FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Customer Support
  4. Kustomer

Kustomer

PreferencesWebsite

Related services

11Sight

11Sight is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 11Sight supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 11Sight ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

42Chat

42Chat is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42Chat integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42Chat helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

8x8

8x8 is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 8x8 supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 8x8 ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences
A

Acquire Live Chat

Acquire Live Chat is a live chat and customer messaging platform that enables businesses to engage with website visitors in real time. It provides instant messaging, chatbot automation, and team collaboration tools to deliver fast, personalized customer support. Acquire Live Chat supports multi-channel communication, conversation routing, and canned responses to improve response times. With built-in analytics and CRM integration, Acquire Live Chat helps convert visitors into customers.

Preferences

ActivEngage

ActivEngage is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. ActivEngage integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, ActivEngage helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

Ada

Ada is a web accessibility solution that helps websites comply with ADA, WCAG, and accessibility standards. It provides automated scanning, remediation tools, and compliance monitoring to ensure content is accessible to all users, including those with disabilities. Ada offers screen reader optimization, keyboard navigation support, and color contrast adjustment. With regular audits and reporting, Ada helps create inclusive digital experiences for everyone.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Kustomer do?

Kustomer is a customer service CRM owned by Meta that powers chat, email and social support through an embeddable widget and unified inbox.

What is Kustomer

Kustomer is a customer service CRM founded in New York and acquired by Meta in 2022. It unifies chat, email, social and voice support around a customer timeline, and offers AI assistance, intent detection and self service. Kustomer is embedded into websites via a JavaScript chat widget and integrates with Meta channels including Messenger, Instagram and WhatsApp Business.

What cookies and data Kustomer collects

The Kustomer chat widget writes cookies such as kustomer-session-id, kustomer-client-id and kustomer-visitor-id, plus localStorage entries for the conversation state. Kustomer receives the visitor IP, the page URL, the chat content, attached files, the authenticated identifier if you provide one and any customer attribute pushed through the SDK. Voice and integrated WhatsApp data feeds the same customer timeline.

GDPR and ePrivacy implications

Loading the chat widget writes to the user device, so Article 5(3) of the ePrivacy Directive requires consent on public pages. Chat content and customer attributes are personal data under the GDPR. The Meta ownership materially raises the Schrems II risk: even if the Kustomer instance is in the EU, the Meta group may access data from the US under US surveillance laws.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and legal basis

Public widget: consent before loading. Authenticated support inside a paid product: contract performance for the helpdesk function. Marketing automation features such as proactive prompts based on browsing behaviour require a separate consent purpose. Inform users that Kustomer is part of Meta and that data flows through US infrastructure.

Data transfers and hosting

Kustomer runs on AWS with US default regions. EU residency on AWS Ireland or Frankfurt is contractually possible and recommended for EU operators. Even with EU residency, support and administrative access by Meta personnel in the US triggers transfer rules. Cover transfers with the EU US Data Privacy Framework and Standard Contractual Clauses; sign the Kustomer/Meta data processing addendum.

Practical compliance steps

Pick EU residency, run a thorough transfer impact assessment given the Meta ownership, document the data flows, mask sensitive identifiers (card numbers, IDs) in transcripts, restrict access to administrative dashboards, set short retention on chat conversations, and offer customers a clear way to request deletion of their timeline.

GDPR consent category

Preferences

Websites using Kustomer must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) when used on a public site; contract performance (Art. 6(1)(b) GDPR) for authenticated customer support inside a paid product
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, EU US Data Privacy Framework, Schrems II considerations (Meta ownership)

DPIA considerations

A DPIA is strongly recommended given the Meta ownership: chat transcripts, customer attributes and conversation history can be enriched with cross context data, which heightens risk under GDPR and Schrems II.

Sample consent text

We use Kustomer (owned by Meta) for customer support. Kustomer writes cookies on your device, processes your messages and IP address, and shares them with Kustomer Inc. and Meta Platforms in the United States. We only load the widget if you accept.

Technical details

Tracking methodJavaScript widget loading the Kustomer chat iframe and tracking events through the Kustomer Chat SDK and APIs
Server locationUnited States (Kustomer Inc., New York), now owned by Meta, with optional EU residency on AWS EU regions
Data transferred outside the EUKustomer Inc. is a US company owned by Meta Platforms Inc. EU residency is available on AWS EU regions but the parent group is US headquartered and may access data from the US for support. Transfers rely on the EU US Data Privacy Framework and the Kustomer/Meta Standard Contractual Clauses.

Third-party domains contacted

kustomerapp.comcdn.kustomerapp.comapi.kustomerapp.comkustomer.com

Cookies placed

NameTypeDurationPurpose
kustomer-session-idthird_partysessionSession identifier for the Kustomer chatter
kustomer-client-idthird_party1 yearAnonymous client identifier across visits
kustomer-visitor-idthird_party1 yearVisitor identifier used to thread conversations

Kustomer uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Kustomer set?

Kustomer writes kustomer-session-id, kustomer-client-id and kustomer-visitor-id, plus localStorage entries for the chat state. Authenticated portals add a session cookie scoped to the customer subdomain.

Is consent required for Kustomer?

On public pages, yes. The widget writes to the user device and processes personal data; Article 5(3) ePrivacy applies. Authenticated customer support inside a paid product runs on contract performance.

Which GDPR legal basis applies?

Consent for public widgets and proactive marketing prompts. Contract performance for authenticated helpdesk. Sensitive data requires Art. 9 GDPR. Always disclose Meta ownership.

Are there transfers to the United States?

Yes. Even with EU residency on AWS, Meta personnel can access data from the US. Cover transfers with the EU US Data Privacy Framework, Standard Contractual Clauses and a transfer impact assessment, with a heightened scrutiny because of Meta.

Do I need a DPIA?

Strongly recommended given Meta ownership, broad data integration (Messenger, Instagram, WhatsApp) and AI assistance features.

How do I implement Kustomer compliantly?

Pick EU residency, run a robust transfer impact assessment, segment consent purposes (chat versus marketing), mask sensitive content in transcripts, set short retention, restrict admin access and document the joint controller boundary with Meta.

Are there alternatives to Kustomer?

For customer service CRM, EU alternatives include Zendesk EU residency, Freshdesk EU, Intercom EU pod, Help Scout EU, Sellsy (France), Crisp (France), and self hosted options like Chatwoot.

How do I update my cookie policy for Kustomer?

List the kustomer cookies (session, client, visitor identifiers) and localStorage entries. State that Kustomer is part of Meta and that the EU US Data Privacy Framework covers the transfer.