Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
SnapWidget embeds social media feeds, most commonly Instagram, on a website through an iframe served from snapwidget.com. The embedded widget loads media from social CDNs, exposing the visitor IP address to SnapWidget and to the underlying social network.
SnapWidget is a third party service that embeds social media feeds on websites using an iframe hosted on snapwidget.com. It is most commonly used to display an Instagram photo grid, but it also supports other social networks. The iframe loads all widget content from SnapWidget servers and renders media directly from social CDN domains such as scontent.cdninstagram.com, which is operated by Meta Platforms.
SnapWidget sets a snapwidget_session functional cookie for the duration of the session to maintain widget rendering state. The visitor IP address is sent to SnapWidget on every iframe load. When the widget renders Instagram images from scontent.cdninstagram.com, the visitor IP is also sent to Meta Platforms, which may set the datr advertising cookie (2 years) and other Meta cookies in the browser. A Cloudflare load-balancing or caching cookie such as _cfuvid may also be set by the infrastructure layer if SnapWidget uses Cloudflare.
Loading the SnapWidget iframe causes the visitor browser to make requests to snapwidget.com and to Meta CDN domains, transmitting the IP address to both third parties before the visitor interacts with the widget. Under the ePrivacy Directive this data exposure requires prior consent when it involves non-essential processing. Under GDPR the IP address is personal data. The website operator is responsible for obtaining consent before the iframe renders, as SnapWidget and Meta are separate data controllers for their respective processing.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The SnapWidget iframe must not render until the visitor has given consent. A common implementation is to replace the iframe with a placeholder image or blurred preview that shows a consent prompt, loading the real iframe only when the user clicks to enable it or after they opt in via the consent management platform. There is no cookieless mode available, so if consent is not given the widget must remain hidden.
SnapWidget operates from the United States and processes visitor IP addresses and request logs there. Embedded Instagram media is served by Meta Platforms from US infrastructure. Both transfers rely on the EU US Data Privacy Framework and standard contractual clauses as safeguards. Website operators should disclose both SnapWidget and Meta as data recipients in their privacy notice and reference the applicable transfer mechanism.
Block the SnapWidget iframe from rendering until the visitor consents to the social media category. Use a click to activate placeholder or integrate with your consent management platform. Add SnapWidget and Meta as data recipients and describe the US transfers in your privacy notice. List the snapwidget_session cookie and any Meta cookies in your cookie policy. Evaluate whether an alternative server-side Instagram feed renderer could eliminate or reduce client-side data exposure.
Websites using SnapWidget must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should be considered when SnapWidget is deployed on high-traffic pages, as the iframe exposes every visitor IP to both SnapWidget in the United States and to Meta Platforms when Instagram content is embedded. Assess whether the decorative social feed is necessary for the service, what data SnapWidget retains about requests, and whether an alternative server-side feed rendering could achieve the same purpose without client-side data exposure.
Sample consent text
We embed a SnapWidget social media feed on this website. When you enable this feature, SnapWidget and the underlying social network (such as Instagram or Meta) will receive your IP address and may set cookies on your device. Data is processed in the United States. You can withdraw your consent at any time.
Third-party domains contacted
snapwidget.comwidget.snapwidget.comscontent.cdninstagram.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| snapwidget_session | Functional | Session | Functional cookie set by SnapWidget to maintain the social feed widget rendering state during the browser session |
| datr | Marketing | 2 years | Meta Platforms browser identifier cookie set when Instagram media is loaded within the embedded widget, used for security and advertising |
| _cfuvid | Functional | Session | Cloudflare infrastructure cookie used for rate limiting and session management on SnapWidget servers |
SnapWidget places tracking cookies for advertising — comply with GDPR using FlowConsent.
SnapWidget sets a snapwidget_session functional cookie for the duration of the session to maintain the widget rendering state. When the widget displays Instagram images from scontent.cdninstagram.com, Meta Platforms may set the datr advertising cookie (2 years) and other Meta cookies. A Cloudflare infrastructure cookie such as _cfuvid may also be set if SnapWidget uses Cloudflare for load balancing or caching.
Yes. Loading the SnapWidget iframe sends the visitor IP to SnapWidget in the United States and, when Instagram content is displayed, also to Meta Platforms. Under the ePrivacy Directive, this data transmission to third parties for non-essential purposes requires prior consent. You must block the iframe from rendering until the user opts in to the social media category.
The legal basis is consent under Article 6(1)(a) of the GDPR and Article 5(3) of the ePrivacy Directive for the transmission of visitor IP addresses to SnapWidget and to Meta Platforms. SnapWidget and Meta are independent data controllers for their respective processing. Consent must be obtained before the iframe loads.
Yes. SnapWidget operates from the United States and processes visitor IP addresses and request logs there. When the widget displays Instagram media, Meta Platforms also processes the visitor IP from US infrastructure. Both transfers rely on the EU US Data Privacy Framework and standard contractual clauses. You should disclose both SnapWidget and Meta as data recipients in your privacy notice.
A DPIA should be considered when SnapWidget is deployed on high-traffic pages, as the iframe exposes every visitor IP to both SnapWidget and to Meta Platforms when Instagram content is embedded. Evaluate whether the decorative social feed is necessary for the service, what data SnapWidget retains, and whether a server-side feed renderer could achieve the same purpose without client-side data exposure.
Block the SnapWidget iframe from rendering until the visitor consents to the social media category. Use a click to activate placeholder or integrate with your consent management platform. Add SnapWidget and Meta as data recipients in your privacy notice and describe the US transfers. List the snapwidget_session cookie and any Meta cookies in your cookie policy. Evaluate whether a server-side Instagram feed renderer could reduce client-side data exposure.
Yes. Server-side Instagram feed renderers such as self-hosted solutions using the Instagram Basic Display API or tools like Instafeed.js with a backend proxy fetch and cache images on your own server, so the visitor browser only contacts your domain. This eliminates the exposure of the visitor IP to SnapWidget and Meta on every page load.
Your cookie policy should list snapwidget_session (duration session, category functional, purpose widget rendering state). If Instagram content is embedded also list datr (2 years, marketing, Meta browser identifier) and _cfuvid if present (session, functional, Cloudflare infrastructure). Identify SnapWidget and Meta Platforms as data controllers for their respective cookies and reference the US data transfer safeguards.