Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Skimlinks, owned by Taboola and Connexity, is a US based affiliate monetization service that automatically rewrites outbound merchant links and tracks clicks and conversions. It sets attribution cookies and shares data with merchant and affiliate networks, which makes it a high risk third party that transfers personal data to the United States. Consent is required before its tracking loads, and operators should document the legal basis and transfer safeguards.
Skimlinks is a US based affiliate monetization service owned by Taboola and Connexity that helps publishers earn commission from outbound links to merchants. It works across publisher sites through its own domains, including skimlinks.com, skimresources.com, redirectingat.com and go.skimresources.com. For the operator it is a high impact third party because it actively rewrites links and tracks user behaviour across the outbound journey rather than just measuring page views.
Skimlinks loads a script that scans the page for outbound merchant links and automatically rewrites them so that clicks pass through its redirect infrastructure. When a user clicks, the service records the click, attributes any resulting purchase, and shares the relevant data with merchant and affiliate networks so commission can be paid. This means the service performs heavy third party tracking and routes user interactions through US based systems.
Skimlinks typically sets attribution and tracking cookies and processes data such as the links clicked, referring pages, device and browser signals, and conversion events. This information can build a picture of a user across publishers and merchants for the purpose of commission attribution. Operators should review the exact cookies in their own deployment, since the precise set can change over time and by configuration.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Skimlinks sets non essential marketing cookies and engages in cross context behavioural tracking, so it falls squarely within the GDPR and the ePrivacy Directive. Under ePrivacy the tracking cookies may only be set after consent, and under the GDPR the sharing of personal data with affiliate networks needs a valid legal basis and transparency. Because the data flows to the US and to multiple partners, the risk profile is high and the accountability obligations are significant.
Consent must be collected through a consent management platform before the Skimlinks script runs, and the link rewriting and tracking should be blocked until the user accepts marketing cookies. Data is transferred to the United States, so operators should rely on standard contractual clauses or another valid transfer mechanism and reflect this in their privacy notice. The sharing with affiliate networks worldwide should also be disclosed clearly.
To use Skimlinks compliantly, block the script by default and load it only after marketing consent, then stop it and clear its cookies when consent is withdrawn. Document the legal basis, complete a DPIA given the tracking and transfers, and put the appropriate data processing and transfer terms in place. List Skimlinks and its domains in your cookie policy and be transparent that outbound links may be monetized and tracked.
Websites using Skimlinks must obtain user consent under GDPR regulations.
DPIA considerations
Because Skimlinks involves systematic tracking of outbound clicks, profiling for monetization, and transfers to the US, a DPIA is strongly advisable. Assess the scale of click and conversion tracking, the sharing with affiliate networks, and the third country transfer risk, and document safeguards such as consent gating, standard contractual clauses, and data minimization.
Sample consent text
We use Skimlinks to monetize outbound links to merchants. This rewrites some links and sets cookies that track clicks and conversions, and it may share data with affiliate networks in the United States. With your consent, Skimlinks tracking will be activated.
Third-party domains contacted
skimresources.comgo.skimresources.comredirectingat.comskimlinks.comr.skimresources.comtaboola.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| skim_session | Marketing | Session | Identifies the visitor session to associate clicks on affiliate links with a single browsing session |
| __cf_bm | Functional | 30 minutes | Bot management cookie used by the Skimlinks infrastructure to distinguish humans from automated traffic |
| skimlinks_referrer | Marketing | 1 year | Stores the referring publisher so that affiliate commissions can be attributed correctly |
| redirectingat | Marketing | 1 year | Set during click redirects to track outbound clicks to merchant sites for sale attribution |
| taboola_tracking | Marketing | 13 months | Used by the Taboola and Connexity group to link affiliate activity to advertising attribution |
| skim_uid | Marketing | 1 year | Persistent identifier that recognizes a device across visits to attribute conversions to clicks |
Skimlinks uses cookies for user preferences — inform visitors with a consent banner.
Skimlinks typically sets attribution and tracking cookies that identify a visitor and link an outbound click to a later purchase. They are third party and persistent, often lasting around a year, and are not strictly necessary. Confirm the exact cookies in your deployment, since the set can change over time.
Yes, consent is required before Skimlinks loads because it sets non essential tracking cookies and rewrites links for monetization. The script should be blocked until the visitor accepts marketing cookies. Loading it without consent would breach the ePrivacy cookie rules.
The applicable legal basis is consent under Article 6(1)(a) GDPR for the tracking cookies and the related data sharing. Legitimate interest is generally not appropriate here given the cross context tracking and the transfers involved. Record the consent based legal basis in your records of processing.
Yes, Skimlinks is US based and transfers personal data to the United States, and it also shares click and conversion data with affiliate networks that can be located worldwide. You should put standard contractual clauses or another valid transfer mechanism in place. Disclose these transfers clearly in your privacy notice.
A DPIA is strongly advisable because Skimlinks involves systematic tracking of outbound clicks, profiling for monetization, and third country transfers. Assess the scale of tracking, the sharing with affiliate networks, and the US transfer risk. Document mitigations such as consent gating and data minimization.
Block the Skimlinks script by default and load it only after the visitor accepts marketing cookies, then stop it and clear its cookies on withdrawal. Put data processing and transfer terms in place, complete a DPIA, and be transparent that outbound links may be rewritten and tracked. List the service and its domains in your cookie policy.
Direct affiliate networks and other monetization tools exist, but most affiliate tracking relies on similar cookies and transfers, so the compliance duties are comparable. Some setups let you keep data within the EU or reduce the cookie footprint. Evaluate alternatives on data location, transparency, and contractual terms.
Add Skimlinks as a named third party, describe its tracking and attribution cookies, and state that outbound links may be monetized. Reference its domains such as skimlinks.com and redirectingat.com and disclose the US transfers and affiliate network sharing. Review the entry whenever the cookies or partners change.