FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Userpilot

Userpilot

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Userpilot do?

Userpilot is a US based product adoption and user onboarding platform headquartered in Austin, Texas. SaaS companies install the Userpilot JavaScript snippet to identify logged in users, ship walkthroughs and tooltips, run NPS surveys, build resource centers and analyse feature adoption. The SDK sets first party cookies on the SaaS application and processes events on AWS US East, with EU residency in AWS Frankfurt available as a paid add on. Cookies and identifiers require consent in the EU.

What is Userpilot?

Userpilot is a product adoption platform incorporated as Userpilot Inc. in Austin, Texas. SaaS companies install the Userpilot JavaScript SDK in their application to deliver onboarding walkthroughs, tooltips, modals, banners, resource centers, NPS surveys and feature adoption analytics. Product teams configure user segments based on attributes (plan, MRR, persona) and events (signed up, completed onboarding) and ship in app experiences targeted at those segments.

Cookies and data collected

The Userpilot SDK writes first party cookies on the SaaS application (userpilot_visitor, userpilot_session) and a localStorage object that stores the Userpilot user ID, company ID, segments and the in app experiences already shown. The SDK transmits identify and track payloads (user attributes, events, screen) to api.userpilot.io. NPS responses, including free text, are stored on the same backend.

GDPR and ePrivacy implications

The Userpilot cookies and localStorage identifiers are not strictly necessary to deliver the SaaS service the customer pays for, so Art. 5(3) ePrivacy requires prior consent in the EU even for authenticated B2B users. The behavioural analytics processing can usually be grounded on B2B legitimate interest, with a documented LIA and a right to object. NPS surveys with free text fields should also be reviewed for sensitive content.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

By default Userpilot processes EU customer data on AWS US East. EU residency on AWS Frankfurt is available as an enterprise add on. Engineering teams in Egypt and the UK may access data under contract. The Userpilot DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and the UK IDTA, and Userpilot is self certified under the EU US Data Privacy Framework.

Practical compliance steps

Sign the Userpilot DPA, request EU residency if your plan allows it, gate the SDK behind a product analytics toggle in user settings or a CMP, list Userpilot in your privacy notice and Article 30 record, complete a DPIA covering NPS and in app nudges, document the US transfer with SCCs and DPF and offer customers a clear way to object to in app messages.

GDPR consent category

Other

Websites using Userpilot must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) for product analytics and in app onboarding on authenticated B2B users with a documented Legitimate Interest Assessment. Consent (Art. 6(1)(a) and Art. 5(3) ePrivacy) for the Userpilot cookies and localStorage on the SaaS application. Consent is also typically required for NPS surveys collecting free text or sensitive feedback.
Risk levelmedium
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, US CCPA/CPRA, SOC 2 Type II, ISO/IEC 27001

DPIA considerations

A DPIA is recommended when Userpilot is used at scale because it combines behavioural analytics, in app messaging, profile based segmentation and NPS feedback. The DPIA should cover cookies, free text NPS responses, the international transfer to the US and the right to object to in app nudges.

Sample consent text

We use Userpilot (Userpilot Inc., United States) to onboard new users, deliver walkthroughs and surveys and analyse feature adoption. Userpilot sets first party analytics cookies in our app and processes events on AWS US East. International transfers are covered by Standard Contractual Clauses and the EU US Data Privacy Framework.

Technical details

Tracking methodIn product user onboarding, product analytics and feature adoption platform: a JavaScript snippet loaded from js.userpilot.io / userpilot.io tracks authenticated SaaS users (identify and track API), renders walkthroughs, tooltips, modals, NPS surveys and resource centers; sets first party Userpilot session and visitor cookies on the SaaS application and stores events in localStorage when offline
Server locationUnited States (Userpilot Inc., Austin, Texas, headquarters); production hosted on AWS US East regions; EU data residency on AWS Frankfurt (eu central 1) is available as an enterprise paid add on; engineering presence in Egypt and the United Kingdom
Data transferred outside the EUUserpilot Inc. is established in the United States. By default, EU customer data is processed on AWS US East. EU data residency on AWS Frankfurt is available as an enterprise add on. The Userpilot DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and the UK International Data Transfer Addendum, and Userpilot is self certified under the EU US Data Privacy Framework.

Third-party domains contacted

userpilot.iojs.userpilot.ioapi.userpilot.ioapp.userpilot.io

Cookies placed

NameTypeDurationPurpose
userpilot_visitorfirst_party1 yearUserpilot long lived visitor identifier used to recognise the same user across visits and to attribute events to the right Userpilot contact.
userpilot_sessionfirst_party30 minutesUserpilot session identifier used to mark which onboarding session the current page view belongs to.
Userpilot.userIdfirst_partyPersistent (localStorage)localStorage key holding the Userpilot user identifier for the logged in SaaS user, used to deliver targeted in app experiences.
Userpilot.completedFlowsfirst_partyPersistent (localStorage)localStorage object tracking which onboarding flows the user has already completed or dismissed to avoid showing them again.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Userpilot set?

The Userpilot SDK writes first party cookies on the SaaS application (userpilot_visitor, userpilot_session) and a localStorage object that stores the Userpilot user ID, company ID, segment membership and the in app experiences already shown to the user.

Do I need consent to use Userpilot?

Yes for the cookies and localStorage identifiers under Art. 5(3) ePrivacy, even for authenticated B2B users. The behavioural analytics processing can be supported by B2B legitimate interest with a documented LIA. NPS free text fields may also need an explicit warning.

What is the legal basis for using Userpilot?

Legitimate interest (Art. 6(1)(f) GDPR) for product analytics on authenticated B2B users with a documented LIA. Consent (Art. 6(1)(a) and Art. 5(3) ePrivacy) for cookies and localStorage. Contract performance (Art. 6(1)(b)) for onboarding flows directly required to use the SaaS.

Does Userpilot transfer data to third countries?

Yes. By default Userpilot processes EU customer data on AWS US East. EU residency on AWS Frankfurt is available as an enterprise add on. Engineering teams in Egypt and the UK may access data under contract. Transfers are covered by the EU SCCs, the UK IDTA and the EU US Data Privacy Framework.

Do I need a DPIA for Userpilot?

Yes when Userpilot is used at scale, because it combines systematic monitoring, profiling and automated in app nudges. The DPIA should cover cookies, NPS free text, the US transfer and the right to object to in app experiences.

How do I implement Userpilot compliantly?

Sign the Userpilot DPA, request EU residency if your plan allows it, gate the SDK behind a product analytics toggle, list Userpilot in your privacy notice and Article 30 record, complete a DPIA, document the US transfer with SCCs and DPF and offer a clear opt out for in app messages.

Are there alternatives to Userpilot?

Alternatives include Appcues (US with DPF), Pendo (US with EU residency, see our dedicated page), Chameleon (US), WalkMe (US with EU residency), Whatfix (India and US), Userflow (Denmark, EU friendly), Userlist and Customer.io for messaging based onboarding.

How should I update my cookie and privacy policy for Userpilot?

List the userpilot_visitor and userpilot_session cookies and the localStorage object in your cookie policy under product analytics. In your privacy notice describe Userpilot as your onboarding and product analytics processor, the US storage on AWS, the SCCs and DPF, the EU residency option and the customer's right to object to profiling.