FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. FullStory
F

FullStory

AnalyticsWebsite

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Acuity Scheduling

Acuity Scheduling is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Acuity Scheduling integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Acuity Scheduling enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences

Affirm

Affirm is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Affirm is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Affirm offers reliable solutions that scale with organizational needs and evolving web standards.

Other

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does FullStory do?

FullStory is a US-based digital experience intelligence platform that captures complete session recordings of every user interaction — mouse movements, clicks, scrolls, rage clicks, and navigation paths. It provides heatmaps, funnel analysis, and AI-powered search across all recorded sessions. Under GDPR and CNIL guidelines, session recording at individual level is high-risk processing requiring mandatory consent, comprehensive input masking, and ideally a DPIA. FullStory offers EU data residency for enterprise customers.

What is FullStory?

FullStory is a digital experience intelligence platform that captures a pixel-perfect replay of every user session — recording the complete DOM state at every moment so teams can replay exactly what any individual user saw and did on their website or application. It provides session search and filtering, funnel analysis across recorded sessions, error detection, rage click tracking, heatmaps, and AI-powered insights that surface behavioural patterns across millions of sessions. FullStory is used by enterprise product, UX, and customer experience teams.

Why FullStory is high-risk under GDPR

FullStory captures every interaction of every user by default. Unlike sampling-based tools, it aims for complete session capture. This means FullStory creates an individual-level behavioural record for every single visitor, constituting large-scale systematic monitoring under GDPR. The CNIL and multiple European DPAs have specifically flagged session replay tools as requiring consent, careful masking, and in many cases a DPIA.

Data masking is non-negotiable

FullStory provides privacy controls including element exclusion (fs-exclude class), text masking (fs-mask), and page exclusion. Configure these comprehensively: exclude all text input fields by default, mask all personally identifiable content, exclude authenticated user areas and payment pages, and apply fs-unmask only to explicitly approved non-sensitive elements. The default FullStory configuration is not GDPR-safe without these protections applied.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

EU data residency and transfers

FullStory offers EU data residency for enterprise customers. For standard deployments, all session recordings are processed on US infrastructure requiring SCCs. Sign the FullStory DPA and SCCs. Request EU data residency if processing large volumes of EU user sessions. Disclose FullStory in your privacy policy and cookie banner.

Practical compliance steps

Conduct a DPIA before deployment. Block FullStory via CMP until consent. Configure fs-exclude on all input fields and sensitive elements. Exclude authenticated pages and payment flows. Sign DPA and SCCs. Apply recording retention limits. Implement FullStory User Privacy API for erasure requests. Consider EU data residency for enterprise deployments.

GDPR consent category

Analytics

Websites using FullStory must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) required for session recording and individual-level behavioural tracking under the ePrivacy Directive and CNIL guidelines. Session replay tools record comprehensive user behaviour and require explicit opt-in consent.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, SCCs for US deployments, DPIA strongly recommended

DPIA considerations

A DPIA is strongly recommended for FullStory deployments. Session recording all website or app users at individual level constitutes large-scale systematic monitoring — one of the explicit DPIA triggers under GDPR Article 35. Complete the DPIA before go-live and document data masking measures.

Sample consent text

We use FullStory to record and analyse how you use this website or application. This includes recording your mouse movements, clicks, and navigation. You can decline this recording below without affecting your ability to use our service.

Technical details

Tracking methodJavaScript tag, full session recording, DOM capture, rage clicks, error detection, heatmaps, AI-powered behavioural analytics
Server locationUnited States with EU data residency option
Data transferred outside the EUFullStory is a US-based digital experience intelligence platform. EU data residency is available for enterprise customers. For standard deployments, all session recordings and behavioural data are processed on US infrastructure requiring SCCs.

Third-party domains contacted

fullstory.comrs.fullstory.comedge.fullstory.com

Cookies placed

NameTypeDurationPurpose
fs_uidpersistent1 yearFullStory user session identifier enabling individual session recording and replay
_fs_ses.prvsessionSessionFullStory session tracking cookie grouping interactions within a single recorded session

FullStory collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

Does FullStory require GDPR consent?

Yes. FullStory records every user session and sets tracking cookies. This is high-risk processing requiring opt-in consent before the FullStory script loads. Block FullStory via your CMP until analytics consent is explicitly given.

What does FullStory record?

FullStory captures mouse movements, click positions, scroll depth, text input interactions (unless masked), page navigation, and rage clicks. It creates a complete visual replay of the user's session in the DOM at the time.

How do I prevent FullStory from capturing sensitive data?

Add the fs-exclude CSS class to all sensitive elements. Use fs-mask on text content. Apply _fs_run_in_iframe: false for embedded content. Exclude sensitive pages entirely. Test using FullStory's privacy tab in the Live Sessions tool to verify masking works correctly.

Do I need a DPIA for FullStory?

Yes. Recording all users at individual session level constitutes large-scale systematic monitoring — a specific DPIA trigger under GDPR Article 35. Complete the DPIA before deploying FullStory on any EU-facing product.

Does FullStory offer EU data residency?

Yes, for enterprise customers. Contact FullStory to enable EU data residency. Standard deployments use US infrastructure requiring SCCs. Request EU residency if your compliance requirements mandate EU-only processing.

What legal basis applies to FullStory?

Consent only. The CNIL specifically requires consent for session replay tools. Legitimate interest cannot justify recording every individual user session across an entire website or application.

How do I handle erasure requests for FullStory session data?

Use the FullStory User Privacy API to delete sessions associated with a specific user identity. Submit deletion requests programmatically. FullStory processes requests and removes sessions from its systems. Document all deletions for compliance records.

Are there GDPR-compliant alternatives to FullStory?

Hotjar (EU region available), Microsoft Clarity (US, requires SCCs), and Contentsquare (French, DPIA required) are the main alternatives. All session replay tools require consent and careful masking — FullStory's advantage is its depth of search and analysis capabilities.