Art. 28 data processing agreement.

Does Caspio transfer data to the US?

On the standard editions, yes. Data submitted through Caspio is processed in AWS datacenters in the United States, a third country under the GDPR. Caspio relies on the EU to US Data Privacy Framework and Standard Contractual Clauses, and the EU Compliance Edition keeps data in Ireland and Germany to avoid the transfer entirely.

Is a DPIA needed for Caspio?

A data protection impact assessment is strongly advised when DataPages collect sensitive or special category data, when forms gather data at scale, or when default US hosting creates a transfer outside the EEA. The assessment should record the data collected, the cookies set, the legal basis, the transfer mechanism and the residual risk. Using the EU Compliance Edition is a meaningful mitigation that lowers the assessed risk.

How do I implement Caspio compliantly?

Map every DataPage and the data it handles, sign a data processing agreement with Caspio, and configure a consent banner that blocks non essential cookies until consent is given. Decide whether the EU Compliance Edition is appropriate to remove the US transfer, and document your transfer mechanism if you keep the standard edition. Then update your privacy notice and cookie policy to reflect these flows.

Are there alternatives to Caspio?

Alternatives include other low code and database platforms such as Knack, Zoho Creator and Microsoft Power Apps, as well as EU hosted form and database tools for stricter data residency. The right choice depends on whether you need US features or strict EEA hosting. For Caspio itself, the EU Compliance Edition is the privacy friendlier option within the same product.

How do I update my cookie policy for Caspio?

List the Caspio cookies, naming the session and security cookies and noting that authenticated DataPages use third party cookies, and explain their purpose and duration. State that form data may be processed in the United States under the Data Privacy Framework and Standard Contractual Clauses, unless you use the EU Compliance Edition. Keep the policy aligned with what your consent banner actually blocks and allows.