FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Gumstack

Gumstack

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Gumstack do?

Gumstack is a US based Shopify app that embeds a live video shopping widget on store pages. Founded in 2020 in Beaverton, Oregon, it lets merchants run one to one video calls and group live streams to drive conversions. The widget sets first-party cookies for session, consent and analytics, and routes interactions to Gumstack servers in the United States. As a result, integrating Gumstack on an EU storefront triggers a third country transfer that must rely on DPF or SCCs and requires informed consent for non essential cookies.

What Gumstack is and how the widget works

Gumstack is a Shopify app that brings live video shopping to merchant storefronts. The company was founded in 2020 in Beaverton, Oregon, and offers both one to one calling and one to many live streaming for product launches and influencer events. Merchants install the app from the Shopify App Store, configure availability windows and embed a button or modal on product pages. When a visitor clicks, the Gumstack widget initialises a WebRTC session that connects the shopper to the merchant team, then logs the interaction for analytics and follow up.

Data and cookies set by the widget

The Gumstack widget sets first-party functional cookies for the visitor session, an identifier used to reconnect to an ongoing video call, a consent record cookie and optional analytics cookies that measure session length and conversion. During a live call, the service processes the WebRTC audio video stream, optional chat messages, the visitor IP address, User-Agent, the referring URL and a viewer identifier that links the conversation back to the merchant CRM. The merchant account hosted by Gumstack stores agent profiles, scheduling data and aggregate dashboards.

GDPR and ePrivacy framework

The Shopify merchant is the controller of the data collected via Gumstack on its storefront. Shopify acts as a processor for the platform side and Gumstack as a processor (or sub-processor depending on the contractual chain) for the live shopping feature. Cookies strictly necessary to deliver the video session explicitly requested by the visitor fall under the Article 5(3) ePrivacy exemption. Analytics, conversion tracking and replay cookies require prior, informed consent, captured through a compliant banner on the storefront before the Gumstack script is loaded.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Transfers to the United States

Gumstack hosts its production environment in the United States and routes WebRTC sessions through US TURN servers when relays are needed. Each live call therefore involves a transfer of personal data to a third country. EU merchants should rely on the EU US Data Privacy Framework adequacy decision when Gumstack Inc. is certified, with the new Standard Contractual Clauses as a contractual fallback and supplementary measures (TLS encryption, tenant segregation, controlled retention of recordings) explicitly documented in the DPA.

Consent and DPIA approach

Live video shopping is more intrusive than a classic cookie banner because it involves real time audio and video. A DPIA is recommended whenever the merchant enables recording, transcription or AI assisted analysis of calls, when the audience includes minors or when the catalogue covers sensitive sectors. The consent banner on the storefront should distinguish strictly necessary cookies (session) from optional cookies (analytics, attribution, replay) and link to a clear privacy notice that mentions the US transfer.

Practical compliance steps and alternatives

Sign the Gumstack DPA, verify the DPF certification on dataprivacyframework.gov, configure the consent banner to gate non essential Gumstack cookies, restrict recording retention to a justified minimum and provide clear in app information before the call starts. EU based alternatives include Bambuser (Sweden), Livescale (Canada with EU regions) and Phygital Plus (France), which offer comparable live shopping features with localised hosting and contractual coverage adapted to the European market.

GDPR consent category

Preferences

Websites using Gumstack must obtain user consent under GDPR regulations.

Legal basisContract performance (Article 6(1)(b) GDPR) for the live video shopping service itself when ordered by the merchant. Consent (Article 6(1)(a) plus Article 5(3) ePrivacy) on the storefront for any non essential Gumstack cookie (analytics, conversion tracking, replay). Functional cookies needed to deliver the video session requested by the visitor fall under the strictly necessary exemption.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, EU US Data Privacy Framework, Schrems II case law (CJEU C-311/18), California Consumer Privacy Act (CCPA/CPRA), Shopify Partner Program Agreement

DPIA considerations

A DPIA is recommended for merchants integrating Gumstack because the service combines video streaming, behavioural analytics and conversion tracking on EU customers. The assessment must cover the categories of data exchanged (IP, identifiers, audio video stream, chat, purchase intent), retention of session recordings, US hosting risks under Schrems II, the role of Shopify and Gumstack as processors, supplementary measures and the rights of data subjects, in particular the right to object and the right to deletion of recordings.

Sample consent text

This store uses Gumstack, a live video shopping app operated from the United States, to offer real time video sessions with our team. Strictly necessary cookies allow the video session to function. With your consent, additional Gumstack cookies measure session analytics and attribution. By accepting, you authorise the transfer of your IP, User-Agent and interaction data to Gumstack Inc., under the EU US Data Privacy Framework or Standard Contractual Clauses.

