Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Wootric by InMoment is an in-app and email micro-survey platform for NPS, CSAT, and CES measurement. It collects scores and verbatim feedback tied to individual user identities, and transfers data to US servers operated by InMoment. Consent is required when deployed client-side with cookies; legitimate interest may apply to cookieless email surveys where a prior customer relationship exists.
Wootric, now part of the InMoment experience intelligence platform, is a micro-survey tool specialising in Net Promoter Score (NPS), Customer Satisfaction (CSAT), and Customer Effort Score (CES) measurement. It can be deployed in two primary ways: as a client-side JavaScript SDK embedded in a web application or mobile app that displays in-app survey modals, or as an email survey delivered directly to users'' inboxes. In both cases, each respondent is identified by their email address or an external user ID passed at SDK initialisation, meaning all survey responses are linked to a specific individual rather than collected anonymously.
The SDK communicates with api.wootric.com to authenticate the account, determine survey eligibility, and submit responses. The client-side script is loaded from cdn.wootric.com. Survey timing and eligibility rules (such as days since last survey or plan type) are evaluated against user properties passed at initialisation, which may include account metadata, subscription tier, or other custom traits.
Wootric collects the survey response score (a numerical rating), verbatim comments provided by the user, the email address or external user ID used at initialisation, any custom user properties passed via the SDK, and technical metadata including page URL, timestamp, and browser information. When deployed as a client-side SDK, Wootric sets cookies to manage survey eligibility windows and prevent survey fatigue. These cookies store a unique user token and the timestamp of the last survey interaction. Email surveys do not set browser cookies but do involve processing the user''s email address and tracking link clicks.
Under the ePrivacy Directive, client-side deployment of Wootric requires prior consent because the SDK sets non-essential cookies. For email-based NPS surveys, the ePrivacy rules on cookies do not directly apply (no cookies are set on the device), but GDPR still governs the processing of personal data. Under GDPR, the legal basis depends on the deployment channel: consent under Article 6(1)(a) is the safest and most straightforward basis for in-app surveys using the SDK; for email surveys sent to existing customers as part of a service improvement programme, legitimate interest under Article 6(1)(f) may be defensible, provided a Legitimate Interest Assessment (LIA) is documented and users can easily opt out of future surveys.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
All Wootric data is processed by InMoment on servers located in the United States. This constitutes a transfer of personal data to a third country under GDPR Chapter V. InMoment participates in the EU-US Data Privacy Framework (DPF), providing an adequacy-equivalent basis for such transfers. Operators deploying Wootric for EEA users should verify that InMoment''s DPF certification is current, document the transfer mechanism in their Records of Processing Activities (RoPA), and consider requesting Standard Contractual Clauses (SCCs) from InMoment as an additional safeguard. The InMoment Data Processing Agreement (DPA) should be reviewed and signed before going live with EEA audiences.
For in-app SDK deployments, integrate the Wootric script loading with your Consent Management Platform (CMP) so it only initialises after the user has accepted the relevant cookie category. For email surveys, if relying on legitimate interest, complete a LIA demonstrating that the processing is necessary, proportionate, and that users'' interests do not override the business interest. Always include an opt-out link in survey emails and honour opt-out requests promptly. In both cases, document the legal basis per processing activity in your RoPA.
To deploy Wootric compliantly: gate the CDN script behind CMP consent for in-app use; list all Wootric cookies in your cookie policy (name, type, duration, purpose); include wootric.com, api.wootric.com, and cdn.wootric.com in your Privacy Policy as InMoment-operated third-party endpoints; sign InMoment''s DPA and verify DPF certification; document your legal basis and transfer mechanism; include a DPIA or risk assessment for large-scale or identity-linked deployments; and provide users with a clear explanation of what survey data is collected and how to opt out.
Websites using Wootric by InMoment must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment (DPIA) should be considered for Wootric deployments that tie NPS or CSAT scores to individual user profiles at scale, especially where feedback is combined with CRM or behavioural data. Key risks include: the transfer of personal data (including email addresses and verbatim comments) to InMoment servers in the United States; the systematic profiling of customer satisfaction linked to identifiable individuals; the potential for open-ended verbatim responses to contain sensitive personal data; and the use of cookies or persistent identifiers in the client-side SDK. Operators should document the chosen legal basis (consent vs. legitimate interest), conduct a Legitimate Interest Assessment (LIA) if relying on Article 6(1)(f), and ensure a valid transfer mechanism such as the EU-US DPF or SCCs is in place before processing EEA personal data.
