FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Appcues

Appcues

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Appcues do?

Appcues is a no code product adoption and user onboarding platform that displays in app modals, tooltips, checklists and slideouts to help users discover features, while tracking interactions for product analytics.

Appcues is a product adoption platform widely used by SaaS companies to design in app guides, onboarding tours, surveys, and feature announcements without engineering effort. It is delivered as a JavaScript SDK that runs inside the host application, fires events to the Appcues backend, and renders custom UI based on segmentation rules.

What Appcues does

The Appcues SDK is loaded with a small script tag from fast.appcues.com. It identifies the logged in user via the identify call you implement (Appcues.identify(userId, properties)), tracks events, evaluates targeting rules client side, and displays flows like modals, tooltips, hotspots, checklists, surveys, and slideouts. Results are sent back to the Appcues backend for analytics and goal tracking.

Cookies and data collected

Appcues sets first party identifiers in localStorage (appcues:user_id, appcues:session_id, appcues:state) and an _aciid cookie used for anonymous identification before the user logs in. Server side, Appcues receives the user ID and properties you pass in identify, every event you track, the user agent, the IP, the page URL, and the timestamp.

GDPR and ePrivacy implications

User IDs and event metadata are personal data. Appcues acts as a processor under your DPA. The SDK writes non strictly necessary storage and identifiers, so Article 5(3) ePrivacy requires prior consent for the tracking and analytics part. A narrow legitimate interest argument can be made for purely strictly necessary onboarding flows that block a feature until completed, but the safe default is consent.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers to the United States

Appcues is hosted on AWS in the United States. Transfers can rely on the EU-US Data Privacy Framework if Appcues remains certified, otherwise on Standard Contractual Clauses combined with a Transfer Impact Assessment. Enterprise customers can request EU residency, which routes traffic and storage through AWS EU regions.

How to deploy it compliantly

Sign the DPA, decide on EU residency if your audience justifies it, and disable Appcues until consent is captured. Minimise the user properties you pass: do not send special category data, restrict identifiers, and prefer hashed user IDs. Document the integration in your record of processing activities and explain Appcues in your privacy notice as a product adoption tool.

GDPR consent category

Other

Websites using Appcues must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for product analytics, legitimate interest possible only for strictly necessary onboarding flows
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, EU-US Data Privacy Framework, CCPA

DPIA considerations

A DPIA is recommended when Appcues tracks logged in users at scale, especially when user properties include sensitive attributes (plan, role, behaviour patterns). Document the SDK identifiers, retention, the EU-US Data Privacy Framework or SCC mechanism, and any EU residency arrangement obtained from Appcues.

Sample consent text

We use Appcues to guide you through new features and to measure how our product is used. Appcues sets identifiers in your browser and processes interactions on its servers in the United States. We only activate it after you accept the product experience category in our cookie banner.

Technical details

Tracking methodJavaScript SDK with first party cookies and localStorage, event collection over HTTPS to Appcues backend
Server locationUnited States (AWS us-east-1) with optional EU residency on request
Data transferred outside the EUAppcues is a US company hosted on AWS in the United States by default. Personal data, including user identifiers and event metadata, is transferred to the US. Transfers rely on the EU-US Data Privacy Framework (Appcues self-certified) or on Standard Contractual Clauses with a Transfer Impact Assessment.

Third-party domains contacted

fast.appcues.comapi.appcues.netevents.appcues.comstatics.appcues.com

Cookies placed

NameTypeDurationPurpose
_aciidhttp_cookie1 yearAnonymous Appcues identifier used to track a visitor before they are logged in or identified.
appcues:user_idlocalStoragePersistent until clearedStores the user ID provided to Appcues.identify so the SDK can match the visitor to their profile.
appcues:session_idlocalStorageSessionStores the current Appcues session identifier used to group events.
appcues:statelocalStoragePersistent until clearedStores in progress flow state (which step the user is on, dismissed flows, etc.).

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Appcues set?

Appcues mostly stores identifiers in localStorage (appcues:user_id, appcues:session_id, appcues:state) and may set an _aciid cookie for anonymous tracking before login. Storage entries can persist for years unless cleared.

Does Appcues require GDPR consent?

Yes for the analytics and personalisation parts. The SDK writes non strictly necessary identifiers, so prior consent is required under Article 5(3) ePrivacy. A narrow legitimate interest argument may cover purely strictly necessary onboarding flows.

What is the legal basis for processing?

Consent under Article 6(1)(a) GDPR for analytics and personalisation. Legitimate interest (Article 6(1)(f)) can be considered only for in app flows that are strictly necessary to deliver the product, with a documented balancing test.

Are data transferred outside the EU?

Yes. Appcues is hosted in the United States on AWS by default. Transfers can rely on the EU-US Data Privacy Framework or on SCCs with a TIA. Enterprise plans can include EU residency on request.

Do I need a DPIA?

A DPIA is recommended at scale or when user properties include sensitive attributes. Document the SDK identifiers, retention, US transfer mechanism, and the proportionality of using Appcues compared with self hosted alternatives.

How do I implement Appcues compliantly?

Sign the DPA, configure EU residency if available, gate the SDK behind consent, minimise user properties, never send special category data, and disclose Appcues in your privacy notice with retention and recipients.

Are there alternatives to Appcues?

Alternatives include Userflow, Userpilot, Chameleon, Pendo, Intro.js, Shepherd.js for open source tour flows, and Reactflow. Some of them offer EU hosting by default.

How do I update my cookie policy for Appcues?

Add an Appcues entry listing the localStorage keys and the _aciid cookie, with their purpose and lifetime. Mention the US transfer mechanism and the role of Appcues as a processor. Link to the Appcues privacy policy.