FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Customer Support
  4. Tidio

Tidio

PreferencesWebsite

Related services

11Sight

11Sight is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 11Sight supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 11Sight ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

42Chat

42Chat is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42Chat integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42Chat helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

8x8

8x8 is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 8x8 supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 8x8 ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences
A

Acquire Live Chat

Acquire Live Chat is a live chat and customer messaging platform that enables businesses to engage with website visitors in real time. It provides instant messaging, chatbot automation, and team collaboration tools to deliver fast, personalized customer support. Acquire Live Chat supports multi-channel communication, conversation routing, and canned responses to improve response times. With built-in analytics and CRM integration, Acquire Live Chat helps convert visitors into customers.

Preferences

ActivEngage

ActivEngage is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. ActivEngage integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, ActivEngage helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

Ada

Ada is a web accessibility solution that helps websites comply with ADA, WCAG, and accessibility standards. It provides automated scanning, remediation tools, and compliance monitoring to ensure content is accessible to all users, including those with disabilities. Ada offers screen reader optimization, keyboard navigation support, and color contrast adjustment. With regular audits and reporting, Ada helps create inclusive digital experiences for everyone.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Tidio do?

Tidio is a customer communication platform combining live chat, AI-powered chatbots, and email marketing automation. Embedded via a JavaScript widget, it tracks visitor behaviour to trigger automated responses and build contact profiles. Under GDPR and the ePrivacy Directive, consent is required before loading Tidio because it sets persistent identification cookies, profiles visitor behaviour for marketing automation, and transfers personal data to Tidio LLC in the United States.

What is Tidio?

Tidio is a customer communication platform that combines live chat, AI-powered chatbots, and email marketing automation into a single embeddable widget. Website owners integrate Tidio via a JavaScript snippet that loads from code.tidio.co. Tidio identifies returning visitors, triggers automated chatbot sequences based on visitor behaviour, and stores contact data for follow-up email campaigns. The platform is operated by Tidio LLC, incorporated in the United States, and runs on Amazon Web Services infrastructure. Tidio is especially popular with e-commerce businesses that use its automation to reduce cart abandonment and qualify leads.

What data and cookies does Tidio collect?

Tidio sets persistent cookies including tidio_cid (a unique contact identifier), _tidioid (a visitor tracking identifier for marketing automation), and tidio_state (widget state and preferences). It collects the visitor IP address, browser type, pages visited, time spent on each page, and device information. When a visitor engages with the chatbot or fills in a contact form, Tidio captures name, email address, and the full conversation transcript. This data is stored in the Tidio contact database and may be used to trigger automated email sequences. The combination of behavioural tracking and marketing automation constitutes profiling under GDPR.

GDPR and ePrivacy implications

The Tidio widget loads automatically on page visit and sets persistent identification cookies before any visitor interaction. Under Article 5(3) of the ePrivacy Directive, this requires prior consent. Under GDPR, the processing of personal data for marketing automation and behavioural profiling requires consent as the legal basis under Article 6(1)(a), since these purposes cannot be justified by legitimate interest when they involve unsolicited automated marketing. Any chatbot flow that results in automated decisions about the visitor may also trigger obligations under GDPR Article 22 regarding automated individual decision-making.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers to the United States

Tidio LLC is incorporated in the United States and processes all data on AWS infrastructure. EU website owners embedding Tidio are therefore making a third-country data transfer subject to GDPR Chapter V. Tidio offers Standard Contractual Clauses (SCCs) and has certified under the EU-US Data Privacy Framework (DPF). Website owners must confirm that a valid Data Processing Agreement is signed with Tidio and must disclose the US transfer and applicable transfer mechanism in their privacy policy.

Consent requirements and implementation

Consent must be obtained before the Tidio widget loads for EU visitors. The Tidio JavaScript snippet must be blocked by default in a CMP and only injected after the visitor accepts the relevant cookie category. Tidio itself provides a GDPR mode in its settings that delays cookie writing, but this does not substitute for blocking the script before consent. Visitors must be clearly informed about Tidio data collection in the consent notice. Consent withdrawal must result in the widget being removed from the page and all associated processing ceasing.

Practical compliance steps

To use Tidio in compliance with GDPR and ePrivacy: (1) Block the Tidio script by default and use a CMP to inject it only after consent. (2) Enable the GDPR mode in Tidio settings as an additional layer of protection. (3) Sign the Data Processing Agreement with Tidio from your account settings. (4) List all Tidio cookies in your cookie policy with accurate names, durations, and purposes. (5) Disclose Tidio data processing and the US transfer in your privacy policy, referencing SCCs or DPF as applicable. (6) Review any chatbot automation flows to ensure they comply with Art. 22 GDPR if they produce decisions affecting visitors. (7) Consider alternative self-hosted chat tools if you need to avoid third-country transfers entirely.

