Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Real time analytics data platform built on ClickHouse that ingests event data through APIs and SDKs without browser cookies, available in EU and US regions.
Tinybird is a real time analytics data platform built on top of ClickHouse, the high performance columnar database. It lets developers ingest large streams of event data and publish fast analytics APIs without managing their own database clusters. Unlike a typical website tag, Tinybird is backend infrastructure that receives data through APIs and software development kits rather than by setting cookies in a visitor browser. This means its compliance profile is shaped by what the customer chooses to send into it and where that data is stored.
Tinybird does not set tracking cookies in end user browsers, so it is cookieless from the visitor point of view. The personal data it holds is whatever the customer ingests, which can include user identifiers, IP addresses, device data and behavioural events sent from applications or pipelines. Because it is designed for scale, the volume of personal data can be very large even though no cookie is involved. The sensitivity depends entirely on the fields the customer decides to send.
Because Tinybird sets no cookies on the device, Art. 5(3) of the ePrivacy Directive does not apply to the platform itself, although it may apply to the upstream collection that feeds it. Under the GDPR, Tinybird normally acts as a processor that handles data on the documented instructions of the customer, who is the controller. A data processing agreement under Art. 28 GDPR is therefore essential, and Tinybird publishes a Data Processing Addendum for this purpose. The controller remains responsible for the legal basis and for informing data subjects about the analytics.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Tinybird itself does not trigger a cookie consent requirement because it stores nothing on the device. Consent may still be needed at the point where the data is collected, for example if a website sets cookies or reads device data before sending events onward. Where the upstream collection is cookieless and relies on legitimate interest, the analytics in Tinybird can often proceed on that basis with a balancing test. The controller should decide the lawful basis before any personal data is ingested.
Tinybird offers several workspace regions, so a customer can keep data within the European Union by selecting an EU region such as eu-west-1. If a United States region is chosen, or if support and sub processors operate from the United States, personal data may be processed in a third country under Standard Contractual Clauses and the EU to US Data Privacy Framework. Self managed regions let an organisation run the platform on its own infrastructure for full data locality. A transfer impact assessment should confirm the safeguards for any flow that leaves the EEA.
Sign the Tinybird Data Processing Addendum and choose an EU region if you want to keep data within the European Union. Minimise what you ingest, pseudonymise identifiers where possible and set retention so that event data is not kept longer than needed. Define the lawful basis at the point of collection and make sure your consent or legitimate interest logic upstream is sound. Finally, document Tinybird as a processor in your records of processing and reflect the analytics in your privacy notice.
Websites using Tinybird must obtain user consent under GDPR regulations.
DPIA considerations
Tinybird does not set browser cookies, but it can process personal data at scale, so a data protection impact assessment is advisable when large volumes of event data relate to identifiable people or when sensitive attributes are ingested. The assessment should focus on what the customer sends into Tinybird, the chosen region, the retention applied and whether identifiers can be reduced through pseudonymisation. Because the controller decides what data flows in, most of the assessment work concerns the upstream collection rather than the platform itself. Choosing an EU region and minimising identifiers materially reduces the residual risk.
Sample consent text
We use analytics to understand how our product is used. The event data is processed by Tinybird, a real time analytics platform, on our behalf and may be stored in the region we have selected. Where this analytics relies on consent, you can accept or decline it here.
Third-party domains contacted
tinybird.coapi.tinybird.coapi.us-east.tinybird.coapi.eu-west-1.tinybird.coTinybird collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Tinybird is backend analytics infrastructure and does not set tracking cookies in end user browsers. It receives data through APIs and SDKs rather than through a browser tag, so from a visitor perspective it is cookieless. Any cookies in your overall analytics setup would come from the upstream collection layer, not from Tinybird itself.
Tinybird itself does not create a cookie consent requirement because it stores nothing on the device. Consent may still be needed where the data is first collected, for example if a website sets cookies or reads device data before sending events. Whether consent applies depends on the upstream collection method rather than on Tinybird.
Tinybird normally acts as a processor under Art. 28 GDPR, handling data on the documented instructions of the customer. The customer as controller sets the legal basis for the ingested data, commonly legitimate interest under Art. 6(1)(f) for product analytics or consent under Art. 6(1)(a) where upstream cookies are involved. A data processing agreement should be in place before any personal data is sent.
It can, depending on the region you choose. If you select an EU region such as eu-west-1, data stays within the European Union. If you select a US region, or if support and sub processors operate from the United States, personal data may be processed there under Standard Contractual Clauses and the Data Privacy Framework. Self managed regions keep data on your own infrastructure.
A data protection impact assessment is advisable when you ingest large volumes of personal data, when events relate to identifiable people, or when sensitive attributes are involved. Because the controller decides what data flows in, much of the assessment concerns the upstream collection and the chosen region. Choosing an EU region and minimising identifiers lowers the residual risk considerably.
Sign the Tinybird Data Processing Addendum and pick an EU region if you want to keep data in the European Union. Minimise the fields you ingest, pseudonymise identifiers where you can and set a sensible retention period. Establish the lawful basis at the point of collection upstream and record Tinybird as a processor in your records of processing.
Alternatives include self hosted ClickHouse, ClickHouse Cloud, and other real time analytics backends such as Apache Pinot or Druid, as well as managed event platforms. For privacy first setups, self hosted ClickHouse or a Tinybird self managed region gives full data locality. The choice depends on how much infrastructure you want to manage and where the data must reside.
Because Tinybird sets no browser cookies, it usually does not need a cookie policy entry of its own. Instead, describe it in your privacy notice as a processor that handles event data on your behalf, and name the region where the data is stored. If your upstream collection sets cookies before sending events, document those cookies and any US transfer in the relevant sections.