Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Olark is a US live chat platform operated by Habla Inc. Its JavaScript widget injects a chat box on the publisher site and sets first party cookies for session continuity. Used by European SMEs, online services and SaaS to qualify leads and answer customer questions in real time.
Olark is a live chat platform operated by Habla Inc., headquartered in Ann Arbor, Michigan. The product targets SMEs, online services and B2B SaaS that need a lightweight chat widget with rules based proactive messages, agent inboxes, transcripts and integrations with HubSpot, Salesforce, Mailchimp and the Olark API.
The Olark widget sets several first party cookies on the publisher domain: olark-state (chat state), hblid (visitor identifier), wcsid (session identifier) and _okbk (preference snapshot). It also opens a WebSocket and XMPP connection to api.olark.com to relay messages in real time.
Habla Inc. acts as a processor under Article 28 GDPR. The widget cookies are dropped before any visitor interaction, so they fall outside the strictly necessary exemption of Article 5(3) ePrivacy. The CNIL, the DSK and the AEPD have explicitly warned that auto loaded chat widgets require consent.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Prior, freely given, specific, informed and unambiguous consent is required before the Olark loader (static.olark.com/jsclient/loader.js) executes. A consent management platform should withhold the script tag until the visitor accepts the functional category. Olark also offers an API method to delete the cookies and end the session, useful when consent is later withdrawn.
Habla Inc. processes data on AWS us-east-1. Olark self certifies under the EU US Data Privacy Framework. Standard Contractual Clauses are included in the Olark DPA. Document this transfer in the record of processing activities and inform visitors in the privacy notice.
Sign the Olark DPA, gate the chat widget behind a consent management platform, list olark-state, hblid, wcsid and _okbk in the cookie policy, document the US transfer under the EU US Data Privacy Framework, configure transcript retention to match your SLAs, mask sensitive fields in pre chat surveys and offer an alternative contact method for visitors who refuse consent.
Websites using Olark must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is not generally required for Olark at SME scale. It becomes recommended when the chat box collects pre chat surveys with sensitive data, when Olark is integrated with CRM systems for visitor profiling, or when the publisher is in a regulated sector (health, finance).
Sample consent text
We use Olark to offer live chat on this website. Olark sets first party cookies (olark-state, hblid, wcsid) on your browser to keep your conversation context. The chat widget is loaded only with your consent. You can still contact us by email if you prefer not to enable chat cookies.
Third-party domains contacted
olark.comstatic.olark.comlogs.olark.comrt.olark.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| hblid | http | 12 months | Habla long term visitor identifier used by Olark to recognise returning visitors across sessions. |
| olfsk | http | 12 months | Olark follow up cookie used to maintain the chat operator pairing across pages. |
| _okdetect | http | Session | Detects whether Olark is enabled on the page and stores temporary widget state. |
| _ok | http | Session | Olark visitor session cookie used to maintain the active chat state during the visit. |
| _okbk | http | Session | Backup state cookie used by Olark to restore the chat session if the page reloads. |
Olark uses cookies for user preferences — inform visitors with a consent banner.
The Olark widget sets olark-state (chat state), hblid (visitor identifier), wcsid (session identifier) and _okbk (preference snapshot) as first party cookies under the publisher domain.
Yes. The Olark widget cookies are dropped before any visitor interaction, outside the strictly necessary exemption. Prior, freely given, specific, informed and unambiguous consent under Article 5(3) ePrivacy is required before the Olark loader executes.
The Olark widget cookies rely on Article 6(1)(a) GDPR consent. Habla Inc. acts as a processor under Article 28 GDPR for ticket and transcript data. The customer relationship and operational metrics rely on contract and legitimate interest.
Yes. Habla Inc. is established in the United States and processes data on AWS us-east-1. Olark self certifies under the EU US Data Privacy Framework. Standard Contractual Clauses are included in the Olark DPA as an additional safeguard.
A DPIA is not required for Olark at SME scale. It becomes recommended when pre chat surveys collect sensitive data, when chat is integrated with CRM for profiling, or when the publisher operates in a regulated sector such as healthcare or finance.
Sign the Olark DPA, gate the chat widget behind a consent management platform, list olark-state, hblid, wcsid and _okbk in the cookie policy, document the US transfer, configure transcript retention to match your SLAs, mask sensitive fields in pre chat surveys and offer an alternative contact method.
EU based live chat alternatives include Crisp (France), Userlike (Germany), LiveAgent (Slovakia), Tidio (Poland), HelpCrunch (EU regions) and self hosted Chatwoot. All require their own cookie and consent assessment.
List olark-state, hblid, wcsid and _okbk with name, domain, duration and purpose in your cookie policy. Disclose the third country transfer to the United States and the EU US Data Privacy Framework certification, and link to the Olark privacy notice.