Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Cordial is a US cross channel marketing platform that uses cordial.js to capture real time behavioral data and build unified customer profiles across email, SMS and push.
Cordial is a US based cross channel marketing and messaging platform run by Cordial Inc. of San Diego. It unifies email, SMS, push and web messaging and builds customer profiles from real time behavioral data so brands can personalise communications at scale.
Cordial loads a JavaScript browser listener, cordial.js, that captures real time events such as page views, clicks and product interactions. It sets cookies, including a browser session identifier, to recognise visitors across the base domain and subdomains, and the identify method links these signals to a known contact. This feeds a cross channel identity graph that matches identifiers across devices and channels.
The cordial.js listener and its cookies are not strictly necessary, so Article 5(3) of the ePrivacy Directive and the GDPR require prior consent. Identity resolution and cross channel profiling amount to large scale profiling, which heightens transparency and accountability duties and usually triggers a data protection impact assessment.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Rely on consent under Article 6(1)(a) for the tracking listener, cookies and profiling, captured through a compliant banner before cordial.js runs. SMS and push messaging also require consent, and you must let people withdraw it as easily as they gave it. Keep clear records of what each person agreed to.
Cordial runs on AWS in the United States, so EU and UK personal data is transferred to a third country. These transfers rely on Standard Contractual Clauses and, where applicable, the EU US Data Privacy Framework, and should be backed by a transfer impact assessment and supplementary measures.
Load cordial.js only after consent, document the identity graph and retention, list Cordial cookies in your policy, sign a data processing agreement with Standard Contractual Clauses, complete a DPIA and honour access, withdrawal and erasure requests.
Websites using Cordial must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is strongly recommended because Cordial performs cross channel profiling and identity resolution, matching identifiers across devices and channels to build unified customer profiles. Assess the scale and combination of behavioral data, the identity graph, transfers to the United States on AWS and the risk of persistent tracking. Define retention, data subject rights handling and safeguards for the US transfer.
Sample consent text
We use Cordial to personalise our email, SMS and push messages and to track how you interact with our site and content across channels. This sets cookies and transfers data to the United States. Do you consent?
Third-party domains contacted
cordial.comapi.cordial.iotrack.cordial.iocdn.cordial.iomsgs.cordial.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| bID | Third-party | Persistent | Browser session identifier set by cordial.js to recognise a visitor and group their real time behavioral events; stored at the base domain so it can be shared across subdomains. |
| cordialId | Third-party | Persistent | Contact identifier used to associate browser activity with a known contact profile for cross channel personalisation and identity resolution. |
| crdl | Third-party | Persistent | Cordial tracking identifier used to maintain continuity of behavioral tracking and link events to the unified customer profile. |
Cordial uses cookies for user preferences — inform visitors with a consent banner.
Cordial sets cookies through its cordial.js browser listener, including a browser session identifier (bID) and contact identifiers such as cordialId. These are stored at the base domain so they can be shared across subdomains to recognise visitors. They are not strictly necessary and require consent.
Yes. The cordial.js browser listener, its cookies and the cross channel profiling are not strictly necessary, so prior consent is required under the ePrivacy Directive and the GDPR. SMS and push messaging also require consent before sending.
The behavioral tracking, cookies and cross channel profiling rely on consent under Article 6(1)(a) of the GDPR. Given the identity resolution and large scale profiling, consent is the appropriate basis rather than legitimate interest for these activities.
Yes. Cordial Inc. is based in the United States and runs only on AWS, so EU and UK data is transferred to the US. Transfers rely on Standard Contractual Clauses and, where applicable, the EU US Data Privacy Framework, with a transfer impact assessment.
Yes, a DPIA is strongly recommended. Cordial performs identity resolution and large scale cross channel profiling, combining behavioral data across devices and channels and transferring it to the United States, all of which are high risk factors that call for a documented assessment.
Load cordial.js only after consent, list Cordial cookies and identifiers in your cookie policy, sign a data processing agreement with Standard Contractual Clauses, complete a DPIA, document the identity graph and retention, and provide easy access, withdrawal and erasure.
Alternatives include other cross channel platforms such as Braze, Iterable, Klaviyo and Salesforce Marketing Cloud, plus EU hosted options. Compare data hosting location, identity resolution scope and transfer safeguards to find a lower risk fit for your needs.
List the Cordial cookies and identifiers such as the bID session cookie and cordialId, explain that they support cross channel tracking and identity resolution, state that data is transferred to the United States on AWS and link to Cordial privacy information. Keep it current.