Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Spatie Support Bubble is an open source Laravel package developed by the Belgian agency Spatie. It adds a small bubble in the corner of a website that lets visitors send short feedback messages. Everything runs inside the operator's own Laravel application: no third party server, no tracking cookies, no scripts loaded from external domains. For EU operators, this makes it a very low risk component under GDPR and ePrivacy, since Spatie itself never receives end user data.
Spatie Support Bubble is an open source Laravel package developed by Spatie, an Antwerp based agency well known in the Laravel ecosystem. It adds a small floating bubble in the corner of a website. Visitors click the bubble to send a short feedback message that flows into the operator''s own database. The package is MIT licensed and is hosted in the operator''s Laravel application, with no calls to Spatie servers.
Feedback text typed by the visitor, the page URL, and any additional context the operator decides to capture (authenticated user identifier, language, environment metadata). The operator decides what is stored and where.
No tracking cookies are set, no third party scripts are loaded, no data leaves the operator''s infrastructure. Article 5(3) ePrivacy does not require consent. GDPR transparency obligations still apply: tell users in the privacy notice that feedback collected through the bubble is stored and reviewed, and document the retention period.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
No prior consent is required to display the bubble. Submitting feedback is itself an explicit user action. Keep the form short and remind the user not to include sensitive personal data, and offer a link to the privacy notice next to the submit button.
The Spatie Support Bubble does not send anything to Spatie or to any third country by itself. The international transfer dimension depends entirely on where the operator hosts the Laravel application. EU operators using EU hosting have no transfer to disclose.
Add a privacy notice paragraph for the feedback bubble, set a retention period on stored feedback (e.g. delete after 12 months), restrict access to the feedback dashboard, and review whether any sensitive content received should be redacted. Pin the package version and read the changelog before upgrading.
Websites using Spatie Support Bubble must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is not required for the Spatie Support Bubble itself. It can be appropriate if feedback contains sensitive content (medical complaints, accident reports) or if the operator enriches messages with significant personal data such as IP or session replays.
Sample consent text
Our website includes a small feedback bubble built with the open source Spatie Support Bubble package. Feedback you send is processed only on our own servers. No third party tracking, no cookies and no consent is required for the bubble itself.
Third-party domains contacted
spatie.begithub.com/spatie/laravel-support-bubbleSpatie Support Bubble uses cookies for user preferences — inform visitors with a consent banner.
None by default. The package is a small Vue/Livewire component that posts feedback directly to the operator's Laravel application. The session cookie used by Laravel itself is strictly necessary and not specific to the Support Bubble.
No. No information is stored on the device beyond what is strictly necessary, and no third party is involved. Article 5(3) ePrivacy does not require consent.
Legitimate interest of the operator in collecting feedback to improve the service, combined with the user's own explicit action when submitting feedback. Transparency under articles 13 and 14 GDPR remains mandatory.
By default no. Feedback stays on the operator's server. International transfer depends solely on where the operator hosts the Laravel application.
Not for the package itself. A DPIA can be appropriate when feedback collected may include sensitive content (medical complaints, accident reports) or when the operator pairs feedback with other identifiers at scale.
Mention the bubble in the privacy notice, define a retention period, restrict access to feedback dashboards, advise users not to share sensitive personal data through the bubble, pin the package version and follow Spatie's security updates.
Alternatives include Userback (Australia), Feedbear, Frill, Canny, Sleekplan, native HelpScout or Intercom widgets, and other open source widgets such as a simple Laravel form. EU hosted or self hosted options minimise transfer risk.
You normally do not list the Spatie Support Bubble in the cookie policy because no tracking cookies are set. Add a privacy notice section explaining that feedback is collected and how it is processed.