Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Uscreen is a US-based video streaming, membership, and OTT platform that hosts video content, manages subscriber payments via Stripe, and tracks viewing behaviour through embedded players. It integrates Cloudflare, Vimeo, and Google Analytics and sets multiple cookies for authentication, analytics, and session management.
Uscreen is a US-based platform that enables content creators and businesses to deliver video streaming, online courses, and membership communities directly to subscribers. Website operators embed Uscreen video players and membership portals using iframes or JavaScript snippets served from uscreen.io and embed.uscreen.io. When a visitor lands on a page with Uscreen content, the player and membership scripts initialise and begin setting cookies and transmitting data to Uscreen''s US servers.
Tracking occurs at multiple layers: the Uscreen player tracks video views, playback position, and completion rates; the membership system tracks authentication state and subscription status; and if Google Analytics is enabled by the site operator, behavioural data is sent to Google''s US infrastructure. Cloudflare acts as the CDN and may set its own cookies for bot detection and performance optimisation.
Uscreen sets authentication cookies to maintain a logged-in session, session cookies to track membership state, and analytics cookies to record content engagement. If the operator enables Vimeo video hosting, Vimeo sets its own tracking cookies. Stripe, used for payment processing, sets cookies to detect fraud and maintain payment session state. Payment card data is processed exclusively by Stripe and is not stored by Uscreen. Personal data processed includes name, email address, billing information, IP address, device identifiers, and detailed video engagement logs.
Under the GDPR, the website operator using Uscreen is the data controller and must ensure a valid Data Processing Agreement is in place with Uscreen. Authentication and payment cookies that are strictly necessary for the delivery of a purchased membership may be exempt from the ePrivacy consent requirement as they are technically required to fulfil the contract. However, analytics cookies, video engagement tracking, and any advertising or retargeting pixels require prior consent under ePrivacy and the GDPR consent standard.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Operators must configure their CMP to block non-essential Uscreen scripts until consent is obtained. Strictly necessary authentication cookies for active members may be loaded without consent when the user has initiated a login. All analytics and engagement tracking scripts, including any Vimeo or Google Analytics integration, must be consent-gated. Consent must be granular: visitors should be able to accept authentication cookies without also accepting analytics tracking. Withdrawal of consent must be honoured and result in analytics cookies being deleted.
Uscreen is a US company and transfers personal data to the United States. The transfer is covered by the EU-US Data Privacy Framework (DPF) if Uscreen is certified, and by Standard Contractual Clauses (SCCs) as a supplementary safeguard. Sub-processors including Stripe, Cloudflare, and Google Analytics also process data in the US. Each sub-processor relationship must be covered by SCCs or DPF certification. You must document all transfer mechanisms in your records of processing activities and reference them in your privacy policy.
To comply when using Uscreen: sign Uscreen''s DPA and retain it, document all sub-processors (Stripe, Cloudflare, Vimeo, Google Analytics) and their transfer mechanisms, configure your CMP to block analytics scripts before consent, add Uscreen and each sub-processor to your privacy policy and cookie notice, set appropriate retention periods for membership and analytics data, and confirm SCCs or DPF certification for each US transfer. If CCPA applies to your audience, implement the required opt-out mechanisms for California residents.
Websites using Uscreen must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should be considered for Uscreen deployments on European websites, particularly where the platform processes payment data in combination with viewing behaviour, where Google Analytics is enabled alongside Uscreen (creating a comprehensive behavioural profile), or where special-category content is streamed (e.g., health or religious content that could reveal sensitive attributes). The US-based hosting and involvement of multiple sub-processors (Stripe, Cloudflare, Vimeo, Google) increases transfer risk and requires documented SCCs or DPF reliance for each. Assess the scope of data linkage between membership data and analytics data.
Sample consent text
We use Uscreen to host and deliver our video content and manage your membership. Uscreen sets cookies for authentication and session management, which are necessary to provide the service. It also sets analytics and video-tracking cookies to understand how you interact with content. Cookies beyond those strictly necessary for your membership require your consent. By accepting, you agree to Uscreen and its sub-processors (including Stripe, Cloudflare, and Google Analytics) processing your data in the United States under the EU-US Data Privacy Framework. You can withdraw non-essential consent at any time via our cookie settings.
