FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Analytics
  4. Exponea

Exponea

AnalyticsWebsite

Related services

34SP.com

34SP.com is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 34SP.com supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 34SP.com enables informed decisions that improve experience and drive results.

Analytics
5

51.LA

51.LA is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 51.LA supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 51.LA enables informed decisions that improve experience and drive results.

Analytics

52Degrees

52Degrees is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. 52Degrees offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, 52Degrees empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

a3 Lazy Load

a3 Lazy Load is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, a3 Lazy Load delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Analytics
A

Able CDP

Able CDP is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Able CDP supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Able CDP enables informed decisions that improve experience and drive results.

Analytics
A

Abralytics

Abralytics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Abralytics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Abralytics empowers organizations to optimize strategy and maximize return on investment.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Exponea do?

Customer data platform and marketing automation suite, now branded Bloomreach Engagement. Tracks visitor events, builds unified profiles and runs personalisation, email, SMS and push campaigns. Heavy tracking with EU and US hosting.

What is Exponea

Exponea was a Slovak customer data platform launched in 2015. It was acquired by Bloomreach in 2021 and rebranded as Bloomreach Engagement. The platform combines a customer data platform, web and mobile analytics, marketing automation, email and SMS sending, in app messaging, web personalisation and predictive scoring in a single product. It serves mainly retail, fashion, financial services and travel customers in Europe and North America.

What data and cookies Exponea collects

The Exponea JavaScript SDK sets a long lived first party cookie (__exponea_etc__) that stores the anonymous visitor identifier and a per session cookie (__exponea_time2__) for timing measurements. Every page view, click, scroll, form interaction, product view, cart event and purchase is sent to the Exponea API. The SDK can also collect device data (browser, OS, screen, language, rough geolocation from IP) and merge anonymous activity with the customer profile once the visitor logs in or provides an email. Server side events imported from a CRM or an e commerce backend are linked to the same profile.

GDPR and ePrivacy implications

Exponea sets non essential cookies and performs cross device profiling, so Article 5(3) of the ePrivacy Directive requires a prior informed opt in before the SDK loads. The downstream processing of behavioural data and the profiling under Articles 6(1)(a) and 22 GDPR require consent for marketing personalisation and impose transparency, opt out and human intervention rights. Regulators such as the French CNIL, the Dutch Autoriteit Persoonsgegevens and the Italian Garante have sanctioned CDP deployments that loaded scripts before consent or relied on legitimate interest for marketing.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements and user controls

The Exponea SDK must be gated behind a cookie banner under an analytics and a marketing category. Bloomreach provides a consent management framework that lets you map purposes (functional, analytics, personalisation, marketing automation) and feed the SDK with the chosen state, so events can either be stored anonymously or attached to the full profile. Visitors must be able to refuse as easily as accept, withdraw consent, and ask for access, rectification, deletion and portability through the Bloomreach customer data centre.

Data transfers and hosting

Bloomreach Engagement runs on AWS with primary regions in Frankfurt, Dublin and Virginia. Customers choose where their production data is stored, but support, R&D and certain administrative systems are operated from Slovakia, the Netherlands and the United States. Transfers to the US rely on the EU US Data Privacy Framework and on standard contractual clauses; supplementary measures include encryption in transit, pseudonymisation of cookie identifiers and limited retention of raw events.

Practical compliance steps

Sign the Bloomreach data processing addendum and the SCCs, choose the EU region where possible, list Exponea in your records of processing as a processor with sub processors disclosed, deploy a CMP that signals consent purposes to the SDK, configure the consent free anonymous mode for visitors who refuse, document the retention policies for events and profiles, run a DPIA before adding predictive models or audience synchronisation with advertising platforms, and review the deployment every twelve months.

GDPR consent category

Analytics

Websites using Exponea must obtain user consent under GDPR regulations.

Legal basisConsent (Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive) for analytics cookies, profiling, marketing automation and personalisation. Legitimate interest (Article 6(1)(f) GDPR) may apply to internal analytics on aggregated data only.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), TTDSG in Germany, French Data Protection Act, UK GDPR and PECR, plus sector rules for financial services and telecom CDPs.

DPIA considerations

A DPIA under Article 35 GDPR is strongly recommended. Exponea builds unified customer profiles from web, mobile and CRM data, enriches them with predictive scoring and triggers automated marketing actions. The scale, the profiling and the systematic monitoring of visitors qualify as high risk. Document the categories of identifiers and events ingested, the inferred attributes and predictive models, the retention rules, the recipients of synchronised audiences and the safeguards for transfers to the United States.

