Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
User.com is an EU based full stack marketing automation, CRM and live chat platform that tracks visitor behaviour and builds unified profiles to trigger automated email, SMS, push, WhatsApp and chat messages.
User.com, formerly known as UserEngage, is a full stack marketing automation, CRM and live chat platform with roots in Poland and the European Union. It unifies marketing, sales and support by tracking how visitors behave on your website and turning that behaviour into automated messages across email, SMS, push, WhatsApp and live chat.
User.com combines a customer relationship management system with marketing automation and live chat in one tool. It identifies visitors, stores contact and behavioural records, and lets marketing teams build automated journeys without heavy development work. Because it sits across the whole customer lifecycle, it processes a wide range of personal and behavioural data on your behalf.
The User.com tracking script records page views, clicks, custom events, the pages and products a visitor looks at, plus device, browser and approximate location data. It sets first party cookies that store a visitor identifier and session details, then links this activity to a unified profile tied to cookies, email addresses and other identifiers. Over time this builds a rich behavioural picture of each person.
Storing identifiers in cookies and reading them back is regulated by the ePrivacy Directive, while the profiling and personalisation that follow fall under the GDPR. Because User.com builds detailed individual profiles, this counts as high risk processing. You act as the data controller and User.com acts as your processor, so a data processing agreement and clear documentation of the data flows are essential.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Tracking, profiling and marketing cookies require prior, freely given, specific and informed consent under Article 6(1)(a) of the GDPR and the ePrivacy rules. The User.com script and its cookies should only load after the visitor has actively opted in, and visitors must be able to refuse or withdraw consent as easily as they gave it. Only core CRM records strictly needed to deliver a contracted service may rely on contract or legitimate interest instead.
User.com hosts core data in the European Union, which keeps the main processing within the bloc. Some subprocessors used for email delivery, infrastructure or support may sit outside the EU. Where that happens, transfers should be covered by Standard Contractual Clauses and supplementary safeguards. Review the current subprocessor list and confirm the mechanisms before you rely on the platform.
Place User.com behind a consent management platform so the script fires only after opt in, list every User.com cookie in your cookie policy, and sign a data processing agreement. Carry out a Data Protection Impact Assessment because of the profiling, set sensible retention limits, and give people a clear way to access, object to or delete their profile. Keep your subprocessor and transfer records up to date.
Websites using User.com must obtain user consent under GDPR regulations.
DPIA considerations
User.com carries out extensive behavioural tracking and builds detailed individual profiles, which is a high risk processing activity that usually requires a Data Protection Impact Assessment. Document the data collected, retention periods and any transfers outside the EU. Pay particular attention to profiling, automated decisions and the volume of behavioural data tied to each visitor.
Sample consent text
We use User.com cookies and tracking to analyse your behaviour and personalise our marketing. Click Accept to allow this, or Reject to use only essential cookies.
Third-party domains contacted
user.comapp.user.comwidget.user.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| userid | Tracking | 1 year | Stores the unique User.com visitor identifier used to recognise returning visitors and link their activity to a unified profile. |
| user_session | Analytics | Session | Maintains the current browsing session so page views, clicks and events are grouped together for behavioural analysis. |
| __uc_ | Tracking | 1 year | First party tracking cookie that records visitor behaviour and ties events to the User.com profile for automation and personalisation. |
| user_chat | Functional | 6 months | Keeps live chat state so a conversation and its history can continue across page loads and visits. |
User.com places tracking cookies for advertising — comply with GDPR using FlowConsent.
User.com sets first party cookies that store a visitor identifier and session details so it can recognise returning visitors and link their behaviour to a profile. These are tracking and analytics cookies rather than strictly necessary ones, so they need consent. List every User.com cookie you deploy in your cookie policy with its name, purpose and duration.
Yes. Because User.com tracks behaviour, sets non essential cookies and builds marketing profiles, you must obtain prior, freely given, specific and informed consent before the script loads. Only core CRM records strictly needed to deliver a service you have agreed to provide may rely on another legal basis.
For tracking, profiling and marketing the legal basis is consent under Article 6(1)(a) of the GDPR, combined with the ePrivacy requirement to obtain consent before storing or reading cookies. Contract under Article 6(1)(b) or legitimate interest under Article 6(1)(f) may cover only the core CRM data needed to run a contracted service.
User.com hosts core data in the European Union, but some subprocessors used for email delivery, infrastructure or support may process data outside the EU, including in the United States. Where that happens, transfers should rely on Standard Contractual Clauses and supplementary safeguards. Check the current subprocessor list to confirm where your data goes.
Most likely yes. User.com carries out large scale behavioural tracking and profiling, which the GDPR treats as high risk and which usually triggers the need for a Data Protection Impact Assessment. The assessment should document the data collected, the profiling logic, retention periods and any transfers outside the EU.
Load the User.com script only after the visitor opts in through a consent management platform, block its cookies until then, and offer an equally easy way to refuse or withdraw. Sign a data processing agreement, document cookies and subprocessors, set retention limits and complete a DPIA before going live.
Alternatives range from EU based marketing automation and CRM tools to privacy focused or self hosted options that minimise profiling. When comparing them, look at where data is hosted, whether tracking can run without non essential cookies, the clarity of the subprocessor list and how transfers outside the EU are handled.
Add a clear entry for User.com that lists each cookie, its purpose and duration, explains that it supports behavioural tracking and marketing profiling, and states that it runs only after consent. Keep the entry in step with the cookies actually set and review it whenever User.com changes its tracking.