Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Insider is a cross channel marketing personalisation and customer experience platform that tracks visitor behaviour across web, app, email and push to build unified profiles and deliver tailored experiences. Its first party Insider Tag (ins.js) sets cookies and uses browser storage to identify visitors and power AI driven segmentation. Because it performs extensive behavioural profiling, it requires prior consent under GDPR and the ePrivacy Directive. A cookieless tag integration is available for visitors who decline tracking.
Insider is a cross channel marketing personalisation and customer experience platform used by online businesses to recognise visitors and tailor content across websites, mobile apps, email, SMS and push. It collects behavioural signals through a first party JavaScript tag known as the Insider Tag, then unifies them into a single customer profile. These profiles feed AI driven segmentation, product recommendations and automated campaigns. Marketing and growth teams rely on it to increase conversion and retention. Because it observes and predicts individual behaviour at scale, it processes large volumes of personal data. This places it firmly within the scope of European data protection and ePrivacy rules.
The Insider Tag sets first party cookies and uses localStorage and sessionStorage to store a unique visitor identifier and session information. This identifier links page views, clicks, searches, product interactions and conversions to build a persistent behavioural profile. The platform also ingests attributes you send, such as email, purchase history and custom events. For web push it registers a service worker and stores a subscriber identifier and permission state. Identifiers commonly persist for up to a year, while session values are shorter lived. Together these data points allow Insider to track returning visitors and personalise their experience.
Under the ePrivacy Directive, storing or reading cookies and similar identifiers that are not strictly necessary requires prior consent. The behavioural profiles Insider builds are personal data under the GDPR, and combining them across channels amounts to profiling. Where personalisation produces significant effects, Article 22 on automated decision making may also apply. Controllers must therefore have a valid legal basis, provide transparent information and honour data subject rights. Supervisory authorities such as the CNIL have made clear that tracking for marketing cannot rely on legitimate interest alone. Insider should never load before consent is captured.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Valid consent must be freely given, specific, informed and unambiguous, and it must be as easy to withdraw as to give. In practice the Insider Tag should be gated behind a consent management platform so that it fires only after the visitor accepts marketing or personalisation cookies. The platform supports a cookie free integration that can serve campaigns without setting tracking cookies for those who decline. Web push requires its own clear opt in that is separate from the browser permission prompt. You should record proof of consent and pass signals to Insider so it respects the visitor choice. Regularly test that no identifiers are written before acceptance.
Insider operates global cloud infrastructure and personal data may be processed outside the European Economic Area, including in the United States. Transfers to third countries require an appropriate safeguard under Chapter V of the GDPR, typically Standard Contractual Clauses and, where the importer is certified, the EU US Data Privacy Framework. Controllers should carry out a transfer impact assessment and apply supplementary measures such as encryption and strict access controls. Enterprise customers may be able to request EU based hosting to keep data within the region. Document the locations involved and disclose them in your privacy notice. Review the data processing agreement and its list of sub processors carefully.
Start by mapping every data point Insider collects and documenting the purpose and retention for each. Gate the Insider Tag behind your consent management platform and verify with browser tools that nothing loads before consent. Conduct a data protection impact assessment given the scale of profiling involved. Sign the data processing agreement, review sub processors and confirm transfer safeguards for the United States. Update your privacy and cookie policies to name Insider, list its cookies and explain the personalisation and push features. Finally, establish a process to handle access, deletion and objection requests and to refresh consent when purposes change.
Websites using Insider must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is strongly recommended. Insider carries out large scale behavioural tracking, cross channel profiling and AI driven personalisation, which under GDPR Article 35 is likely to result in a high risk to data subjects. The DPIA should map all data flows including transfers to the United States, assess the necessity and proportionality of profiling, document the legal basis and consent mechanism, evaluate automated decision making, and define retention and minimisation measures.
Sample consent text
We use Insider to recognise you across our website and apps, analyse your behaviour and show you personalised content and offers. This involves cookies, browser storage and profiling, and may transfer data outside the EU. These tools load only after you give your consent, which you can withdraw at any time.
Third-party domains contacted
api.useinsider.comuseinsider.cominsrtb.cominspublic.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ins-uic | first party | up to 1 year | Stores the unique Insider visitor identifier used to recognise returning visitors and link behaviour into a persistent profile for personalisation. |
| ins-storage | first party (localStorage) | persistent until cleared | Holds visitor attributes, events and campaign state in browser storage to power personalisation and recommendations. |
| ins-session | first party (sessionStorage) | session | Stores temporary session information for the current visit such as page context and in session behaviour. |
Insider collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The Insider Tag sets first party cookies that store a unique visitor identifier and session data used to build behavioural profiles and personalise content, commonly lasting up to a year. It also uses localStorage and sessionStorage, and for web push it registers a service worker and stores a subscriber identifier and permission state. The exact cookies depend on which Insider products you enable.
Yes. Because Insider performs behavioural tracking, cross channel profiling and personalisation, its cookies and identifiers are not strictly necessary and require prior consent under the ePrivacy Directive. The Insider Tag should only load after the visitor accepts marketing or personalisation cookies through your consent banner. Web push notifications need a separate clear opt in.
The appropriate legal basis is consent under GDPR Article 6(1)(a), because the processing involves extensive profiling and personalisation for marketing purposes. Legitimate interest is generally not sufficient given the scale and intrusiveness of the tracking. You must obtain consent before any tracking begins and keep a record of it.
Yes, it can. Insider runs global cloud infrastructure and personal data may be processed outside the EU, including in the United States. Such transfers rely on Standard Contractual Clauses and, where applicable, the EU US Data Privacy Framework, supported by supplementary measures. Enterprise customers may be able to request EU based hosting.
In most cases yes. The large scale behavioural tracking, profiling and automated personalisation that Insider enables are likely to result in a high risk to individuals, which triggers the requirement for a data protection impact assessment under GDPR Article 35. The DPIA should document data flows, transfers, the legal basis and mitigation measures.
Gate the Insider Tag behind a consent management platform so it only fires after consent, and verify with browser tools that no identifiers are written beforehand. Sign the data processing agreement, confirm transfer safeguards and complete a DPIA. Use the cookieless integration for visitors who decline, and disclose Insider in your privacy and cookie policies.
Alternatives include other personalisation and customer engagement platforms such as Bloomreach, Dynamic Yield, Braze and Emarsys, as well as consent first or cookieless tools. When evaluating options, consider EU data residency, the depth of profiling, transparency of sub processors and the strength of consent controls. The right choice depends on your channels and risk appetite.
List the Insider cookies and browser storage entries with their names, purposes and durations, and explain the cross channel profiling and personalisation they enable. State that data may be transferred to the United States and describe the safeguards. Keep the policy in sync with your consent banner and review it whenever you enable new Insider features.