Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Vue.ai by Mad Street Den is a retail AI platform that uses visual AI to automate product tagging and deliver personalised recommendations, profiling shoppers and product images to tailor ecommerce experiences.
Vue.ai, built by Mad Street Den, is a retail and enterprise AI platform that brings visual AI to ecommerce. It automates product tagging, powers visual search and generates personalised recommendations by analysing both product imagery and the behaviour of visitors and shoppers. Because Vue.ai profiles individuals to tailor the experiences they see, deploying it on a website that serves European users brings clear obligations under the GDPR and the ePrivacy Directive.
Vue.ai is an AI suite for retailers that combines computer vision and machine learning. Its core capabilities include automated product tagging, catalogue management, visual search, and personalised product recommendations. Founded in 2016 and headquartered in Redwood City, California, with engineering operations in Chennai, India, the company was acquired by M2P in 2025. When integrated into an online store, Vue.ai studies how each shopper navigates and which products they engage with, then uses that profile to surface tailored content and recommendations.
To personalise recommendations, Vue.ai relies on JavaScript tags and APIs that capture behavioural signals such as page views, product clicks, browsing paths, search terms and add to cart actions. It typically sets cookies or uses similar identifiers to recognise a returning visitor and to keep a consistent personalisation profile across a session and between visits. This information is behavioural and tied to an identifier, so under European law it is treated as personal data even when no name or email is collected directly.
Vue.ai is not strictly necessary to deliver a website, so the ePrivacy Directive requires prior consent before its cookies and identifiers are placed on a user device. The profiling it performs also engages the GDPR, since shoppers are categorised and targeted based on automated analysis of their behaviour. The appropriate legal basis for this personalisation, profiling and analytics activity is consent under Article 6(1)(a), and that consent must be freely given, specific, informed and as easy to withdraw as it was to grant.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Vue.ai tags should load only after the visitor has accepted personalisation cookies through your consent management platform. The default state must be no tracking, with no pre ticked boxes and no reliance on legitimate interests for these purposes. Your consent banner needs to name the personalisation activity clearly, explain that profiling shapes the recommendations shown, and offer a genuine reject option. Records of consent should be retained so you can demonstrate compliance to a supervisory authority.
Vue.ai processes data in the United States and in India, so personal data from the European Union leaves the EEA. Transfers to the United States can be covered by the EU US Data Privacy Framework where the provider is certified, while transfers to India, which is not the subject of an adequacy decision, rely on Standard Contractual Clauses backed by a transfer impact assessment and suitable technical safeguards. You should confirm the current transfer mechanism in your data processing agreement and keep it under review.
Start by mapping every Vue.ai cookie and identifier and adding them to your cookie policy with clear purposes and durations. Gate the tags behind your consent platform so they fire only on acceptance, and test that rejection truly blocks them. Sign a data processing agreement that addresses transfers to the United States and India, complete a data protection impact assessment for the profiling, and review the setup periodically as Vue.ai features evolve. Together these steps let you use AI personalisation while respecting European privacy law.
Websites using Vue.ai must obtain user consent under GDPR regulations.
DPIA considerations
Vue.ai performs profiling of shoppers by analysing browsing behaviour and product interactions to drive AI personalisation, which constitutes large scale automated processing that can require a data protection impact assessment. Controllers should document the personalisation logic, assess risks to individuals and evaluate transfers to the United States and India. A DPIA is recommended where Vue.ai is deployed across high traffic ecommerce properties.
Sample consent text
We use Vue.ai to analyse your browsing and product interactions so we can personalise recommendations; these analytics and personalisation cookies are only set with your consent.
Third-party domains contacted
vue.aimadstreetden.comapi.vue.aiCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| vue_visitor_id | Personalisation | 12 months | Assigns a persistent visitor identifier so Vue.ai can recognise returning shoppers and link their behaviour to a stable personalisation profile. |
| vue_session | Personalisation | Session | Maintains the current personalisation session, tying together page views and product interactions during a single visit. |
| vue_personalisation | Personalisation | 6 months | Stores personalisation preferences and recommendation signals used to tailor the product recommendations shown to the shopper. |
| vue_behaviour | Analytics | 13 months | Records behavioural events such as clicks, searches and add to cart actions to train and serve the AI personalisation models. |
Vue.ai uses cookies for user preferences — inform visitors with a consent banner.
Vue.ai typically sets personalisation and visitor identification cookies or similar identifiers. These store a stable visitor ID, recognise returning shoppers and hold the personalisation profile used to tailor product recommendations across a session and between visits.
Yes. Vue.ai is not strictly necessary to run a website and it profiles shoppers, so the ePrivacy Directive and the GDPR require prior, freely given consent before its tags and cookies are loaded on the user device.
The appropriate legal basis is consent under Article 6(1)(a) GDPR, covering personalisation, profiling and analytics cookies. Legitimate interests is not a valid basis for placing these non essential cookies under the ePrivacy Directive.
Vue.ai processes data in the United States and in India, so personal data from the EU leaves the EEA. US transfers can rely on the EU US Data Privacy Framework, while transfers to India rely on Standard Contractual Clauses with a transfer impact assessment.
A data protection impact assessment is recommended. Vue.ai carries out large scale profiling of shoppers to drive automated personalisation, which can pose a high risk to individuals and triggers the DPIA criteria, especially on high traffic stores.
Gate Vue.ai tags behind your consent platform so they fire only after acceptance, document every cookie in your policy, sign a data processing agreement covering US and India transfers, run a DPIA and test that rejecting consent truly blocks tracking.
Alternatives include other visual AI and personalisation providers such as Algolia, Bloomreach, Dynamic Yield and Nosto. Each still requires consent for non essential cookies and a transfer assessment where data leaves the EEA under European law.
Yes. List every Vue.ai cookie and identifier in your cookie policy with a clear purpose and retention period, explain the personalisation and profiling involved, and keep the entries accurate as Vue.ai features evolve.