Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Swiftype Site Search, now part of Elastic, is a hosted search service that adds fast site and application search through an embedded JavaScript snippet and a search API. The embed can set first party cookies and use localStorage to track a search session and collect query analytics. All customer data is stored in the United States, in Texas data centers with AWS US backups, with no EU hosting option. EU websites therefore need a consent banner for its non essential cookies and a valid transfer mechanism.
Swiftype Site Search is a hosted search product that gives websites and applications fast, relevant search without running their own search infrastructure. It is now part of Elastic, the company behind the Elasticsearch and Elastic Stack ecosystem. You add it by embedding a JavaScript snippet that loads from Swiftype and Elastic domains and calls a hosted search API. Because the snippet runs in the visitor browser and the index lives on Swiftype servers, search queries and related data are sent to the provider. This convenience comes with a larger privacy footprint than a self hosted engine, since a third party processes the queries and can set cookies. Understanding what it stores and where is essential before deploying it on an EU facing site.
The Swiftype embed can set first party cookies and use localStorage to store a search session identifier and remember preferences, and an analytics enabled configuration may add further first party cookies. It collects the search queries that visitors type, the results they click, and technical metadata such as IP address and browser information used to operate and improve the search. This query and click data is processed as analytics to measure search performance, which goes beyond what is strictly necessary to return results. Because the data is sent to Swiftype servers, the provider acts as a processor for the personal data contained in queries and logs. You should treat the search session cookies and analytics as requiring consent rather than as strictly necessary. Always confirm the current cookie behaviour in your own deployment, as it can change with configuration.
Under the ePrivacy Directive, the cookies and storage Swiftype uses for session tracking and analytics are not strictly necessary, so prior consent is required before the embed sets them. Under the GDPR you act as the data controller for the search queries and visitor data, and Swiftype operated by Elastic acts as your processor, which means you need a data processing agreement in place. The search analytics functionality relies on consent, while purely returning results that a visitor explicitly requested might be argued under legitimate interest, but the cookie consent obligation still applies. Because all data is stored in the United States, an international transfer assessment is also required. The combination of non essential cookies, analytics, and US storage makes Swiftype a higher risk choice for EU websites. Clear documentation and a robust consent flow are essential.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Treat the Swiftype embed as a non essential third party that must be blocked until the visitor gives consent. Integrate it with your consent management platform so the script only loads after the user accepts the relevant cookie category, typically functional or analytics. Avoid firing the embed on page load before consent is captured, and provide a clear way to withdraw consent that stops further loading. Your consent banner should name Swiftype or Elastic, explain that search queries are processed in the United States, and link to your privacy notice. Test that declining consent genuinely prevents the cookies and the network calls. Keep a record of consent so you can demonstrate compliance if challenged.
Swiftype stores all customer data in the United States, using Texas data centers as the primary platform with offsite backups in Amazon AWS infrastructure in the US, and it does not host data within the European Union. For an EU website this means visitor search queries are transferred to a third country, which the GDPR only permits with an appropriate safeguard. You should rely on the EU US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses, and complete a transfer impact assessment that considers US surveillance laws. Document the safeguard in your records of processing and your privacy notice. If you cannot accept a US transfer, an EU hosted or self hosted search engine is a better fit. Review the transfer mechanism periodically as the legal landscape evolves.
Start by signing the Swiftype data processing addendum with Elastic and confirming the transfer safeguard you will rely on for US storage. Configure your consent management platform to block the embed until consent is given for the relevant cookie category. Update your privacy notice and cookie policy to name Swiftype, describe the session and analytics cookies, and disclose the US transfer. Set sensible retention for search analytics and limit who can access the Swiftype dashboard. Complete a transfer impact assessment and, where the risk is significant, a Data Protection Impact Assessment. Test the consent flow to ensure declining truly stops the cookies and the calls. Finally, schedule periodic reviews so your documentation stays aligned with the live configuration.
Websites using Swiftype Site Search must obtain user consent under GDPR regulations.
DPIA considerations
Swiftype warrants a careful assessment because it sends search queries and visitor data to servers in the United States and sets cookies that are not strictly necessary. A Data Protection Impact Assessment is advisable where search logs can be linked to identifiable users or combined with other personal data, or where large volumes of queries are processed. Document the categories of data sent to Swiftype, the US storage location, the transfer safeguard relied on, and the retention of search analytics. Record how consent is obtained before the embed loads and how data subject requests are handled.
Sample consent text
This website uses Swiftype Site Search by Elastic to power our search. With your consent, it sets cookies and stores a search session identifier, and your search queries are processed on servers in the United States. You can accept or decline these non essential cookies at any time.
Third-party domains contacted
swiftype.comapi.swiftype.coms.swiftypecdn.comelastic.coCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Search session identifier | first_party | session to a few months | Stores a search session identifier used to associate a visitor's searches and clicks for search analytics and result relevance. |
| localStorage search preferences | first_party | persistent until cleared | Stores recent queries and display preferences in the browser to support the search widget experience. |
| Search analytics | first_party | session to a few months | Set in an analytics enabled configuration to measure search performance such as query volume and click through, which is not strictly necessary and requires consent. |
Swiftype Site Search collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The Swiftype embed can set first party cookies and use localStorage to store a search session identifier and remember preferences, and an analytics enabled configuration may add further first party cookies. These are not strictly necessary because they support search analytics, so they should be treated as requiring consent. Always verify the exact cookies in your own deployment, as behaviour can change with configuration.
Yes. Because Swiftype sets cookies that are not strictly necessary and collects search analytics, the ePrivacy Directive requires prior consent before the embed loads. You should block the script behind your consent banner and only load it once the visitor accepts the relevant cookie category.
Core search functionality may be argued under legitimate interest (GDPR Article 6(1)(f)), but the non essential cookies and search analytics require consent (Article 6(1)(a)) under the ePrivacy Directive. In practice you rely on consent for the cookies and a processor agreement with Elastic for the underlying data processing.
Yes. Swiftype stores all customer data in the United States, in Texas data centers with AWS US backups, and does not host data in the European Union. EU use is a transfer to a third country that needs a safeguard such as the EU US Data Privacy Framework or Standard Contractual Clauses plus a transfer impact assessment.
A Data Protection Impact Assessment is advisable. Swiftype sends search queries and visitor data to the US and sets non essential cookies, and a DPIA is particularly warranted where search logs can be linked to identifiable users or large volumes of queries are processed.
Sign the Elastic data processing addendum, confirm your US transfer safeguard, and integrate the embed with your consent management platform so it only loads after consent. Update your privacy and cookie policies to name Swiftype, describe its cookies and disclose the US transfer, and test that declining consent stops the cookies and network calls.
Self hosted engines such as Meilisearch, Typesense or OpenSearch let you keep search data in the EU with no third party tracking cookies. Hosted alternatives with EU data residency options also exist. These reduce both the cookie consent burden and the international transfer risk.
List the Swiftype search session and analytics cookies with their purpose and approximate duration, state that it is provided by Elastic, and disclose that search queries are processed and stored in the United States. Note the transfer safeguard you rely on and review the entry whenever the configuration or cookie set changes.