Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
LiveChat is a Polish live chat and customer messaging platform operated by Text S.A. The JavaScript widget injects a chat box on the publisher site and sets first party cookies for session continuity. Used by European ecommerce, SaaS and online services to qualify leads and provide real time support.
LiveChat is a customer messaging platform operated by Text S.A., a publicly listed Polish company based in Wroclaw. The flagship product is a JavaScript chat widget; the broader Text suite also includes HelpDesk, ChatBot, KnowledgeBase and OpenWidget. European ecommerce, SaaS and online services use LiveChat for real time sales conversations and customer support.
The LiveChat widget sets __lc_cid (visitor identifier, 2 years), __lc_cst (session secret, 2 years), __livechat_lastvisit and __livechat as first party cookies under the publisher domain. It also opens a WebSocket connection to api.livechatinc.com for real time messaging and stores conversation state in localStorage.
Text S.A. acts as a processor under Article 28 GDPR for the chat transcripts, agent identifiers and visitor profile data. The widget cookies are non strictly necessary because they are dropped before any visitor interaction. The CNIL, the DSK and the Polish UODO all require prior consent under Article 5(3) ePrivacy for auto loaded chat widgets.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A consent management platform should hold back the LiveChat loader (cdn.livechatinc.com/tracking.js) until the visitor accepts the functional category. LiveChat exposes the LC_API JavaScript API which can pause or resume tracking, useful when consent is withdrawn. For low traffic SME publishers, LiveChat can also be configured to load only on dedicated support pages where consent is implicit.
Text S.A. is established in Poland (EEA) and processes data on AWS infrastructure with primary regions in Europe (eu-central-1 Frankfurt). The Text S.A. DPA confirms that personal data of EEA visitors stays within the EEA. Customer support engagement may occasionally involve US based subcontractors, covered by Standard Contractual Clauses in the DPA.
Sign the Text S.A. DPA, gate the LiveChat widget behind a consent management platform, list __lc_cid, __lc_cst, __livechat_lastvisit and __livechat in the cookie policy, document the EEA processing, configure transcript retention to match your SLAs, mask sensitive pre chat fields and apply the LC_API consent gate when applicable.
Websites using LiveChat must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is not generally required for LiveChat because data stays inside the EEA and the volume of personal data per chat is small. A DPIA becomes recommended when the chat collects pre chat surveys with sensitive data, when LiveChat is integrated with HelpDesk and ChatBot for automated triage, or in regulated sectors.
Sample consent text
We use LiveChat (operated by Polish company Text S.A.) for live chat support. The widget sets first party cookies (__lc_cid, __lc_cst) on your browser to keep your conversation state. Data is processed within the EEA. The chat widget is loaded only with your consent.
Third-party domains contacted
livechatinc.comlivechatinc.comcdn.livechatinc.comlivechat.comapi.livechatinc.comaccounts.livechat.comsecure.livechatinc.comcdn.livechatinc.comsecure.livechat.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| __lc_cid | http | 2 years | LiveChat client identifier used to recognise the visitor across sessions and stitch chats together. |
| __lc_cid | Functional | 3 years | LiveChat visitor identifier set on the publisher domain to recognise returning chatters across sessions. |
| __lc_cst | http | 2 years | LiveChat client session timestamp used to maintain the chat continuity across page reloads. |
| __lc_cst | Functional | 3 years | LiveChat security token bound to the visitor identifier to protect against session hijacking. |
| __lc2_cid | Functional | 2 years | LiveChat v2 visitor identifier for the newer LiveChat SDK. |
| __livechat | http | Session | General LiveChat state cookie used to track the widget status and the current chat in progress. |
| __livechat_lastvisit | http | 2 years | Records the last visit timestamp to differentiate first time and returning visitors in LiveChat analytics. |
| __lc2_cst | Functional | 2 years | LiveChat v2 security token bound to __lc2_cid. |
| __livechat | Functional | 3 years | LiveChat session marker set on livechatinc.com that flags an active chat conversation. |
| __lc_visitor_id | Functional | 3 years | LiveChat visitor identifier on livechatinc.com used to maintain agent routing affinity. |
LiveChat uses cookies for user preferences — inform visitors with a consent banner.
