Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Justuno is a conversion optimisation platform that uses popups, banners and audience targeting to turn website visitors into leads and customers. It loads a first party JavaScript snippet that sets cookies and pixels to recognise visitors, control how often messages appear and build visitor profiles for AI driven targeting and personalisation. Because it is a United States based service that profiles behaviour, its non essential cookies require consent and its use involves an international data transfer.
Justuno is a conversion optimisation and visitor targeting platform used mainly by ecommerce and lead generation websites. It offers popups, banners, email and SMS capture forms, and audience targeting tools that decide which message to show to which visitor. Justuno is a United States company headquartered in California, and website owners add a first party JavaScript snippet that lets it set cookies, pixels and other technologies to power its features. A distinctive part of Justuno is its visitor profiles and AI driven audience segmentation, which build a picture of each visitor and can enrich it with additional attributes once a person opts in. Because it observes behaviour and profiles visitors, it processes personal data on behalf of the website that deploys it.
Justuno sets first party cookies and uses pixels and browser storage to recognise visitors, remember whether a promotion has already been shown and apply display frequency rules. These identifiers also feed visitor profiles and A B testing and can persist from a session up to around a year depending on configuration. Justuno records on site behaviour such as pages viewed, items interacted with, referring source and technical signals like IP address and device details. Once a visitor opts into lead capture, their profile can be enriched with attributes such as location and other audience data, and Justuno stores the opt in timestamp and campaign. Together this lets Justuno target audiences and personalise offers in real time.
Under the ePrivacy Directive, storing or reading information on a visitor device requires consent unless it is strictly necessary for a service the visitor explicitly requested. The cookies and pixels Justuno uses for profiling, targeting and personalisation are not strictly necessary, so they fall within the consent requirement. Under the GDPR the building of visitor profiles and AI driven segmentation is profiling of personal data that needs a valid lawful basis, transparency and, where relevant, information about the logic involved. The website operator is the controller and must inform visitors and collect consent before non essential Justuno scripts load. Justuno acts as a processor and offers a data processing agreement, contact deletion tools and consent features to support compliance.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Marketing popups, audience targeting, visitor profiling and AI driven personalisation all rely on consent under Article 6(1)(a) of the GDPR. The practical approach is to integrate Justuno with a consent management platform so its non essential scripts and pixels are blocked until the visitor accepts the marketing or personalisation category. Consent must be freely given, specific, informed and as easy to withdraw as to give, and visitors should be able to decline profiling without losing access to the site. Justuno also offers consent checkbox layers for its own forms, which help document opt in but do not replace a site wide consent banner. Basic frequency capping might be argued under legitimate interest in narrow cases with a documented balancing test.
Justuno is based in the United States and processes visitor data there, so any use by a European website involves a transfer of personal data to a third country. Such transfers need a valid mechanism, which in practice means relying on the EU US Data Privacy Framework where Justuno is certified, or on Standard Contractual Clauses combined with supplementary measures. The data processing agreement should set out the safeguards and the sub processors involved. Operators should confirm Justuno current certification status and document the transfer mechanism in their record of processing activities. Given the profiling involved, a transfer risk assessment is a sensible part of due diligence.
Sign the Justuno data processing agreement, confirm the transfer mechanism and add both to your record of processing and sub processor list. Integrate Justuno with a consent management platform so its non essential cookies, pixels and profiling only run after the visitor accepts marketing or personalisation. Disclose the cookies, pixels and visitor profiling in your cookie and privacy policies, and explain the AI driven targeting in plain language. Provide easy ways to withdraw consent and to exercise access and deletion rights, and use Justuno contact deletion tools to honour erasure requests. Review configuration and the United States transfer position periodically so practice stays aligned with what visitors were told.
Websites using Justuno must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is strongly recommended because Justuno builds visitor profiles and applies AI driven audience targeting, which involve systematic monitoring and profiling of visitor behaviour. Document the data collected, the cookies and pixels used, the profile enrichment that occurs after opt in, retention periods and the consent mechanism. Pay particular attention to the United States transfer position and the supplementary measures relied on, and record the lawful basis for each purpose.
Sample consent text
We use Justuno to show you relevant offers and to personalise your experience based on your activity on this site. This sets cookies and may build a visitor profile, and data is processed in the United States. Do you consent to these marketing and personalisation cookies?
Third-party domains contacted
justuno.comcdn.jst.aiapp.justuno.comcdn.justuno.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _ju_tracker | first party | up to 1 year | Stores a visitor identifier used to recognise returning visitors, build visitor profiles and support audience targeting and frequency capping. |
| _ju_dm | first party | up to 1 year | Used for visitor and device matching so behaviour can be attributed to a profile across visits for targeting and analytics. |
| ju_session | first party | session | Maintains the current session so campaign state and on site interactions are tracked consistently during a visit. |
Justuno uses cookies for user preferences — inform visitors with a consent banner.
Justuno sets first party cookies and uses pixels and browser storage to recognise visitors, remember whether a promotion has been shown and apply display frequency rules. These identifiers also feed visitor profiles and A B testing and can last from a session up to around a year. When a visitor opts in, additional profile data and the opt in timestamp are stored.
Yes. Because Justuno sets non essential cookies and pixels and builds visitor profiles for targeting and AI driven personalisation, prior consent is required under the ePrivacy Directive and the GDPR before those scripts run. The profiling involved makes a clear marketing or personalisation consent step especially important.
The main legal basis is consent under Article 6(1)(a) of the GDPR for marketing popups, audience targeting, visitor profiling and AI driven personalisation. Legitimate interest under Article 6(1)(f) may be considered only for basic display frequency capping with a documented balancing test. The website operator is the controller and decides the basis for each purpose.
Yes. Justuno is a United States company and processes visitor data there, so European websites are making a transfer to a third country. This should rely on the EU US Data Privacy Framework where Justuno is certified, or on Standard Contractual Clauses with supplementary measures set out in the data processing agreement. Confirm the current certification and document the mechanism in your record of processing.
A data protection impact assessment is strongly recommended because Justuno builds visitor profiles and applies AI driven targeting, which involve systematic monitoring and profiling. The assessment should cover the data collected, the cookies and pixels used, profile enrichment, retention, the consent mechanism and the United States transfer. The profiling and transfer combination makes a documented DPIA the safer course.
Sign the Justuno data processing agreement, confirm the transfer mechanism and integrate Justuno with a consent management platform so its cookies, pixels and profiling only run after consent. Disclose the cookies, pixels and visitor profiling in your cookie and privacy policies and explain the AI driven targeting clearly. Offer easy ways to withdraw consent and to request access and deletion, and use Justuno contact deletion tools.
Comparable conversion and popup platforms include Adoric, Poptin, GetSiteControl, OptinMonster and Privy. Each sets cookies and many profile or target visitors, so the same consent and transparency obligations apply. If you want to limit United States transfers, look at providers with EU hosting or self hosted options and review their data processing terms.
List the Justuno cookies and pixels with their purposes and durations, describe the visitor profiling and group everything under marketing or personalisation rather than strictly necessary. Name Justuno as the provider, state that data is processed in the United States and explain the transfer safeguard, then link to its privacy information. Keep the policy aligned with your consent banner and review it whenever you change Justuno features.