Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Web analytics, heatmaps and personalisation platform whose JavaScript SDK tracks pageviews, clicks and scrolls with servers in Japan and China.
Ptengine is a web analytics and customer engagement platform that combines pageview and event tracking with heatmaps (clicks, scrolls, attention) and on site personalisation. Originating from Japan and active in China and internationally, it is widely used by ecommerce and content publishers.
The Ptengine JavaScript SDK sets cookies prefixed with _pt and records pageviews, custom events, click coordinates, scroll depth and mouse movement to generate heatmaps and session insights. Data is sent to Ptengine servers hosted in Japan and China.
Ptengine clearly performs non essential analytics and behavioural tracking, requiring prior consent under Article 5(3) of the ePrivacy Directive and Article 6(1)(a) of the GDPR. Transfers to Japan benefit from the EU adequacy decision for private sector data, while transfers to China require Standard Contractual Clauses with strong supplementary measures.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Risks include detailed behavioural profiling through heatmaps, transfers to China where surveillance laws are wide, and possible exposure of form content if not masked. Mitigations include strict consent gating, enabling input masking, disabling session recording, anonymising IPs and signing a data processing agreement with appropriate transfer mechanisms.
Load Ptengine through a consent management platform in the analytics and personalisation categories, only after the corresponding consent. Configure the SDK to mask input fields, exclude pages with sensitive content, set short retention, and document Japan and China transfers in your records of processing.
Websites using Ptengine must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is strongly recommended due to behavioural tracking through heatmaps, the use of personalisation, transfers to Japan and China and potential capture of input content. Document data flows, retention, transfer safeguards and mitigations such as input masking.
Sample consent text
We use Ptengine to understand how visitors use our website and to personalise content. This service stores cookies and transfers data to Japan and China. You can accept or refuse from our consent banner.
Third-party domains contacted
ptengine.comptengine.jpjs.ptengine.comjs.ptengine.jpapi.ptengine.comptengine.cnCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _ptqs | analytics | 30 minutes | Stores session state, last query string and referrer used by the Ptengine SDK for session attribution. |
| _ptUvar | analytics | 2 years | Persistent visitor identifier used by Ptengine to recognise returning users across sessions. |
| _ptUseridvar1 | analytics | 2 years | Custom user identifier set by Ptengine when the publisher provides a logged in user reference. |
| _ptHQID | analytics | 1 year | Heatmap identifier used by Ptengine to associate captured interactions with heatmap experiments. |
| _ptSeg | marketing | 1 year | Stores the audience segments computed by Ptengine to deliver personalisation rules. |
| _ptUid | analytics | 2 years | Anonymous user identifier set by Ptengine for analytics aggregation. |
Ptengine collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Ptengine sets first party cookies on the publisher domain prefixed with _pt, including _ptqs for queries and session state, _ptUseridvar1 and _ptUvar for the persistent visitor identifier, plus heatmap and session related cookies. These cookies enable analytics, heatmaps and personalisation and are not strictly necessary.
Yes. Because Ptengine performs detailed behavioural tracking through heatmaps and personalisation, prior, free, specific and informed consent is required under Article 5(3) of the ePrivacy Directive and Article 6(1)(a) of the GDPR. The SDK must remain inactive until consent is granted.
The legal basis is the data subject consent under Article 6(1)(a) of the GDPR, combined with Article 5(3) of the ePrivacy Directive for cookies and similar technologies. Legitimate interests are not appropriate for behavioural tracking and personalisation of this type.
Yes. Ptengine hosts data on servers located in Japan and China. Japan benefits from a partial EU adequacy decision for private sector data, while transfers to China must be covered by Standard Contractual Clauses with supplementary measures and a transfer impact assessment.
A DPIA is strongly recommended due to systematic behavioural monitoring, personalisation profiling, transfers to a non adequate country (China) and the possible capture of input content. The DPIA should describe data flows, retention, transfer mechanisms and mitigations.
Load Ptengine through a consent management platform with analytics and personalisation categories, enable input masking, exclude sensitive pages from heatmaps, reduce retention and sign a data processing agreement with appropriate transfer mechanisms. Inform users clearly about Japan and China hosting.
Privacy oriented alternatives include Matomo with EU hosting and on premise heatmaps, Mouseflow EU, Contentsquare with EU configuration and Hotjar EU. These tools provide heatmaps, recordings and analytics with EU data residency and stronger data minimisation options.
Add Ptengine in your cookie policy under analytics and personalisation with the _pt cookies, durations and purposes. Indicate that data is processed by Ptengine on servers in Japan and China, mention the applicable transfer mechanism and link to the Ptengine privacy policy.