Sample consent text
We use Wootric by InMoment to send you short satisfaction surveys (NPS, CSAT, or CES) to help us improve our products and services. Your feedback, including any comments you provide, is processed by InMoment on servers in the United States. Wootric may use cookies to manage survey delivery. By clicking "Accept", you consent to this processing. You can withdraw your consent at any time by contacting us.
Third-party domains contacted
wootric.comapi.wootric.comcdn.wootric.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| wootric_user_token | persistent | 1 year | Stores a unique user token to identify the respondent and manage survey eligibility across sessions. |
| wootric_last_survey | persistent | 1 year | Records the timestamp of the last survey shown or completed to enforce survey frequency limits and prevent fatigue. |
| wootric_session | session | Session | Manages survey display logic and eligibility checks within a single browsing session. |
| wootric_surveyed | persistent | 90 days | Flags that the user has already been shown a specific survey to avoid repetition within the suppression window. |
Wootric by InMoment collects user analytics data — you legally need a consent banner. Try FlowConsent free.
When deployed as an in-app JavaScript SDK, Wootric sets cookies to manage survey eligibility windows and prevent survey fatigue. These typically include a unique user token cookie and a timestamp cookie recording when the user last received or responded to a survey. The exact cookie names may vary by SDK version. Email-based Wootric surveys do not set any browser cookies, though they do involve tracking whether the email link was clicked.
Consent is required for client-side in-app deployment of Wootric because it sets non-essential cookies in the user's browser. For email-based NPS surveys sent to existing customers, consent may not be strictly required if the deployment relies on legitimate interest under GDPR Article 6(1)(f), provided a Legitimate Interest Assessment is documented and users can easily opt out. When in doubt, obtaining explicit consent is the safest approach for EEA audiences.
For in-app SDK deployments using cookies, consent under GDPR Article 6(1)(a) is the recommended legal basis. For transactional email surveys to existing customers without cookies, legitimate interest under Article 6(1)(f) may apply, subject to a documented Legitimate Interest Assessment (LIA) and a clear opt-out mechanism. In all cases, the legal basis must be documented per processing activity in your Records of Processing Activities, and users must be informed of the basis in your Privacy Policy.
Yes. Wootric is operated by InMoment, a US-based company, and all survey data including scores, verbatim comments, and user identifiers is processed on US servers. This constitutes a third-country transfer under GDPR Chapter V. InMoment participates in the EU-US Data Privacy Framework (DPF), which provides an adequacy-equivalent basis. Operators should verify InMoment's DPF certification is current, and may also request Standard Contractual Clauses (SCCs) from InMoment as additional protection.
A DPIA is recommended if you use Wootric to systematically link satisfaction scores to individual user profiles at scale, particularly if combined with CRM, behavioural, or demographic data. A DPIA is mandatory under GDPR Article 35 when the processing is likely to result in a high risk to individuals. Even where not strictly required, a documented risk assessment before deploying any tool that transfers EEA personal data to the US is considered good practice by most data protection authorities.
For in-app SDK use, gate Wootric initialisation behind your CMP so the SDK only loads after the user consents. For email surveys, document a Legitimate Interest Assessment, include an opt-out link in every survey email, and handle opt-out requests without delay. In both cases, sign InMoment's Data Processing Agreement, list Wootric cookies in your cookie declaration, reference InMoment as a data processor in your Privacy Policy, and document the EU-US DPF or SCCs as your transfer mechanism in your Records of Processing Activities.
EU-based or privacy-focused alternatives for NPS and CSAT measurement include Nicereply (EU hosting available), Survicate (GDPR-compliant with EU data residency), or Delighted (with privacy controls). For complete data ownership, open-source tools such as Formbricks or self-hosted survey platforms allow NPS collection with data remaining on your own infrastructure. The best alternative depends on your integration needs, user volume, and preference for managed vs. self-hosted solutions.
Add Wootric to your cookie policy table listing the cookie name, type (analytics or functional), duration, and purpose. Reference wootric.com, api.wootric.com, and cdn.wootric.com as the third-party domains. Update the processors section of your Privacy Policy to name InMoment as a data processor and describe the US transfer, the mechanism (DPF or SCCs), and user rights regarding survey data. If you use automated cookie scanning, scan after deploying Wootric to capture any cookies set by the SDK. Review and update at least annually.