Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Userflow is a European product onboarding and in app guidance platform, based in Copenhagen, Denmark, that teams embed in their web application to build no code onboarding flows, checklists, tooltips, banners and surveys. Once installed it identifies each user, records which flows and steps they have seen, tracks flow progress and completion and captures product usage events, so it reads and writes cookies and localStorage on the user device. Because this behavioural product analytics is not strictly necessary, Userflow should load only after the user has given consent.
Userflow is a product onboarding and in app guidance platform based in Copenhagen, Denmark, inside the European Union. It lets product and growth teams build onboarding flows, checklists, tooltips, banners and surveys without code and show them to users directly inside a web application. Userflow runs as a JavaScript snippet that loads its code from Userflow servers and renders its guidance on top of the host application.
Once Userflow is installed, it identifies each user, either with an identifier that your application passes to userflow.identify or with an anonymous identifier that Userflow generates and stores in browser localStorage. It records which flows and steps the user has seen, tracks flow progress and completion and captures product usage events and user attributes. To do this it reads and writes cookies and localStorage on the user device, and it can forward the resulting events to connected analytics and messaging tools.
The identifiers and product usage events that Userflow processes are personal data under the GDPR, because they relate to an identifiable user. Storing and reading identifiers on the user device also falls within Article 5(3) of the ePrivacy Directive, which the CNIL in France under the TDDDG, the German authorities under the TDDDG and the AEPD in Spain all enforce as a strict prior consent obligation for non essential trackers.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before the non essential analytics layer of Userflow runs, because behavioural product analytics is not strictly necessary to deliver the service the user asked for. That consent must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as to accept. Until the user accepts, the tracking should not run and no non essential cookies or localStorage entries should be written. Guidance that is strictly necessary for an authenticated user may rely on a separate basis, but the analytics and profiling functions need consent.
Userflow ApS is established in the European Union, which reduces but does not remove transfer risk. Userflow hosts production data on Google Cloud Platform and relies on further subprocessors for hosting, analytics and support, some of which are established in the United States. Where a subprocessor processes European user data in the United States, the transfer requires the EU Standard Contractual Clauses within the Userflow Data Processing Addendum and a documented Transfer Impact Assessment in line with the Schrems II ruling. Because the position depends on the current subprocessor list, confirm each subprocessor and its region before you rely on Userflow.
Gate the Userflow analytics behind your consent management platform so that non essential tracking fires only after the relevant category is accepted. Describe Userflow in your cookie policy, including the identifiers it sets and their lifetime. Sign the Userflow Data Processing Addendum, review the subprocessor list, complete a Transfer Impact Assessment where United States processing applies and apply the shortest workable retention on user records. Pass only the user attributes you genuinely need through userflow.identify to minimise the personal data collected.
Websites using Userflow must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is advisable when Userflow is used at scale to profile users or to combine product usage with account identifiers. Document the behavioural analytics collected by the embed, the identifiers stored in cookies and localStorage, the user attributes sent through userflow.identify, the forwarding of events to connected analytics and messaging tools, any transfer to United States subprocessors and the retention period applied to user records. Configure the embed so that non essential analytics load only after consent and pass only the attributes you genuinely need.
Sample consent text
We use Userflow, a product onboarding service operated by Userflow ApS (Denmark), to guide you inside our application. Userflow identifies you, records which onboarding steps you have seen and stores identifiers in cookies and localStorage on your device. This data is hosted in the European Union and may be processed by subprocessors in the United States under the EU Standard Contractual Clauses. Userflow analytics will only load if you click Accept.
Third-party domains contacted
userflow.comjs.userflow.comapi.userflow.come.userflow.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| userflow.userId | localStorage | Persistent (until cleared) | Stores the user identifier, either supplied by the host application through userflow.identify or generated by Userflow as an anonymous identifier, so that a returning user is recognised and usage is attributed to a single profile. |
| userflow_session | HTTP cookie (first party) | Session | Holds the current session, set with the secure flag, so that flow interactions and product usage events are grouped together during a single visit. |
| userflow.flowState | localStorage | Persistent (until cleared) | Stores which onboarding flows and steps the user has seen and the current progress, so that a flow can resume where the user left off and completed flows are not shown again. |
| userflow.events | localStorage | Persistent (until cleared) | Buffers product usage events, such as steps viewed, clicks and completions, before they are sent to the Userflow ingestion endpoints. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
Userflow stores a user identifier that is either supplied by your application or generated by Userflow and kept in browser localStorage, along with localStorage entries that hold flow progress and buffered usage events, and it can set a first party session cookie with the secure flag. Together they let Userflow recognise the user and record which flows and steps have been seen.
For the non essential analytics you do. Userflow performs behavioural product tracking and writes identifiers to the user device, so under the ePrivacy rules you must obtain prior consent before that layer runs. The tracking should stay blocked until the user accepts, even though strictly necessary guidance for a logged in user may rest on a separate basis.
The valid legal basis for the non essential analytics is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. Legitimate interest cannot be used for behavioural product analytics and profiling, although strictly necessary in app guidance may rely on a separate basis.
Userflow is based in the European Union and hosts data on Google Cloud Platform, but it uses subprocessors, some of which are in the United States. Where United States processing applies you need the EU Standard Contractual Clauses in the Userflow Data Processing Addendum and a Transfer Impact Assessment, so check the current subprocessor list before deployment.
A Data Protection Impact Assessment is recommended when Userflow is used at scale to profile users or to combine product usage with account identifiers. Assess the behavioural tracking, the identifiers stored on the device, the user attributes sent through userflow.identify and any transfer to United States subprocessors.
Load the non essential analytics only through your consent management platform after the relevant category is accepted, describe Userflow in your cookie policy, sign the Data Processing Addendum and complete a Transfer Impact Assessment where United States processing applies. Pass only the attributes you need through userflow.identify and apply a short retention period.
Alternatives include Appcues, Pendo, Chameleon, Intro.js and WalkMe. They raise similar consent, cookie and transfer questions, so evaluate their hosting location and data processing terms before assuming any of them is lighter on privacy.
Add a dedicated entry that names Userflow ApS as the provider, lists the user and session identifiers with their lifetimes, explains the product usage analytics collected, and discloses the European Union hosting and any United States subprocessors with their safeguard. Keep the entry in step with your consent categories.