Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Jirafe was an ecommerce analytics platform that measured shopper behaviour, conversion, and cart abandonment for stores built on systems such as Magento and Demandware. It loaded a JavaScript tag that set analytics cookies to identify visitors and sessions. Jirafe was acquired by SAP Hybris around 2015 and the standalone product was subsequently discontinued. If a site still loads a legacy Jirafe tag, it should be audited and most likely removed, and while present it requires consent under the GDPR and the ePrivacy Directive.
Jirafe was a dedicated ecommerce analytics platform aimed at online retailers. It collected and visualised shopper behaviour, traffic, conversion funnels, and cart abandonment, and was commonly used alongside commerce systems such as Magento and Demandware. The product was acquired by SAP Hybris around 2015, and the standalone Jirafe service was subsequently discontinued. As a result, a live Jirafe deployment is uncommon today, and any reference to it usually points to a legacy tag left in a theme or tag manager.
As an analytics tool, Jirafe loaded a JavaScript tag that set cookies to recognise returning visitors and to group activity into sessions. Typical Jirafe analytics cookies included a visitor identifier cookie with a lifetime of roughly one to two years and a session cookie. Alongside the cookies it would process IP addresses, pages and products viewed, and ecommerce events such as add to cart and purchase. Because product documentation is no longer maintained, exact cookie names and durations should be confirmed with a live cookie scan rather than assumed.
Where a Jirafe tag is still present, the cookies are read from and written to the visitor terminal for analytics rather than strictly necessary purposes, so Article 5(3) of the ePrivacy Directive requires prior consent. The visitor identifier and behavioural data are personal data under the GDPR, which means a lawful basis, transparency, and a record of processing activities are required. A particular concern is that an unmaintained legacy tag may continue to set cookies and possibly send data without any current contract or oversight.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
As an analytics technology, Jirafe is not strictly necessary, so it must not load before the visitor has actively accepted the analytics or statistics category. Pre ticked boxes and implied consent do not meet the GDPR standard. In practice, however, the more important step for most sites is not to fine tune consent for Jirafe but to confirm whether the tag is still firing at all, because a discontinued service that keeps loading is a liability rather than a benefit.
Historically Jirafe processed data on infrastructure in the United States, so any surviving transfer should be assessed under the Standard Contractual Clauses. The recommended action is to audit your site and tag manager for any Jirafe tag or domain, and to remove it unless you can demonstrate an active, contracted purpose. While it remains, gate it behind your consent management platform, document the cookies in your cookie policy, and verify the exact cookies and endpoints with a scan because the original documentation is no longer reliable.
Websites using Jirafe must obtain user consent under GDPR regulations.
DPIA considerations
Jirafe was an ecommerce analytics platform that tracked shopper behaviour and cart abandonment using a visitor identifier cookie and session cookies, and it was discontinued after the SAP Hybris acquisition. The main DPIA concern is a legacy tag continuing to set cookies and potentially transfer data without any current contract, oversight, or maintained documentation. Assess whether the tag still fires, the cookies and data it sets, the lack of a controller relationship, and any residual transfer, with the primary mitigation being removal of the tag.
Sample consent text
This site previously used Jirafe to analyse how shoppers browse and buy. Jirafe placed analytics cookies on your device to recognise your browser and group your activity into sessions. These cookies load only after you accept the analytics category. If you have reached this notice, please be aware that Jirafe is a discontinued service and any remaining tag is in the process of being reviewed and removed.
Third-party domains contacted
cdn.jirafe.comapi.jirafe.comjirafe.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| jirafe | analytics | About 1 to 2 years (typical, verify with a scan) | Representative Jirafe visitor identifier cookie used to recognise returning shoppers and attribute behaviour over time. Because the product is discontinued, treat this as a typical example and confirm the exact name and duration with a live cookie scan. |
| __jirafe | analytics | Session (typical, verify with a scan) | Representative Jirafe session cookie used to group a shopper's activity into a single visit. As documentation is no longer maintained, verify whether this cookie is still set on your site rather than assuming its presence. |
| jirafe_ec | analytics | Session (typical, verify with a scan) | Representative ecommerce event cookie associated with Jirafe used to support measurement of actions such as product views and cart activity. Confirm with a cookie scan because the original specification is no longer authoritative. |
Jirafe collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Jirafe typically set analytics cookies such as a visitor identifier cookie lasting about one to two years and a session cookie. Because the product is discontinued and its documentation is no longer maintained, treat these names as representative and confirm the exact cookies on your site with a live cookie scan.
Yes, while any Jirafe tag is present. Its analytics cookies are not strictly necessary, so Article 5(3) of the ePrivacy Directive and the GDPR require prior, opt in consent before the tag loads. In most cases, however, the better answer is to remove the tag because the service is discontinued.
For any surviving Jirafe tag the basis is consent under Article 6(1)(a) of the GDPR and Article 5(3) of the ePrivacy Directive, as with other analytics. Legitimate interest is not appropriate because the cookies require consent and there is unlikely to be a current processing agreement with a discontinued service.
Historically Jirafe processed data on infrastructure in the United States, so a legacy tag could still send data there. Any such transfer should be assessed under the Standard Contractual Clauses, but in practice the realistic step is to confirm whether the tag still transmits anything and to remove it.
If a Jirafe tag is still active you should at least document the processing, but the more pressing issue is that a discontinued, unmaintained tag may operate without a controller relationship or oversight. Assess whether it still fires, what it sets and sends, and the residual transfer, with removal as the primary mitigation.
Audit your site, theme, and tag manager for any Jirafe tag, script, or domain. If you cannot demonstrate an active, contracted purpose, remove it. While it remains, gate it behind your consent management platform, document the cookies, and verify the exact behaviour with a cookie scan rather than relying on old documentation.
Since Jirafe is discontinued, you should replace it rather than maintain it. Modern ecommerce analytics options include privacy focused tools such as Matomo, as well as the analytics features built into platforms like Magento, Shopify, or your current commerce system, chosen according to your data residency and consent needs.
If any Jirafe cookies remain, list each one with its purpose and duration and note that the service is being phased out. Once the tag is removed, delete the Jirafe entries from your cookie policy and confirm with a cookie scan that no Jirafe cookies are still being set.