Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Target2Sell is a French AI product recommendation and personalisation engine for ecommerce that tailors product suggestions to each visitor in real time across the whole site, email, store and call centre.
Target2Sell is a French artificial intelligence engine that personalises ecommerce experiences by recommending the most relevant products to every visitor in real time. Founded in 2012 in Paris and now part of Mirakl, it analyses visitor behaviour to drive recommendations on the home page, product pages, the basket and even 404 pages, as well as across email, store and call centre channels. Because this relies on behavioural tracking, visitor identifiers and profiling, it has clear data protection implications that website operators must understand.
Target2Sell is a product recommendation and personalisation platform aimed at online retailers and marketplaces. Using proprietary AI algorithms, it ranks and suggests products tailored to each shopper at every stage of the buying journey, which providers report can lift conversion rates significantly. The engine is integrated through JavaScript tags and an API, and it observes how each visitor browses in order to build a profile that informs the recommendations they see.
To personalise recommendations, Target2Sell collects behavioural data such as pages viewed, products clicked, search terms, items added to the basket and purchase signals. It relies on cookies and identifiers to recognise a returning visitor and to keep their profile consistent across a session and over time. Although much of this data is pseudonymous, the combination of a persistent identifier with detailed browsing history can identify or single out an individual, which means it qualifies as personal data under the GDPR.
Two regimes apply. The ePrivacy Directive governs the act of storing or reading cookies and identifiers on a device, and it requires consent for any storage that is not strictly necessary for the service the user requested. The GDPR governs the subsequent processing of the personal data, and building individual profiles to personalise content is treated as profiling. As the operator of the website you are the data controller, while Target2Sell acts as a processor on your behalf, so a data processing agreement under Article 28 is required.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because personalisation cookies are not strictly necessary, you must obtain prior, freely given, specific and informed consent before Target2Sell tags fire. In practice this means the recommendation scripts should be blocked until the visitor accepts, and a consent management platform should gate them. Consent must be as easy to withdraw as it was to give, and you should keep records that demonstrate when and how each visitor agreed.
As a French provider, Target2Sell processes personal data within the European Union, which avoids the complexity of transfers to third countries that lack an adequacy decision. You should nonetheless confirm the current hosting arrangements in your contract, check whether any sub processors operate outside the EU, and ensure standard contractual clauses are in place should that ever change. Recording the hosting location in your records of processing supports your accountability obligations.
Start by mapping every cookie and identifier Target2Sell sets, then disclose them in your cookie policy and privacy notice. Gate the tags behind a consent banner, sign the Article 28 processing agreement, and carry out a data protection impact assessment given the profiling involved. Define clear retention periods, honour access and erasure requests, and review the setup periodically so your documentation stays aligned with how the engine actually behaves.
Websites using Target2Sell must obtain user consent under GDPR regulations.
DPIA considerations
Target2Sell builds individual visitor profiles from real time behavioural tracking to personalise recommendations, which constitutes profiling under the GDPR. Because the processing is systematic, large scale and used to evaluate visitors, a data protection impact assessment is strongly recommended. Document data minimisation, retention limits and the lawful basis for each cookie and identifier.
Sample consent text
We use Target2Sell to analyse your browsing and show you personalised product recommendations; these cookies are only set with your consent.
Third-party domains contacted
target2sell.comtgt.target2sell.commirakl.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| t2s_id | Personalisation | 12 months | Persistent visitor identifier used to recognise a returning visitor and keep their recommendation profile consistent over time. |
| t2s_session | Personalisation | Session | Maintains the visitor context during a browsing session so recommendations stay relevant across pages. |
| t2s_reco | Personalisation | 6 months | Stores recommendation and interaction signals such as viewed and clicked products to tailor future suggestions. |
| t2s_behaviour | Analytics | 13 months | Records browsing behaviour such as page views, searches and basket activity to build and refine the visitor profile. |
Target2Sell uses cookies for user preferences — inform visitors with a consent banner.
Target2Sell uses cookies and visitor identifiers to recognise returning visitors and to track browsing behaviour such as page views, clicks, searches and basket activity. These identifiers let the engine build a profile of each visitor so it can personalise the product recommendations shown across your site.
Yes. Personalisation and profiling cookies are not strictly necessary, so under the ePrivacy Directive you must obtain prior, freely given and informed consent before the Target2Sell tags fire. The scripts should stay blocked until the visitor accepts through your consent banner.
The appropriate legal basis is consent under Article 6(1)(a) of the GDPR, because the processing involves personalisation and profiling cookies. You should not rely on legitimate interests for setting these cookies, since the ePrivacy rules require consent for non essential storage.
No. Target2Sell is a French provider and processes personal data within the European Union, so there is no routine transfer to the United States. You should still confirm the hosting arrangements and any sub processors in your contract, and put standard contractual clauses in place if that ever changes.
A data protection impact assessment is strongly recommended. Target2Sell carries out systematic, large scale profiling of visitor behaviour to evaluate and personalise, which is exactly the kind of processing that triggers the need for a DPIA under the GDPR.
Block the Target2Sell tags behind a consent management platform, disclose every cookie in your cookie policy and privacy notice, and sign an Article 28 data processing agreement. Carry out a DPIA, set retention periods, and make sure consent can be withdrawn as easily as it was given.
Alternatives include other recommendation and personalisation engines such as Algolia Recommend, Nosto, Dynamic Yield and Kameleoon. Each has its own data and hosting practices, so review the cookies they set, where data is processed and the consent each one requires before choosing.
Yes. Your cookie policy and privacy notice should list the Target2Sell cookies and identifiers, explain their purpose and duration, name Target2Sell as a processor, and tell visitors how to manage or withdraw consent. Keep the policy in step with what the engine actually sets.