Third-party domains contacted
uscreen.iouscreen.tvembed.uscreen.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| uscreen_auth_token | functional | 30 days | Authentication token that maintains a logged-in membership session and grants access to purchased video content |
| uscreen_session | functional | Session | Manages the current browsing session state and prevents the need to re-authenticate on every page load |
| uscreen_analytics | analytics | 1 year | Records video engagement data including play counts, watch-time, and content completion rates to help operators understand audience behaviour |
| __stripe_mid | functional | 1 year | Stripe payment processor cookie for fraud prevention and fraud detection during checkout; set by Stripe (stripe.com) |
| __cf_bm | functional | 30 minutes | Cloudflare bot management cookie used to distinguish legitimate users from automated traffic on Uscreen-served content |
| uscreen_video_prefs | functional | 6 months | Stores video player preferences such as playback quality and volume settings for a consistent viewing experience |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
Uscreen sets authentication cookies to maintain logged-in membership sessions, session cookies for anonymous visitors browsing content previews, and analytics cookies to record video engagement data such as plays and completion rates. If Google Analytics is enabled by the site operator, additional analytics cookies are set. Stripe adds payment and fraud-detection cookies during checkout flows, and Cloudflare may set performance and bot-detection cookies.
Partial consent is required. Authentication cookies that are strictly necessary to deliver a paid membership service a user has actively requested may be loaded without prior consent under the ePrivacy Directive's strictly necessary exemption. However, analytics tracking, video engagement tracking, and any advertising or retargeting integrations require prior consent from EU visitors. The Uscreen embed should be split so that only strictly necessary elements load before consent is obtained.
Two primary legal bases apply. Contract performance (Article 6(1)(b) GDPR) covers processing necessary to deliver the membership and streaming service a subscriber has purchased, including authentication and payment processing. Consent (Article 6(1)(a) GDPR) is the appropriate basis for analytics, video engagement tracking, and any marketing or retargeting processing. Legitimate interest is unlikely to override the consent requirement for tracking given the availability of less intrusive alternatives.
Yes, Uscreen is a US company and transfers personal data to the United States. Additionally, sub-processors including Google Analytics, Stripe, and Cloudflare also process data in the US. Transfers should be covered by the EU-US Data Privacy Framework (DPF) where the entity is certified, supplemented by Standard Contractual Clauses (SCCs). You must verify certification status and document the applicable transfer mechanism for each sub-processor in your records of processing activities.
A DPIA is strongly recommended where Uscreen processes payment data alongside detailed video viewing histories, as this combination creates a rich profile of subscriber behaviour and financial data. A DPIA is also advisable if the content streamed could reveal special-category data (health, religion, sexuality), if Google Analytics is layered on top of Uscreen membership data, or if the site serves a large EU audience. Document the necessity, proportionality, and risk mitigation measures.
Sign Uscreen's DPA and obtain and retain signed SCCs for US transfers. Configure your CMP to block all non-essential Uscreen JavaScript until consent is given, while allowing authentication scripts to load for active subscribers post-login. Add Uscreen, Stripe, Cloudflare, Vimeo, and Google Analytics to your cookie notice and privacy policy. Set data retention limits in Uscreen's admin panel for membership and engagement data. Implement a CCPA opt-out mechanism if you have California-resident subscribers.
EU-hosted alternatives for video membership include Ventuno and PeachPay-based custom WordPress solutions using self-hosted video (e.g., Peertube). For creators wanting minimal tracking, Memberful combined with a self-hosted or Bunny.net-delivered video provides greater data control. Moodle with BigBlueButton covers online course delivery without US-based processing. These alternatives require more technical setup but reduce third-country transfer complexity significantly.
Your cookie policy must include separate entries for each cookie set by Uscreen, Stripe, Cloudflare, Vimeo (if used), and Google Analytics (if used), listing the cookie name, type, duration, purpose, and the entity that sets it. For each US-based entity, state the transfer mechanism (DPF certification, SCCs, or both). Indicate the legal basis for each category and how users can withdraw consent. Review and update the policy each time Uscreen releases a new version or modifies its sub-processor list.