Sample consent text

We use Exponea (now Bloomreach Engagement) to recognise you across our website, app and emails and to personalise our communications. This sets analytics and marketing cookies and shares your interactions with Bloomreach in the European Union and the United States. We need your consent before activating these cookies. You can accept, refuse or withdraw your consent at any time.

Technical details

Tracking methodJavaScript SDK with first party and third party cookies, server side events API
Server locationEuropean Union (Frankfurt, Dublin) and United States (Virginia), customer chosen region
Data transferred outside the EUYes. Exponea (now Bloomreach Engagement) runs on AWS in the EU and the US. Customers select a primary region but support, R&D and some backups may involve transfers to the United States and to Slovakia and the Netherlands. Transfers rely on the EU US Data Privacy Framework and on standard contractual clauses.

Third-party domains contacted

exponea.combloomreach.cominfinario.comexponea.io

Cookies placed

NameTypeDurationPurpose
__exponea_etc__first party analytics3 yearsLong lived first party identifier used by the Exponea SDK to recognise the visitor across sessions and link events to the customer profile.
__exponea_time2__first party sessionSessionPer session cookie used by the Exponea SDK to measure event timings and synchronise the device clock with the server.
__exponea_consent__first party preference13 monthsOptional consent state cookie storing the visitor cookie banner choices for the Exponea SDK (analytics, personalisation, marketing).
xnpe_*third party (web push)13 monthsWeb push notification cookie set when the visitor subscribes to push notifications via the Exponea web push channel.
ba_idfirst party marketing13 monthsIdentifier used to link advertising audiences synchronised from Exponea with retargeting platforms.

Exponea collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

Which cookies does Exponea set?

The Exponea JavaScript SDK sets a long lived first party cookie (__exponea_etc__) that stores the anonymous visitor identifier, a per session cookie (__exponea_time2__) used for timing measurements, and an optional consent state cookie (__exponea_consent__) that remembers the visitor choices. Server side events imported through the API do not add browser cookies but extend the same profile.

Is user consent required to load Exponea?

Yes. The SDK sets non essential cookies and starts collecting behavioural data as soon as it loads. Article 5(3) of the ePrivacy Directive requires a prior informed opt in. The SDK must be blocked by default in your tag manager or CMP and triggered only after acceptance in the analytics and marketing categories of the banner.

What is the legal basis for processing?

Consent (Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive) for the cookies, the profiling and the marketing personalisation. Legitimate interest (Article 6(1)(f) GDPR) may cover purely aggregated internal analytics, but is not accepted by EU regulators for marketing automation or for cross channel personalisation.

Does Exponea transfer data to the United States?

Yes. Bloomreach Engagement operates from EU regions (Frankfurt, Dublin) and US regions (Virginia), and support and R&D teams are based in Slovakia, the Netherlands and the United States. Transfers to the US rely on the EU US Data Privacy Framework and on standard contractual clauses, supplemented by encryption in transit, pseudonymisation and limited retention.

Do I need a DPIA for Exponea?

Yes, in practice. The scale of data collection, the cross device profiling, the predictive scoring and the systematic monitoring fall squarely within the Article 35 GDPR criteria. A DPIA must document the categories of data, the inferred attributes, the retention rules, the recipients of synchronised audiences and the safeguards for transfers to the US.

How do I implement Exponea compliantly?

Sign the Bloomreach DPA and SCCs, choose the EU region, deploy a CMP that signals consent purposes to the SDK, configure an anonymous mode for visitors who refuse, restrict access to the back office with strong authentication, document retention rules for events and profiles, run the DPIA before activating predictive models or advertising synchronisation and review every twelve months.

What alternatives exist if Exponea does not fit?

Other CDPs and marketing automation platforms include Tealium AudienceStream, mParticle, Twilio Segment, Salesforce Data Cloud, RudderStack, Adobe Real Time CDP and Klaviyo. EU based alternatives include Commanders Act and Piwik PRO CDP. Each option still requires a DPA, a consent banner and a transfer assessment.

How should I update my cookie policy for Exponea?

List Exponea (Bloomreach Engagement) as a processor with the cookies it sets (__exponea_etc__, __exponea_time2__, optional consent cookie), their purpose, duration and category. Mention the hosting region and the EU US Data Privacy Framework. Link to the Bloomreach privacy policy and to the preference centre that lets visitors exercise their rights. Review the entry every twelve months.