FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. OneSignal
O

OneSignal

Marketing

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does OneSignal do?

OneSignal is one of the most widely used web and mobile push notification platforms, operated from the United States. It registers a service worker on your website to send push notifications and tracks subscription tokens, device metadata and IP addresses on AWS US infrastructure. Both the push subscription and the related cookies require explicit user consent in addition to the browser native push prompt.

What is OneSignal?

OneSignal is a customer engagement platform founded in 2014 in San Mateo, California. It is one of the most widely used solutions for web push, mobile push, in app messaging, email and SMS, with over a million sites and apps using it. The web SDK registers a service worker on the publisher domain to handle push notifications.

Cookies and data collected

OneSignal stores a push subscription identifier, the OneSignal player ID and a device record (browser, OS, country, language, IP address). On the publisher site it registers a service worker (OneSignalSDKWorker.js) and uses localStorage for the player ID. Mobile SDKs collect installation and app usage events. Subscriber tags and segments may include any custom attribute the publisher attaches.

GDPR and ePrivacy implications

Web push is a non essential tracker according to most EU regulators, so the OneSignal SDK and its service worker should be loaded only after the user gives consent under Art. 5(3) ePrivacy. The browser native push prompt is an additional but not sufficient consent because it does not cover the prior storage and processing required to register the subscription. Marketing notifications themselves rely on consent (Art. 6(1)(a) GDPR).

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and hosting

OneSignal hosts its primary infrastructure on AWS US. Subscription tokens, device records, IP addresses and engagement events are processed in the United States. Transfers rely on the EU US Data Privacy Framework certification (where applicable) and on Standard Contractual Clauses included in the OneSignal DPA. Enterprise plans may offer regional residency options.

Practical compliance steps

Sign the OneSignal DPA from the dashboard. Block the OneSignal SDK behind your CMP and load it only after explicit opt in. Use a custom soft prompt before requesting the browser native push permission, with a clear description of the purpose. Add OneSignal to your privacy notice with the US transfer, the SCC and DPF basis and the categories of data collected. Provide an obvious unsubscribe path inside notifications and the OneSignal subscriber settings.

GDPR consent category

Marketing

Websites using OneSignal must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for the push subscription, the marketing notifications and the related cookies on the website. Browser native push prompts also require an unambiguous user opt in. Consent must be granular and reversible.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, CAN-SPAM, CCPA, EU US Data Privacy Framework

DPIA considerations

A DPIA is recommended for OneSignal deployments that combine large subscriber bases, behavioural segmentation and cross device user identification, given the persistent identifiers involved and the US transfer.

Sample consent text

We use OneSignal (OneSignal Inc., United States) to send push notifications. By accepting you consent to the registration of a push subscription, the related identifiers and the transfer of your data to OneSignal in the US under appropriate safeguards.

Technical details

Tracking methodweb push notification SDK and mobile push SDK; service worker registration on the website domain, push subscription tokens managed by the OneSignal backend
Server locationUnited States (OneSignal Inc., San Mateo, California; primary processing on AWS US, with regional edge nodes)
Cookieless tracking availableYes
Data transferred outside the EUOneSignal Inc. is a US company. Push subscription tokens, device metadata, in app activity and IP addresses are processed on AWS US infrastructure. Transfers rely on the EU US Data Privacy Framework certification (where applicable) and on Standard Contractual Clauses included in the OneSignal DPA. Some EU customers can request data residency options on Enterprise plans.

Third-party domains contacted

cdn.onesignal.comapi.onesignal.comonesignal.comimages.onesignal.com

Cookies placed

NameTypeDurationPurpose
onesignal-pageview-countfirst_partyPersistent (localStorage)Tracks the number of pageviews so OneSignal can trigger a soft prompt after a configured threshold.
onesignal-notification-promptfirst_partyPersistent (localStorage)Records whether the user has dismissed the soft prompt to avoid repeated prompting.

OneSignal places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

What identifiers does OneSignal set?

OneSignal stores a push subscription identifier and the OneSignal player ID in localStorage on the publisher domain, registers a service worker (OneSignalSDKWorker.js) and sends a device record (browser, OS, country, language, IP) to its backend. Optional pageview and prompt counters are also stored in localStorage.

Do I need consent to use OneSignal?

Yes. Most EU regulators consider web push a non strictly necessary tracker, so the OneSignal SDK and its service worker must be loaded only after consent under Art. 5(3) ePrivacy. The browser native push prompt is an additional but not sufficient consent because it does not cover the prior storage and registration steps.

What is the legal basis for OneSignal?

Consent (Art. 6(1)(a) GDPR) for the push subscription, the related identifiers and the marketing notifications. The opt in must be granular and as easy to withdraw as it was to give. Notification scheduling and analytics performed in the OneSignal backend are sub processing under Art. 28.

Does OneSignal transfer data to third countries?

Yes. OneSignal Inc. is a US company and its primary infrastructure runs on AWS US. Subscription tokens, device records, IP addresses and engagement events are processed in the United States. Transfers rely on the EU US Data Privacy Framework certification (where applicable) and on the Standard Contractual Clauses included in the OneSignal DPA.

Do I need a DPIA for OneSignal?

A DPIA is recommended for OneSignal deployments that combine large subscriber bases, behavioural segmentation and cross device user identification, given the persistent identifiers involved and the US transfer.

How do I implement OneSignal compliantly?

Sign the OneSignal DPA. Block the SDK behind your CMP and load it only after explicit opt in. Use a custom soft prompt explaining the purpose before requesting the browser native push permission. Add OneSignal to your privacy notice with the US transfer, the SCC and DPF basis, and the categories of data collected. Provide an obvious unsubscribe path inside notifications.

Are there alternatives to OneSignal in the EU?

EU based alternatives include WonderPush (France), Pushwoosh (data residency in EU available), Sendmunk (Germany) and self hosted Mautic with the web push extension. For mobile only, Firebase Cloud Messaging from EU regions can be used for transactional messages but raises similar transfer questions for marketing.

How should I update my privacy policy for OneSignal?

State that OneSignal (OneSignal Inc., United States) is a processor for push notifications and engagement. Describe the service worker, the player ID, the device record, the IP address processing and the campaign analytics. Note the US transfer with the SCC and DPF basis, and provide a one click unsubscribe link or page.