Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Sirge is a United States based marketing attribution and ad tracking app, built mainly for Shopify stores. It follows ad clicks, UTM parameters and the customer journey to attribute conversions to Facebook, TikTok and other campaigns, using first party cookies, click identifiers and server side tracking. Because it processes personal data and feeds advertising platforms, it needs valid consent under the GDPR.
Sirge is a marketing attribution and ad tracking app based in the United States. It is built mainly for Shopify stores that run paid campaigns on platforms such as Facebook and TikTok. By following the customer journey from the first ad click to the final purchase, Sirge tells merchants which campaigns actually drive revenue. This makes it a powerful tool, but also one that processes a large amount of personal data about shoppers.
Sirge relies on first party cookies, click identifiers and UTM parameters to recognise visitors and connect them to specific campaigns. It uses server side tracking to send conversion events back to the advertising platforms, which improves measurement even when browsers block scripts. The data involved includes online identifiers, browsing behaviour on the store and purchase information. Under the GDPR this is personal data, so it must be handled with a clear legal basis and proper transparency.
The cookies and identifiers that Sirge stores or reads on a visitor device fall under article 5(3) of the ePrivacy Directive, which requires prior consent for any non essential storage. The processing of the collected data is then governed by the GDPR. Because attribution and advertising are not strictly necessary to deliver the store, the appropriate legal basis is consent under article 6(1)(a). Merchants in the European Union therefore cannot activate Sirge by default before a visitor has agreed.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Valid consent must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as to accept. A compliant setup keeps Sirge inactive until the visitor opts in through a consent banner, and it blocks both the cookies and the server side events until that moment. The consent record should show what the visitor agreed to and when. Visitors must also be able to withdraw their consent later without difficulty.
Sirge is a United States company, and it shares attribution data with advertising platforms that also operate there. This means personal data leaves the European Union and reaches a third country. Transfers should rely on the EU US Data Privacy Framework where the recipient is certified, or on the Standard Contractual Clauses backed by a transfer impact assessment. Merchants should document these safeguards and inform visitors that their data may be processed outside the European Economic Area.
To use Sirge lawfully, connect it to a consent management platform so that tracking only starts after opt in. Document the cookies in your cookie policy, name Sirge in your privacy notice, and sign a data processing agreement that covers the international transfers. Keep a record of consent and review the configuration whenever Sirge adds new features or destinations. With these measures in place, merchants can benefit from accurate attribution while respecting the rights of their visitors.
Websites using Sirge must obtain user consent under GDPR regulations.
DPIA considerations
Sirge combines advertising attribution, click identifiers and server side events with transfers to the United States, so a data protection impact assessment is recommended. Assess the scale of behavioural tracking, the profiling of shoppers across ad platforms, the legal basis for each cookie, and the safeguards for international transfers under the EU US Data Privacy Framework and the Standard Contractual Clauses.
Sample consent text
We use Sirge to measure which advertising campaigns lead to purchases. With your consent, Sirge sets first party cookies and click identifiers and sends conversion events to advertising platforms in the United States. You can accept or refuse these attribution cookies, and you can change your choice at any time.
Third-party domains contacted
sirge.comapi.sirge.comcdn.sirge.comtrack.sirge.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| sirge_uid | first party attribution | up to 1 year | Stores a persistent attribution identifier (also seen as _srge) to link an ad click to a later conversion. |
| sirge_click | first party advertising | up to 90 days | Holds the click identifier captured from the ad platform so the conversion can be attributed to the right campaign. |
| sirge_session | first party analytics | session | Identifies a single browsing session to group page views and events during the customer journey. |
Sirge collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Sirge mainly sets first party cookies such as the attribution identifier (often called sirge_uid or _srge), a click identifier and a session value. These are stored on the visitor browser to link an ad click to a later purchase. Because they serve advertising and analytics, they are not strictly necessary and require consent.
Yes. The cookies and click identifiers fall under article 5(3) of the ePrivacy Directive, so prior consent is needed before they are stored. The related processing relies on consent under article 6(1)(a) of the GDPR. Sirge should stay inactive until the visitor has agreed.
The appropriate legal basis is consent, both for storing the cookies under ePrivacy and for the GDPR processing under article 6(1)(a). Legitimate interest is not suitable here because advertising attribution is not necessary to run the store and creates meaningful tracking. You should record each consent decision.
Yes. Sirge is United States based and shares attribution data with advertising platforms in third countries. These transfers should rely on the EU US Data Privacy Framework when the recipient is certified, or on the Standard Contractual Clauses with a transfer impact assessment. Visitors should be told their data may leave the European Economic Area.
A data protection impact assessment is strongly recommended. Sirge combines large scale behavioural tracking, cross platform profiling and transfers to the United States, which are the kind of factors that point to higher risk. The assessment should document the data flows, the safeguards and the measures that reduce risk.
Connect Sirge to a consent management platform so that no cookie or server side event fires before opt in. List the cookies in your cookie policy, name Sirge in your privacy notice and sign a data processing agreement. Keep proof of consent and review the setup whenever Sirge changes.
Other attribution and analytics tools exist, including options that keep data within the European Union or offer a privacy first design. The right choice depends on your advertising platforms and on how much data leaves the European Economic Area. Whatever the tool, consent and a clear legal basis remain necessary for advertising tracking.
Add a clear entry that names the Sirge cookies, their purpose of advertising attribution, their duration and the fact that data may be processed in the United States. Explain how visitors can refuse or withdraw consent. Keep the policy in step with the consent banner so the two always match.