LiveChat sets first party cookies on the publisher domain (__lc_cid, __lc_cst, __lc2_cid, __lc2_cst) and third party cookies on livechatinc.com (__livechat, __lc_visitor_id, AWSALB session affinity). They store the visitor identifier, the chat continuity token and the agent routing state.
The widget sets __lc_cid (visitor identifier, 2 years), __lc_cst (session secret, 2 years), __livechat_lastvisit and __livechat as first party cookies under the publisher domain. The conversation state is also kept in localStorage.
Persistent LiveChat cookies (visitor identification, history retrieval) are not strictly necessary and require consent under article 5(3) ePrivacy. A minimal session only chat that does not store identifiers can be loaded without consent.
Yes. The widget cookies are non strictly necessary because they are dropped before any visitor interaction. Prior, freely given, specific, informed and unambiguous consent under Article 5(3) ePrivacy is required before the LiveChat loader executes.
Performance of a contract for the chat conversation itself. Legitimate interest for limited fraud prevention. Consent for persistent cookies, marketing follow up and integration with CRM lead enrichment.
Widget cookies rely on Article 6(1)(a) GDPR consent. The agent inbox processing relies on Article 6(1)(b) GDPR (contract) for the customer relationship and Article 6(1)(f) GDPR (legitimate interest) for fraud prevention and service operations.
LiveChat hosts customer data on AWS in Frankfurt and Dublin. EU customer data normally stays in the EEA. Some sub processors may operate under EU SCCs. Verify the Text S.A. sub processor list before assuming pure EU residency.
Not by default. Text S.A. is established in Poland (EEA) and processes data on AWS infrastructure with European primary regions. The Text S.A. DPA confirms EEA data residency. Occasional support engagement may involve US subcontractors, covered by Standard Contractual Clauses.
A DPIA is recommended for AI chatbot deployments, when transcripts are retained beyond 12 months, when chat data feeds a US based CRM, or when the chat handles sensitive topics (health, legal, financial advice).
A DPIA is not generally required for LiveChat because data stays inside the EEA and the volume of personal data per chat is small. It becomes recommended when pre chat surveys collect sensitive data, when LiveChat is paired with ChatBot for automated triage, or in regulated sectors.
Decide between persistent and session only chat. Block persistent cookies behind your CMP. Define a transcript retention policy and document it. Sign the Text S.A. DPA with EU SCCs for non EU sub processors. Use the Personal Data Eraser to honour Erasure requests.
Sign the Text S.A. DPA, gate the LiveChat widget behind a consent management platform, list __lc_cid, __lc_cst and __livechat cookies in the cookie policy, document the EEA processing, configure transcript retention, mask sensitive pre chat fields and apply the LC_API consent gate.
European live chat alternatives include Crisp (France), Userlike (Germany), LiveAgent (Slovakia), Tidio (Poland, same regulatory environment), HelpCrunch (EU regions), Smartsupp (Czech Republic) and self hosted alternatives such as Chatwoot.
Crisp (Nantes, EU), Userlike (Cologne, EU), Tidio (Polish, similar profile), Chatwoot (open source self hosted), Smartsupp (Czech), Front (US), Intercom (US), Zendesk (US) or Help Scout (US) for higher feature counts at the cost of more complex transfers.
List the __lc_cid, __lc_cst, __lc2_cid, __lc2_cst first party cookies and the third party cookies on livechatinc.com with domain, duration and purpose. Identify Text S.A. as processor in the privacy notice. Note the EU hosting and describe any sub processor transfers.
List __lc_cid, __lc_cst, __livechat_lastvisit and __livechat with name, domain, duration and purpose. State the EEA data residency, identify Text S.A. as the processor, document the localStorage usage and link to the LiveChat privacy notice.