Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
RCode Vision is a lesser known web technology, linked to the vendor site rcodevision.com, that is detected on websites as an analytics or measurement script. It loads JavaScript that may set first party and possibly third party cookies to record visits and behaviour. Because public documentation is limited, the exact cookies, durations, and data flows should be confirmed with a live cookie scan and with the provider. As a non essential analytics tool it requires consent under the GDPR and the ePrivacy Directive.
RCode Vision is a lesser known web technology associated with the vendor site rcodevision.com that appears on websites as an analytics or measurement script. In general terms it is a JavaScript script that records visits and on site behaviour so that the site operator can understand traffic and engagement. Public documentation about its precise features is limited, so this guide describes it generically and recommends verifying specifics with the provider. Treat the description here as a measured, professional overview rather than an authoritative product specification.
As a measurement script, RCode Vision may set first party and possibly third party cookies to record visits and behaviour, typically including a visitor identifier cookie lasting around one year and a session cookie. Alongside cookies, analytics scripts of this kind commonly process IP addresses, browser and device information, pages viewed, and referral data. Because the exact cookie names, durations, and endpoints are not clearly documented, you should confirm them with a live cookie scan rather than rely on assumptions.
Because the cookies are read from and written to the visitor terminal for analytics rather than strictly necessary purposes, Article 5(3) of the ePrivacy Directive requires prior consent. A visitor identifier together with IP addresses and behavioural data is personal data under the GDPR, so a lawful basis, transparency, and a record of processing activities are required. You should also identify whether RCode Vision acts as a processor on your behalf and put an appropriate data processing agreement in place.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
As a non essential analytics technology, RCode Vision must not load before the visitor has actively accepted the analytics or statistics category in your consent banner. Pre ticked boxes, implied consent from continued browsing, and cookie walls do not meet the GDPR standard. Consent must be freely given, specific, informed, and granular, and just as easy to withdraw as to give, with the script blocked until consent is recorded.
Whether data leaves the EEA depends on where the provider hosts its infrastructure, which is not clearly documented, so confirm the hosting location and any onward transfers with the provider and, if data is processed outside the EEA, put Standard Contractual Clauses or another mechanism in place. In practice, run a cookie scan to capture the exact cookies and endpoints, gate the script behind your consent management platform, document the cookies and their durations in your cookie policy, and ask the provider for a data processing agreement and clear hosting information.
Websites using RCode Vision must obtain user consent under GDPR regulations.
DPIA considerations
RCode Vision is an analytics or measurement script that may set first party and possibly third party cookies, such as a visitor identifier and a session cookie, to record visits and behaviour, although public documentation is limited. A DPIA or at least a documented assessment is advisable because the exact data flows, cookies, and hosting location are not clearly known. It should establish what the script actually sets and sends through a cookie scan, confirm whether data leaves the EEA, and verify the controller and processor roles, with consent gating and a data processing agreement as mitigations.
Sample consent text
We use RCode Vision to measure how visitors use our website. It may place analytics cookies on your device to recognise your browser and record your activity, and these cookies load only after you accept the analytics category. The exact cookies and data involved are being verified, and we will keep our cookie policy up to date. You can withdraw your consent at any time through our cookie settings.
Third-party domains contacted
rcodevision.comcdn.rcodevision.comapi.rcodevision.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| rcv_id | analytics | About 1 year (typical, verify with a scan) | Representative visitor identifier cookie used to recognise returning visitors and attribute behaviour over time. The exact name and duration are not authoritatively documented, so confirm them with a live cookie scan on your own site. |
| rcv_session | analytics | Session (typical, verify with a scan) | Representative session cookie used to group a visitor's activity into a single visit for measurement. Treat this as a typical example and verify the actual cookie with a scan rather than assuming its presence. |
| rcv_ref | analytics | About 30 days (typical, verify with a scan) | Representative cookie that may store referral or campaign source information for analytics. Confirm whether this cookie is set, and its true duration, through a live cookie scan because vendor documentation is limited. |
RCode Vision collects user analytics data — you legally need a consent banner. Try FlowConsent free.
RCode Vision is an analytics script that may set first party and possibly third party cookies, typically a visitor identifier cookie lasting around one year and a session cookie. Because public documentation is limited, treat these as representative and confirm the exact names and durations on your site with a live cookie scan.
Yes. As a non essential analytics technology its cookies are not strictly necessary, so Article 5(3) of the ePrivacy Directive and the GDPR require prior, opt in consent before the script loads. Keep the script blocked until the visitor accepts the analytics category.
The lawful basis is consent under Article 6(1)(a) of the GDPR and Article 5(3) of the ePrivacy Directive, as for other analytics cookies. Legitimate interest is generally not available because consent is already required to read from and write cookies to the visitor terminal.
It is not clearly documented. Whether data leaves the EEA depends on where the provider hosts its infrastructure, so confirm the hosting location and any onward transfers with the provider. If data is processed outside the EEA, put Standard Contractual Clauses or another transfer mechanism in place and disclose it.
At least a documented assessment is advisable because the exact data flows, cookies, and hosting are not clearly known. Use a cookie scan to establish what the script actually sets and sends, confirm whether data leaves the EEA, clarify the controller and processor roles, and record consent gating and the data processing agreement as mitigations.
Run a cookie scan to capture the exact cookies and endpoints, then gate the script behind your consent management platform so it loads only after analytics consent. Document the cookies and durations in your cookie policy, name the provider, and obtain a data processing agreement together with clear information on where data is hosted.
Yes. Established, well documented analytics options include privacy focused tools such as Matomo, Plausible, or Fathom, which offer transparent cookie behaviour and EU hosting. For a lesser known script with limited documentation, a clearly documented alternative often makes compliance and auditing easier.
List each cookie you confirm through a scan, with its purpose and duration, name the provider as a recipient, and describe the analytics purpose. Note that some details were verified by scan rather than vendor documentation, and keep the entries in sync with regular rescans.