Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Gravitec is an EU based web push notification service that subscribes visitors to browser push notifications through service workers and push tokens and sends campaigns. It requires explicit browser push permission and consent for its analytics cookies, so it should not run until both are given. As an EU provider its transfers are limited, but operators should still document the legal basis and the subscription data it processes.
Gravitec is an EU based web push notification service, operated from Estonia, that lets websites subscribe visitors to browser push notifications and send them campaigns. It works through its own domains, including gravitec.net, app.gravitec.net and cdn.gravitec.net, and uses the browser push mechanism rather than email. For the operator it is a marketing third party that processes subscription data and can use analytics cookies to measure campaign performance.
Gravitec registers a service worker in the visitor browser and, once the visitor grants push permission, obtains a push token from the browser push service. That token is used to deliver notifications even when the visitor is not on the site. Alongside this, Gravitec can set analytics cookies to track opt ins, deliveries, and clicks so that campaign performance can be measured.
Gravitec typically processes push subscription tokens, subscriber identifiers, and engagement data such as deliveries and clicks, and it can set analytics cookies for measurement. The push token and related signals can constitute personal data because they identify a specific browser or device. Operators should review the exact cookies and the subscriber data in their own setup, since the precise fields can vary by configuration.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Web push and analytics cookies both bring Gravitec within the GDPR and the ePrivacy Directive. Sending push notifications is a form of electronic marketing that requires the visitor to opt in, and the analytics cookies are not strictly necessary, so they require consent. The push subscription itself relies on explicit browser permission, which should be requested in a clear, non deceptive way and recorded as part of the consent trail.
Consent should cover both the push subscription and the analytics cookies, and the service should not run until the visitor has accepted. Gravitec is EU based and processes primarily within the EU, so third country transfers are limited, although push delivery depends on browser push services that can use global infrastructure. Where any such routing involves a transfer, operators should confirm that appropriate safeguards are in place and disclose the processing in their notices.
To deploy Gravitec compliantly, request push permission clearly and gate the analytics cookies behind a consent category, then block both until consent is given. Provide an easy way to unsubscribe and to withdraw consent, and make sure withdrawal stops notifications and clears the analytics cookies. List Gravitec and its domains in your cookie policy, document the legal basis, and keep subscriber data to the minimum needed with sensible retention.
Websites using Gravitec must obtain user consent under GDPR regulations.
DPIA considerations
A full DPIA is usually not mandatory for standard web push, but a documented risk assessment is recommended where push tokens, subscriber lists, and analytics cookies are combined. Assess the volume of subscribers, the data linked to push tokens, and any analytics profiling, and record mitigations such as double opt in, clear permission prompts, and easy unsubscribe.
Sample consent text
We use Gravitec to send browser push notifications and to measure how they perform. This requires your explicit push permission and may set analytics cookies. With your consent, Gravitec push notifications and these cookies will be activated.
Third-party domains contacted
gravitec.netgravitec.netapp.gravitec.neteu.gravitec.netcdn.gravitec.netfcm.googleapis.comupdates.push.services.mozilla.comweb.push.apple.comwns2-by3p.notify.windows.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| gravitecSubscriptionId | Functional | Persistent | Stores the unique push subscription identifier that links the browser to the Gravitec account |
| gravitec_subscriber | persistent | 1 year | Links the browser to its push subscription so notifications can be delivered and managed. |
| gravitec_permission | persistent | 1 year | Records the push permission state so the prompt is not shown again unnecessarily. |
| _grsm | Functional | 6 months | Remembers the subscription state and whether the permission prompt has already been shown |
| gravitec_analytics | persistent | 6 months | Measures opt ins, deliveries, and clicks to evaluate campaign performance. |
| _ga | Analytics | 2 years | Google Analytics cookie used on the Gravitec dashboard to distinguish unique visitors |
| gravitec_session | session | Session | Maintains state during a single visit while the subscription flow runs. |
| _gid | Analytics | 24 hours | Google Analytics cookie that distinguishes visitors over a short period |
| grtc_segment | Functional | 1 year | Stores segmentation attributes used to target push campaigns to the subscriber |
Gravitec places tracking cookies for advertising — comply with GDPR using FlowConsent.
Gravitec typically sets cookies that link the browser to its push subscription, record the push permission state, and support analytics for deliveries and clicks. The analytics cookies are non essential and require consent, while the subscription cookies relate to the push opt in. Confirm the exact cookies in your own deployment, since they can vary by configuration.
Yes, consent is required for both the push subscription and the analytics cookies. The push notifications need an explicit opt in and the browser push permission, and the analytics cookies are not strictly necessary. Gravitec should not run until the visitor has accepted.
The legal basis is consent under Article 6(1)(a) GDPR for the push subscription and for the analytics cookies. Sending push messages is electronic marketing that relies on opt in consent. Record both the push permission and the cookie consent in your consent trail.
Gravitec is EU based and processes primarily within the EU, so third country transfers are limited. However, push delivery relies on browser push services that can route through global infrastructure. Where any such routing involves a transfer, confirm that appropriate safeguards are in place.
A full DPIA is usually not mandatory for standard web push, but a documented risk assessment is recommended. Pay attention where push tokens, subscriber lists, and analytics cookies are combined at scale. Record mitigations such as double opt in, clear prompts, and easy unsubscribe.
Request push permission clearly and gate the analytics cookies behind a consent category, blocking both until consent is given. Provide easy unsubscribe and consent withdrawal that stops notifications and clears the analytics cookies. List Gravitec and its domains in your cookie policy and document the legal basis.
Other web push providers exist, including EU hosted options, and email or in app messaging can serve similar goals with different consent needs. Whichever you choose, web push still requires an explicit opt in and, for analytics, cookie consent. Evaluate alternatives on data location, opt in design, and contractual terms.
Add Gravitec as a named third party, describe its subscription and analytics cookies, and explain that it sends browser push notifications after an explicit opt in. Reference its domains such as gravitec.net and app.gravitec.net and link to its policy. Review the entry whenever the cookies or processing change.