Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
OneStat is a hosted web analytics service that uses a JavaScript page tag and cookies to track visitors, recording a unique visitor identifier, IP address and navigation behaviour.
OneStat is a hosted web analytics service offered at onestat.com. The operator inserts a small JavaScript page tag into the website, and OneStat then records statistics about visits, such as pages viewed, time on page, referral source and navigation paths. It is a software as a service product, so the data is processed on OneStat own systems rather than on the operator server.
For a European audience OneStat is a classic third party analytics tool: useful for understanding traffic, but reliant on cookies and the processing of visitor data that fall squarely within GDPR and ePrivacy rules.
OneStat sets a unique visitor cookie that identifies each browser by a random number, allowing it to distinguish new and returning visitors. Alongside the cookie it records the IP address, the browser string, the pages visited, the duration of each view and the previous page, building a profile of navigation behaviour.
Although the visitor is identified only by a random number rather than a name, the combination of a persistent identifier with the IP address and behaviour constitutes personal data under the GDPR.
The OneStat analytics cookie is not strictly necessary for the website to function, so it falls under Article 5(3) of the ePrivacy Directive and requires prior consent. The associated processing of the IP address and behaviour needs a legal basis under Article 6 of the GDPR, and the operator must inform visitors clearly and honour their rights.
OneStat acts as a processor on behalf of the website operator, so a data processing agreement is required, and the operator remains the controller responsible for lawfulness and transparency.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because the analytics cookie is non essential, valid prior consent must be collected before the OneStat tag loads and before the cookie is set. The consent must be freely given, specific, informed and unambiguous, and the consent banner must let visitors refuse as easily as they accept, with no tracking taking place until acceptance.
As a hosted service, OneStat receives the analytics data on its own servers. The operator should confirm where OneStat stores and processes the data, and if any of that processing takes place outside the European Economic Area, put in place a valid transfer mechanism such as standard contractual clauses together with a transfer impact assessment.
Load the OneStat tag only after consent, sign a data processing agreement, and confirm the hosting location and transfer safeguards. Describe the analytics cookie and the data collected in your cookie policy and privacy notice, set a proportionate retention period, and consider IP truncation or an EU hosted analytics alternative if you want to minimise risk.
Websites using OneStat must obtain user consent under GDPR regulations.
DPIA considerations
OneStat assigns a unique visitor cookie and records IP addresses and navigation behaviour, which is a regular monitoring of visitors but on a smaller and less intrusive scale than identification or enrichment tools. A full DPIA may not always be mandatory, yet a documented risk assessment is advisable, especially regarding where the provider stores and processes the data.
Sample consent text
With your consent we use OneStat to measure how our website is used. This sets analytics cookies and records information such as your IP address, the pages you view and your browser. You can refuse or withdraw your consent at any time in the cookie settings.
Third-party domains contacted
onestat.comstat.onestat.comonestatfree.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| OneStatUniqueVisitor | Analytics | 2 years | Unique visitor cookie that identifies the browser by a random number so OneStat can distinguish new and returning visitors. Not strictly necessary, so it requires prior consent. |
| OneStatSession | Analytics | 30 minutes | Session cookie used by OneStat to group page views into a single visit and measure session duration. Requires prior consent. |
| OneStatReferrer | Analytics | Session | Stores the referral source for the current visit so OneStat can attribute traffic and campaigns. Requires prior consent. |
| OneStatFirstVisit | Analytics | 2 years | Records the timestamp of the first visit to help OneStat distinguish first time from repeat visitors over time. Requires prior consent. |
OneStat collects user analytics data — you legally need a consent banner. Try FlowConsent free.
OneStat sets analytics cookies, most notably a unique visitor cookie that identifies the browser by a random number, along with session and referral cookies. These cookies are not strictly necessary, so they require prior consent before they are placed.
Yes. The OneStat analytics cookie is non essential, so under Article 5(3) of the ePrivacy Directive prior consent is required before it is set. The tag should not load and no cookie should be placed until the visitor has actively accepted.
Consent under Article 6(1)(a) of the GDPR is the appropriate basis, because the service relies on non essential analytics cookies and processes the IP address and behaviour. This aligns with the consent requirement of Article 5(3) of the ePrivacy Directive.
OneStat is a hosted service, so the analytics data is sent to its own servers. The operator should confirm the hosting location and, if any processing occurs outside the EEA, put a valid transfer mechanism such as standard contractual clauses in place.
A full DPIA is not always mandatory for standard OneStat analytics, since it is less intrusive than identification tools. A documented risk assessment is nonetheless advisable, particularly to confirm where the provider stores and processes the data.
Load the OneStat tag only after consent, sign a data processing agreement, and verify the hosting and transfer safeguards. Describe the analytics cookies in your cookie policy, set a proportionate retention period, and consider IP truncation to reduce the data footprint.
Privacy friendly alternatives include EU hosted analytics such as Matomo and Plausible, which can be configured to avoid third country transfers and, in some cases, to run without cookies. These options often reduce the consent and transfer burden compared with a hosted tool.
List the OneStat unique visitor cookie and any session or referral cookies with their purpose and duration, and state that analytics data is sent to OneStat servers. Review and update the policy whenever the OneStat configuration or the set of cookies changes.