Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Syndeca is a US based shoppable content platform that lets retailers embed digital catalogs, lookbooks, flyers and shoppable images and videos on their website through a simple embed code, with integrated Google Analytics that may set first and third party cookies.
Syndeca is a US based shoppable content platform that helps retailers turn catalogs, lookbooks, flyers and product imagery into interactive, shoppable experiences embedded directly on their own website. When you add the Syndeca embed code, the platform loads its widget and its integrated Google Analytics, which together observe how visitors browse and interact with the embedded content. This page explains, in plain terms, what data the embed processes, the cookies it can set, and what European operators need to consider under the GDPR and the ePrivacy Directive.
Syndeca provides a hosted platform for digital catalogs, shoppable lookbooks, weekly ads and circulars, shoppable images and shoppable video. Retailers create content in the platform and publish it to their site with an embed code, so the experience feels native while the content and assets are served from Syndeca infrastructure on a content delivery network. The platform is designed to render across desktop, tablet and mobile devices, and it includes integrated analytics so merchandising and marketing teams can measure how each catalog performs.
The embed processes visitor interaction and engagement data, such as which catalog pages, products and hotspots are viewed and clicked, how long visitors stay and which links they follow. Through its integrated Google Analytics, Syndeca can set first and third party cookies, including the Google Analytics _ga style identifiers used to distinguish visitors and sessions. These cookies, together with device and approximate location signals derived from the connection, allow the platform to attribute engagement and measure catalog performance over time.
Because Syndeca relies on cookies and analytics that are not strictly necessary to deliver the page, two legal regimes apply. The ePrivacy Directive requires informed, prior consent before such cookies are stored or read on a visitor device, and the GDPR governs the resulting processing of personal data, including the identifiers in those cookies. As the website operator you are typically the controller for this processing, so you remain responsible for transparency, lawful basis and honouring visitor choices, even though Syndeca acts as a processor and Google operates the analytics layer.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The appropriate lawful basis for the analytics and marketing cookies set through the embedded catalog is consent under Article 6(1)(a) of the GDPR, given freely, specifically and on the basis of clear information. In practice this means the Syndeca embed and its Google Analytics should be blocked until the visitor actively accepts, and refusing should be as easy as accepting. A consent management platform that gates the embed script keeps you aligned with both the ePrivacy consent rule and the GDPR record keeping expectations.
Syndeca is hosted in the United States and serves its content from US based infrastructure, and the integrated Google Analytics also processes data on US systems. For visitors in the European Union and the wider European Economic Area, this means personal data is transferred to a third country. Such transfers should be covered by an appropriate mechanism, most commonly the EU US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses supported by a transfer impact assessment and supplementary safeguards.
Start by mapping every cookie and data flow the embed creates, then load the Syndeca script only after consent through your consent management platform. Name Syndeca and its analytics in your cookie policy and privacy notice, describe the US transfer and the safeguard you rely on, and keep a processing agreement with the vendor. Set sensible retention limits, test that declining consent truly prevents the cookies, and review the setup whenever Syndeca or Google changes how the integrated analytics behaves.
Websites using Syndeca must obtain user consent under GDPR regulations.
DPIA considerations
Because the Syndeca embed loads integrated Google Analytics and can set first and third party cookies, it processes visitor interaction data and transfers personal data to the United States. A data protection impact assessment is recommended where engagement tracking is extensive or combined with other profiling, and you should document the lawful basis, retention periods and transfer safeguards. Confirm that consent is captured before any non essential cookie or analytics script fires.
Sample consent text
We use Syndeca to display shoppable catalogs and analytics cookies that measure how you interact with this content; these may transfer data to the United States, and they load only with your consent.
Third-party domains contacted
syndeca.comwww.syndeca.comwww.google-analytics.comwww.googletagmanager.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _ga | Third party analytics | 2 years | Google Analytics cookie that distinguishes individual visitors so engagement with the embedded Syndeca catalog can be measured. |
| _gid | Third party analytics | 24 hours | Google Analytics cookie that distinguishes visitors over a short period to measure daily interaction with the embedded content. |
| _ga_<container_id> | Third party analytics | 2 years | Google Analytics 4 cookie that persists session state and counts visits for the property used by the Syndeca embed. |
| _gat | Third party analytics | 1 minute | Google Analytics cookie used to throttle the request rate and limit data collection on high traffic catalogs. |
| syndeca_session | First party functional | Session | First party cookie set by the Syndeca widget to maintain the state of the shoppable catalog during a visit. |
Syndeca collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Through its integrated Google Analytics, Syndeca can set first and third party cookies, including the Google Analytics _ga style identifiers that distinguish visitors and sessions, plus cookies used to measure engagement with the embedded catalog. Because these are not strictly necessary to display the content, they should load only after the visitor has given consent.
Yes. The embed relies on analytics and marketing cookies that are not essential to deliver the page, so under the ePrivacy Directive you must obtain informed, prior consent before the script runs and before any such cookie is stored or read. The embed should stay blocked until the visitor actively accepts.
The appropriate basis is consent under Article 6(1)(a) of the GDPR for the analytics and marketing cookies set through the embedded catalog. Consent must be freely given, specific, informed and as easy to withdraw as to give, and you should keep records that demonstrate it.
Yes. Syndeca is hosted in the United States and serves content from US infrastructure, and its integrated Google Analytics also processes data on US systems, so personal data of EU and EEA visitors is transferred to a third country. You should rely on a valid transfer mechanism, typically the EU US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses with supplementary safeguards.
A data protection impact assessment is recommended where engagement tracking through the embed is extensive or combined with other profiling, since it processes interaction data and transfers it internationally. Even where a full DPIA is not mandatory, documenting the lawful basis, retention periods and transfer safeguards is good practice.
Map every cookie and data flow the embed creates, then load the Syndeca script only after consent through a consent management platform. Name Syndeca and its analytics in your cookie policy and privacy notice, describe the US transfer and the safeguard you rely on, keep a processing agreement in place and test that declining consent truly prevents the cookies.
Syndeca itself does not offer a cookieless mode, since its integrated Google Analytics depends on cookies. If you need to minimise cookies or keep processing within the EU, you can evaluate shoppable content or catalog tools that support EU hosting and privacy friendly, consent independent analytics, and compare their transfer and tracking behaviour against your requirements.
List the Syndeca and Google Analytics cookies with their names, purpose and duration, explain that they require consent, and state that data may be transferred to the United States under the relevant safeguard. Keep the policy aligned with what your consent banner actually controls and review it whenever the embed or its analytics changes.