GDPR consent category

Preferences

Websites using Tidio must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for behavioural tracking, marketing automation, and visitor profiling. Legitimate interest (Art. 6(1)(f) GDPR) may apply to strictly functional chat session cookies, subject to a balancing test.
Risk levelmedium
Applicable regulationsGDPR (EU) 2016/679, ePrivacy Directive 2002/58/EC

DPIA considerations

A DPIA should be considered for websites using Tidio's marketing automation features, particularly where behavioural profiling is combined with email marketing and visitor identification. The processing of personal data for automated decision-making in chatbot flows may also require a DPIA under Art. 35 GDPR.

Sample consent text

We use Tidio to provide live chat and automated support on this website. Tidio uses cookies to identify returning visitors and may use your data for marketing automation. Data is processed by Tidio LLC in the United States. Please accept to enable the chat widget.

Technical details

Tracking methodEmbedded JavaScript widget loaded from code.tidio.co, persistent visitor identification cookies, behavioural tracking for chatbot automation and marketing features, email marketing integration
Server locationUnited States (AWS infrastructure)
Data transferred outside the EUVisitor data including contact information, chat transcripts, and behavioural data is processed by Tidio LLC in the United States on AWS infrastructure. Transfers rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework (DPF).

Third-party domains contacted

tidio.cowidget.tidio.cotracking.tidio.co

Cookies placed

NameTypeDurationPurpose
tidio_cidpersistent1 yearAssigns a unique contact identifier to the visitor for live chat and marketing automation
_tidioidpersistent1 yearStores the Tidio visitor identity to personalise chat interactions and track engagement
tidio_statesessionsessionPreserves the chat widget open or closed state during the current browsing session
tidio_sessionsessionsessionMaintains the current Tidio chat session data including conversation context

Tidio uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Does Tidio require GDPR consent to load?

Yes. Tidio sets persistent identification cookies and begins collecting visitor behavioural data as soon as the widget loads on the page, before any visitor interaction. Under the ePrivacy Directive, prior consent is required for these non-essential cookies. Under GDPR, the marketing automation and behavioural profiling features also require consent. You must block the Tidio script until consent is granted.

What cookies does Tidio set?

Tidio sets tidio_cid (a unique contact identifier, 1 year), _tidioid (a visitor tracking identifier for marketing automation, 1 year), tidio_state (widget state and preferences, 1 year), and tidio_session_<id> (a session-level conversation tracker, session duration). These cookies enable visitor identification across sessions, marketing automation triggering, chatbot personalisation, and chat history management.

What is the legal basis for using Tidio under GDPR?

Consent under Article 6(1)(a) GDPR is the required legal basis for Tidio marketing automation, behavioural tracking, and visitor profiling. Legitimate interest may apply only to strictly necessary session cookies, subject to a documented balancing test. Given that Tidio primary value proposition includes marketing automation triggered by visitor behaviour, consent is the appropriate basis for the overall processing. Tidio offers a GDPR mode in its settings but this does not replace proper consent collection via a CMP.

Does Tidio transfer data to the United States?

Yes. Tidio LLC is incorporated in the United States and processes all data on AWS infrastructure. EU website owners embedding Tidio are making a third-country data transfer subject to GDPR Chapter V. Tidio relies on Standard Contractual Clauses (SCCs) and has certified under the EU-US Data Privacy Framework (DPF). You must sign the Tidio Data Processing Agreement, disclose the transfer in your privacy policy, and reference the applicable mechanism (SCCs or DPF).

Do I need a DPIA for Tidio?

A DPIA should be considered for websites using Tidio marketing automation features, especially where behavioural profiling is combined with email marketing and visitor identification. If any Tidio chatbot flow makes automated decisions affecting visitors (routing, pricing, content personalisation), this may independently trigger the DPIA requirement under Article 35 GDPR due to the automated decision-making component under Article 22.

How do I implement GDPR-compliant consent for Tidio?

Block the Tidio JavaScript snippet by default using a CMP and inject it only after advertising or marketing consent is granted. Enable Tidio built-in GDPR mode in your Tidio dashboard as an additional safeguard. Sign the Tidio Data Processing Agreement available in your account settings. Ensure that withdrawing consent removes the Tidio widget and stops all associated data processing in real time.

Are there privacy-friendly alternatives to Tidio?

Yes. Chatwoot is an open-source live chat platform that can be self-hosted on EU infrastructure, eliminating third-country data transfers. Crisp offers EU-hosted options for live chat without marketing automation. For simpler chatbot functionality without cross-border data flows, a self-hosted solution using an open-source chatbot framework on EU servers is the most privacy-compliant approach.

How do I document Tidio in my cookie policy and privacy notice?

In your cookie policy, list each Tidio cookie (tidio_cid, _tidioid, tidio_state, tidio_session) with its name, category (marketing or functional), duration, and purpose. In your privacy notice, include Tidio as a data processor, describe its marketing automation and visitor profiling activities, state the legal basis (consent), disclose the US data transfer and the applicable mechanism (SCCs or DPF), and reference your signed Data Processing Agreement.