Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Apollo, also known as Apollo.io, is a United States based business to business sales intelligence and engagement platform. On websites it is deployed as a visitor tracking script and, in outbound email, as tracking pixels. The script writes a first party cookie, builds an anonymous visitor profile and matches it against the Apollo contact database, which is extensive personal data, in order to reveal the companies and contacts behind a visit. Because this is non essential tracking that identifies people, Apollo must load only after the visitor has given consent.
Apollo, also known as Apollo.io, is a business to business sales intelligence and engagement platform based in the United States. On a website it is deployed as a visitor tracking script that loads from Apollo servers, and in outbound email it appears as tracking pixels embedded in messages. The tracker turns anonymous website traffic into named accounts and contacts by writing a first party cookie, building a visitor profile and matching that profile against the very large contact database that Apollo maintains.
When a visitor lands on a page that carries the Apollo script, the tracker writes a first party cookie to the browser, generates an anonymous visitor identifier and records behavioural events such as the pages viewed, the time spent and the navigation path. These events are sent to Apollo ingestion endpoints through track_request calls. Apollo then matches the visitor and any collected identifiers against its own contact database, which holds extensive personal data on business professionals, in order to reveal the company and, where possible, the specific individuals behind the visit. In outbound email, Apollo tracking pixels record when a message is opened and can tie that action back to a known contact.
The visitor identifiers, behavioural events and matched contact records that Apollo processes are personal data under the GDPR, because they relate to identifiable people and are used to profile them. Writing and reading a cookie on the visitor device falls squarely within Article 5(3) of the ePrivacy Directive, which the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain all enforce as a strict prior consent obligation for non essential trackers. The matching of visitor data against a large third party database is exactly the kind of large scale profiling that European regulators scrutinise most closely.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before the Apollo tracking script loads, because it is not strictly necessary to deliver the content of the page and it identifies the visitor. That consent must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as to accept. Until the visitor accepts, the script must not run, no first party cookie should be written and no behavioural events should be sent to Apollo. Legitimate interest for the underlying contact database is heavily contested by European regulators and should not be relied upon for this tracking.
Apollo processes visitor data, behavioural events and matched contact records on United States based infrastructure, so European visitor and prospect data is transferred outside the European Economic Area. Such transfers require the EU Standard Contractual Clauses within the Apollo Data Processing Addendum and a documented Transfer Impact Assessment that considers United States surveillance law, in line with the Schrems II ruling and the guidance of the European Data Protection Board. The enrichment of visitor data against a United States held database adds further weight to the need for a robust transfer assessment.
Gate the Apollo script behind your consent management platform so that it fires only after the marketing or analytics category has been accepted, and classify Apollo under that category. Provide clear information about Apollo in your cookie policy, including the first party cookie it sets and its lifetime, the behavioural tracking it performs and the matching against the Apollo database. Sign the Apollo Data Processing Addendum, complete a Transfer Impact Assessment and apply the shortest workable retention on visitor and prospect records. Where contact level identification is not needed, avoid enabling it, and review whether legitimate interest can genuinely be justified before relying on it.
Websites using Apollo must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is strongly advisable, and often mandatory, when Apollo is used to track website visitors and match them against its very large contact database, because this combines behavioural tracking with large scale profiling and enrichment of identifiable people. Document the visitor identifiers written by the tracking script, the behavioural events sent to Apollo, the matching against the Apollo contact database, the email tracking pixels, the transfer of data to the United States and the retention period applied to visitor and prospect records. Configure the script so that it loads only after consent and avoid enabling contact level identification where it is not strictly necessary.
Sample consent text
We use Apollo, a sales intelligence service operated by Apollo.io (ZenProspect, Inc., United States), to understand which organisations visit our site. Apollo stores a first party cookie on your device, records how you browse and matches this data against its own contact database. This data may be transferred to the United States under the EU Standard Contractual Clauses. Apollo will only load if you click Accept.
Third-party domains contacted
apollo.ioassets.apollo.ioapi.apollo.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Apollo website visitor tracking cookie | HTTP cookie (first party) | Up to 12 months | Set by the Apollo tracking script (tracker.iife.js) when a visitor loads a page. Stores an anonymous visitor identifier so Apollo can recognise the browser across visits and attribute behavioural events to a single visitor profile, which is then matched against the Apollo contact database. |
| Apollo tracking event buffer | localStorage | Persistent (until cleared) | Used by the Apollo tracker to hold visitor state and buffer behavioural events (pages viewed, time spent, navigation path) on the device before they are sent to Apollo ingestion endpoints through track_request calls. |
Apollo places tracking cookies for advertising — comply with GDPR using FlowConsent.
The Apollo tracking script sets a first party cookie that stores an anonymous visitor identifier, typically lasting up to twelve months, and it uses browser storage to buffer behavioural events before sending them to Apollo. Together they let Apollo recognise a returning visitor and record how each page is used.
Yes. The Apollo tracker performs non essential behavioural tracking and writes a first party cookie to the visitor device, so under the ePrivacy rules you must obtain prior consent before the script loads. It should stay blocked until the visitor accepts.
The only valid legal basis is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. Legitimate interest for the underlying Apollo contact database is heavily contested by European regulators and should not be relied on for this tracking.
Yes. Apollo hosts its platform, tracking infrastructure and contact database on United States infrastructure, so European visitor and prospect data is transferred there. You need the EU Standard Contractual Clauses in the Apollo Data Processing Addendum and a Transfer Impact Assessment to cover the transfer.
A Data Protection Impact Assessment is strongly recommended, and often mandatory, because Apollo combines behavioural tracking with large scale profiling by matching visitors against its contact database. Assess the tracking, the identifiers stored on the device, the enrichment against the Apollo database and the United States transfer.
Load the tracking script only through your consent management platform after the marketing or analytics category is accepted, describe Apollo in your cookie policy, sign the Data Processing Addendum and complete a Transfer Impact Assessment. Avoid contact level identification where it is not needed and apply a short retention period.
Alternatives for sales intelligence and visitor identification include ZoomInfo, Lusha, Cognism, Leadfeeder and Clearbit. They raise similar consent, cookie and transfer questions, so review their hosting location and data processing terms before assuming any of them is lighter on privacy.
Add a dedicated entry that names Apollo.io (ZenProspect, Inc.) as the provider, lists the first party visitor cookie with its lifetime, explains the behavioural tracking and the matching against the Apollo contact database, and discloses the United States transfer and its safeguard. Keep the entry in step with your consent categories.