Technical details

Tracking methodJavaScript widget embedded on Shopify storefront pages that initialises a live video shopping session. Sets first-party functional cookies for session, consent record and basic analytics. Relies on WebRTC for the audio video stream and on HTTPS API calls to Gumstack backend for scheduling, recording and conversion tracking.
Server locationUnited States. Gumstack is operated by Gumstack Inc. from Beaverton, Oregon, with production infrastructure hosted on US cloud regions (primarily Amazon Web Services).
Data transferred outside the EUCustomer interactions with the widget, including IP address, User-Agent, viewer identifier, chat content and any video stream metadata, are routed to Gumstack servers in the United States. Gumstack relies on the EU US Data Privacy Framework certification when listed, with the new Standard Contractual Clauses (Module 3 processor to processor when chained through Shopify, or Module 2 controller to processor for direct merchant contracts) as fallback. Supplementary measures include TLS in transit, encryption at rest and segregated tenant data.

Third-party domains contacted

gumstack.comapp.gumstack.comapi.gumstack.comcdn.gumstack.comlive.gumstack.com

Cookies placed

NameTypeDurationPurpose
gumstack_sessionfirst_partySessionIdentifies the live video shopping session and links the visitor to the active WebRTC connection. Strictly necessary functional cookie.
gumstack_viewer_idfirst_party12 monthsPersistent viewer identifier used to resume an interrupted call and to display the visitor history to the agent.
gumstack_consentfirst_party12 monthsStores the cookie consent choice made by the visitor for the Gumstack widget, including analytics opt in or opt out.
gumstack_analyticsfirst_party13 monthsAggregated session analytics (duration, drop off, conversion). Loaded only after the visitor accepts analytics cookies.
gumstack_attributionfirst_party90 daysConversion attribution token that links a purchase back to a Gumstack live session. Marketing category, requires consent.

Gumstack uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Gumstack set on a Shopify storefront?

Gumstack sets first-party functional cookies for the video session, a persistent viewer identifier, the consent record and optional analytics and attribution cookies. The strictly necessary cookies are loaded as soon as a visitor opens the widget. Analytics and attribution cookies should only load after the visitor has accepted them in the consent banner.

Do I need consent before loading Gumstack on my store?

Yes for any non essential cookie or processing (analytics, attribution, replay, AI analysis). The strictly necessary session cookie used to deliver the video call requested by the visitor falls under the Article 5(3) ePrivacy exemption, but the visitor must be informed before the call starts that the session is operated from the United States.

What is the legal basis for processing data via Gumstack?

The merchant Gumstack relationship relies on contract performance under Article 6(1)(b) GDPR, formalised by the app subscription and the DPA. On the storefront, strictly necessary cookies rely on the same logic, while analytics, attribution and replay cookies require consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy. Recording calls additionally requires explicit information and a documented purpose.

Does Gumstack transfer personal data outside the EU?

Yes. Gumstack Inc. is based in Beaverton, Oregon, and runs its infrastructure on US cloud regions. WebRTC sessions, identifiers, recorded calls and analytics data therefore reach the United States. The transfer relies on the EU US Data Privacy Framework when Gumstack is certified, or on the new Standard Contractual Clauses combined with supplementary technical measures.

Is a DPIA needed for Gumstack?

Yes when the merchant activates call recording, transcription, AI analysis or marketing attribution, when the audience includes minors or when the catalogue covers sensitive sectors. The DPIA should cover data categories (audio, video, chat, identifiers), retention, US transfer risks, the role of Shopify and Gumstack and the residual risk after technical and contractual measures.

How do I deploy Gumstack in a compliant way?

Sign the Gumstack DPA, configure the Shopify consent banner or a third-party CMP to gate non essential Gumstack cookies, customise the pre call notice with the US hosting disclosure, restrict recording retention to a justified minimum, train agents on data subject rights and add Gumstack to your record of processing activities and sub-processor list.

What are the alternatives to Gumstack for live shopping?

European alternatives include Bambuser (Sweden), Phygital Plus (France) and Caast.tv (France), all of which offer live and one to one video shopping with EU hosting options. Livescale (Canada with EU regions) and Vimeo Studio are also worth considering. The choice depends on Shopify compatibility, recording features, replay quality and the contractual framework offered by the vendor.

How should I update the cookie policy when using Gumstack?

Add a dedicated section listing each Gumstack cookie (name, purpose, retention, category), mention Gumstack Inc. as processor, the United States hosting and the transfer mechanism (DPF or SCCs). Disclose any call recording, the retention period and the legal basis used. Update the notice when you change the analytics or attribution settings, when you enable AI analysis or when the DPF status of Gumstack changes.