Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Smallchat is a live chat widget that connects a website chat box to a Slack workspace, letting a team answer visitor messages directly from Slack.
Smallchat is a hosted live chat widget that connects a chat box on your website to a Slack workspace. When a visitor opens the widget and sends a message, that conversation appears as a thread inside Slack, where your team replies. To the visitor it feels like an ordinary website chat, while your team answers from a tool they already use every day.
You add Smallchat to your site with a single embed script. The script loads the chat box, styles it to match your brand and links each conversation to a Slack thread. Smallchat is a US based product, and Slack, which receives the messages, is also operated from the United States. Because the widget runs in the visitor browser and exchanges data with these external services, it is a third party processor that you need to describe in your privacy documentation.
Smallchat sets cookies in the visitor browser to keep the chat session active and to recognise a returning visitor, so a conversation can continue across pages and visits. It collects the messages a visitor types and any contact information they choose to enter, such as a name or email address. This content flows into Slack, where each conversation becomes a thread, and it can be exported to a CSV file. All of this is personal data when it relates to an identifiable visitor.
Under the GDPR you are the controller for the chat data you collect, while Smallchat and Slack act as processors. You need a lawful basis, a clear privacy notice and an agreement that governs the processing. The ePrivacy Directive adds a separate rule about storing and reading cookies. A cookie that is strictly necessary to run a chat the visitor has just started can be set without prior consent, but any cookie that loads before the visitor interacts, or that serves analytics or marketing, requires consent first.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The cleanest approach is to load Smallchat only after the visitor chooses to chat, or after they accept it through your consent banner. Handling the live conversation itself can usually rely on legitimate interest, because the visitor asked to talk to you. Consent is the right basis for any non essential cookie or analytics feature placed before that interaction. Whichever path you take, make it easy to refuse, and record what the visitor agreed to.
Because Smallchat and Slack are operated from the United States, chat data about EU and EEA visitors is transferred outside the European Economic Area. These transfers should rely on a recognised safeguard, typically the EU US Data Privacy Framework where the providers are certified, supported by Standard Contractual Clauses. Name these transfers in your privacy notice, explain that messages reach a US workspace, and keep a short note of the safeguards you depend on.
List Smallchat and Slack in your records of processing and your cookie policy, including the chat cookies and their purpose. Sign the relevant data processing terms, set a retention period for chat transcripts and visitor exports, and delete data you no longer need. Tell visitors before they share information that their messages go to your team in Slack, and respect access and deletion requests across both the widget and the Slack workspace.
Websites using Smallchat must obtain user consent under GDPR regulations.
DPIA considerations
Smallchat collects visitor chat messages and any contact details entered, and forwards them to Slack in the United States, so a record of processing and a transfer assessment are advisable. A full DPIA is usually not mandatory for a standard support widget, but it is recommended where chat content may reveal sensitive information or where visitors are profiled. Document retention periods, the legal basis and the safeguards used for the US transfer.
Sample consent text
We use Smallchat to run our website chat, which sets a chat cookie and sends your messages to our team in Slack in the United States; please accept before starting a conversation.
Third-party domains contacted
small.chatslack.comslack-edge.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| sc_session | Necessary | Session | Keeps the live chat session active so an ongoing conversation continues while the visitor moves between pages. |
| sc_visitor_id | Necessary | 1 year | Stores a visitor identifier so a returning visitor is recognised and their previous conversation can be linked. |
| sc_widget_state | Functional | 30 days | Remembers whether the chat box is open or closed and other widget display preferences across visits. |
Smallchat uses cookies for user preferences — inform visitors with a consent banner.
Smallchat sets cookies in the visitor browser to keep the chat session active and to recognise a returning visitor, so a conversation can continue across pages and visits. These first party cookies hold a session identifier and a visitor identifier. List them and their purpose in your cookie policy.
You need consent for any cookie that loads before the visitor interacts or that is not strictly necessary, in line with the ePrivacy Directive. A cookie that is strictly necessary to run a chat the visitor has just opened can be set without prior consent. The cleanest approach is to load the widget only after the visitor chooses to chat or accepts it in your banner.
Handling a chat the visitor started can usually rely on legitimate interest under Art. 6(1)(f) GDPR, because the visitor asked to talk to you. Any non essential chat or analytics cookie loaded before interaction needs consent under Art. 6(1)(a) GDPR. Record which basis applies to each purpose in your documentation.
Yes. Smallchat is US based and sends each conversation into Slack, which is also operated from the United States, so data about EU and EEA visitors is transferred outside the European Economic Area. These transfers should rely on the EU US Data Privacy Framework where the providers are certified, supported by Standard Contractual Clauses. Name the transfers in your privacy notice.
A full DPIA is usually not mandatory for a standard support chat widget, but it is recommended where chat content may reveal sensitive information or where visitors are profiled. At a minimum, keep a record of processing and a short transfer assessment. Document retention periods, the legal basis and the safeguards used for the US transfer.
Load the widget only after the visitor chooses to chat or accepts your consent banner, and disclose Smallchat and Slack in your privacy notice and cookie policy. Sign the relevant data processing terms, set a retention period for transcripts and visitor exports, and delete data you no longer need. Make it easy to refuse non essential cookies.
Yes. Other Slack connected chat tools and standalone live chat widgets exist, and some offer EU hosting or stricter cookie controls. If transfers to the United States are a concern, look for a provider with EU based servers or a cookieless mode. Whichever tool you choose, check its data location, cookies and processing terms.
Add an entry for Smallchat that lists the chat session and visitor identifier cookies, their duration and their purpose. Explain that messages and any contact details are sent to Slack in the United States, and link to the relevant privacy and processing terms. Review the entry whenever Smallchat changes the cookies it sets.