Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Omnisend is an ecommerce email and SMS marketing platform. Its web snippet sets first party cookies such as omnisendContactID and tracks browsing, carts, and signups, linking them to contact profiles. Data is processed in the European Union and the United States, and the tracking is used for marketing, so prior consent is required under the GDPR and the ePrivacy Directive.
Omnisend is an email and SMS marketing platform built for ecommerce stores. It combines campaign sending, automation, signup forms, and on site tracking so that merchants can recover abandoned carts, segment audiences, and personalise messages. A small JavaScript snippet runs on the storefront to capture browsing and shopping behaviour and connect it to contact profiles in Omnisend.
The Omnisend snippet sets first party cookies such as omnisendContactID, omnisendSessionID, and omnisendAnonymousID. Together they identify the contact, hold the current session, and track anonymous visitors until they identify themselves. Omnisend processes identifiers, email addresses and phone numbers, IP addresses, device and browser information, pages viewed, products browsed, cart contents, and signup and purchase events, all linked to a contact profile.
The Omnisend cookies are used for marketing tracking and profiling rather than a strictly necessary function, so Article 5(3) of the ePrivacy Directive requires prior consent before they are set. Linking browsing and shopping behaviour to identifiable contacts is personal data processing under the GDPR, which requires a lawful basis, transparency about profiling, and a record of processing activities. Sending email and SMS marketing additionally requires a valid marketing opt in.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The Omnisend snippet must not load and its tracking cookies must not be set before the visitor accepts the marketing category in your consent management platform. Email and SMS marketing each need their own valid opt in, and SMS in particular requires clear, specific consent. Consent must be freely given, specific, informed, and as easy to withdraw as to grant, and pre ticked boxes do not meet the standard.
Omnisend processes data in the European Union and the United States, and transfers to the United States rely on Standard Contractual Clauses, so you should document the transfer and sign the Omnisend Data Processing Agreement. In practice, gate the Omnisend snippet behind your consent management platform, capture separate marketing opt ins for email and SMS, set sensible data retention, and list the Omnisend cookies and their durations in your cookie policy.
Websites using Omnisend Email Marketing & SMS must obtain user consent under GDPR regulations.
DPIA considerations
Omnisend sets persistent first party cookies (omnisendContactID, omnisendAnonymousID) that link browsing, carts, and signups to identifiable contact profiles, and processes data in the European Union and the United States. A DPIA should assess the scale of behavioural profiling for marketing, the combination of browsing, cart, and contact data, transfers to the United States under Standard Contractual Clauses, and retention periods, together with mitigations such as consent gating, separate opt ins for email and SMS, and shortened data retention.
Sample consent text
We use Omnisend to run our email and SMS marketing and to personalise the messages you receive. Omnisend places cookies on your device to recognise your browser and link your browsing and cart activity to your contact profile. These cookies load only after you accept the marketing category, and the data may be processed in the European Union and the United States. You can withdraw your consent at any time through our cookie settings.
Third-party domains contacted
omnisrc.comapi.omnisend.comapp.omnisend.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| omnisendContactID | marketing | 1 year | Identifies a known Omnisend contact so that browsing, cart, and signup activity can be attributed to the correct contact profile for email and SMS marketing. |
| omnisendAnonymousID | marketing | 1 year | Tracks an anonymous visitor across pages and sessions until they identify themselves, so that earlier activity can be merged into their contact profile. |
| omnisendSessionID | marketing | Session | Holds the current session so that on site events within a single visit are grouped together and attributed correctly. |
Omnisend Email Marketing & SMS uses cookies for user preferences — inform visitors with a consent banner.
Omnisend sets first party cookies such as omnisendContactID, which identifies a known contact for about a year, omnisendAnonymousID, which tracks anonymous visitors for about a year, and omnisendSessionID, which holds the current session. Together they link browsing and cart activity to a contact profile.
Yes. The Omnisend tracking cookies are used for marketing and profiling, not a strictly necessary function, so Article 5(3) of the ePrivacy Directive and the GDPR require prior, opt in consent before the snippet loads. Email and SMS marketing each need their own valid opt in as well.
The storage and reading of the Omnisend cookies relies on consent under the ePrivacy Directive, and the profiling and marketing that follow rely on consent under Article 6(1)(a) of the GDPR. SMS and email marketing also rest on consent, and legitimate interest is generally not available for the non essential cookies.
Omnisend processes data in both the European Union and the United States. Transfers to the United States rely on Standard Contractual Clauses, which you should reference in your privacy notice along with Omnisend as a recipient. Keeping processing in the EU where possible reduces transfer risk.
A full DPIA is not always mandatory, but it is advisable because Omnisend profiles shoppers for marketing, combines browsing, cart, and contact data, and transfers some data to the United States. Document the purposes, data categories, retention, and safeguards, and reassess if you enable large scale automation or detailed behavioural segmentation.
Load the Omnisend snippet only after the visitor accepts the marketing category in your consent management platform, and keep the tracking cookies blocked until then. Capture separate, clear opt ins for email and SMS, sign the Data Processing Agreement, set sensible data retention, and document the cookies in your cookie policy.
EU based or privacy focused ecommerce marketing tools such as Brevo, Mailjet, or EU hosted email platforms can keep more data within the European Union. They do not always offer the same combined email, SMS, and automation features, so the right choice depends on whether you need Omnisend specific functionality or prefer EU data residency.
List the omnisendContactID, omnisendAnonymousID, and omnisendSessionID cookies, with their purpose and duration, name Omnisend as a recipient, and disclose that data may be processed in the EU and the US under Standard Contractual Clauses. Keep the entries in sync with a regular cookie scan so that new or renamed Omnisend cookies are reflected accurately.