FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. Pendo
P

Pendo

PreferencesWebsite

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Acuity Scheduling

Acuity Scheduling is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Acuity Scheduling integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Acuity Scheduling enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences

Affirm

Affirm is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Affirm is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Affirm offers reliable solutions that scale with organizational needs and evolving web standards.

Other

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Pendo do?

Pendo is a product analytics, in app guidance, NPS and Session Replay platform developed by Pendo.io Inc in Raleigh, North Carolina. The JavaScript SDK loaded from cdn.pendo.io captures user interactions, feature adoption, in app guide displays and survey responses inside a website or SaaS application, and sends events to AWS US regions by default. EU operators must collect consent where Pendo is used on public marketing pages, configure aggressive PII masking and run a DPIA when the Session Replay add on is enabled.

What Pendo is and how it works

Pendo is a product experience platform developed by Pendo.io Inc in Raleigh. The JavaScript SDK loaded from cdn.pendo.io instruments a website or a SaaS application to capture user interactions (clicks, page views, feature adoption), NPS responses, in app guide displays and product analytics events. Pendo also offers feedback and roadmap modules, a guide builder for tooltips, modals and onboarding flows, and an optional Session Replay add on. The platform is used by product, customer success and growth teams to measure adoption and engagement.

What data Pendo processes

Pendo processes the visitor identifier, account identifier, IP address, User Agent, page URL, language, custom user and account attributes the operator pushes via pendo.initialize, and a stream of interaction events (clicks, hovers, form interactions, NPS responses, guide views). The SDK sets first party cookies (_pendo_visitorId, _pendo_accountId, _pendo_meta) on the operator domain. When the Session Replay add on is enabled, full DOM mutations and masked form inputs are captured in the same way as a dedicated session replay tool.

GDPR, ePrivacy and consent

On public marketing pages, Pendo is not strictly necessary to the requested service and the SDK plus its cookies require prior opt in consent under Article 5(3) of the ePrivacy Directive. Inside an authenticated SaaS application, the operator can rely on Article 6(1)(b) GDPR (contract) and Article 6(1)(f) GDPR (legitimate interest) for product improvement, subject to a balancing test and clear information. Session Replay always requires explicit consent because of the high risk of incidentally capturing special category data.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International transfers and EU residency

Pendo.io Inc operates from the United States and processes events on AWS US regions by default. EEA visitor data is transferred to the US under the EU US Data Privacy Framework (Pendo is self certified) and Standard Contractual Clauses, with a documented transfer impact assessment. Enterprise customers can subscribe to the EU data residency add on that stores events in AWS Frankfurt, although the control plane and Session Replay analytics remain US operated.

Practical compliance and safer alternatives

Defer the SDK load on public pages until consent, mass mask all input fields in the Pendo configuration, configure URL exclusions for sensitive pages, reduce retention of events to the shortest period needed, sign the Pendo Data Processing Addendum, opt in to the EU data residency add on where available and run a DPIA when Session Replay is enabled. Safer alternatives include Heap, Amplitude with EU residency, Mixpanel with EU residency, Matomo Analytics self hosted and PostHog self hosted, which keep data inside the operator infrastructure.

GDPR consent category

Preferences

Websites using Pendo must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(a) GDPR (consent) for the SDK loading and the related tracking cookies on public marketing pages. Inside an authenticated SaaS application, Article 6(1)(b) GDPR (contract) and Article 6(1)(f) GDPR (legitimate interest) for product improvement and customer support may also be relied upon, subject to a balancing test. Session Replay always requires explicit consent.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, French CNIL guidance on product analytics, German TTDSG, Spanish LSSI, Schrems II case law, EU US Data Privacy Framework, EDPB Guidelines 4/2019 on systematic monitoring when Session Replay is enabled

DPIA considerations

A DPIA is recommended whenever Pendo is deployed on EU facing SaaS applications and required when the Session Replay add on is enabled. The DPIA must cover the consent flow on public pages, the lawful basis inside authenticated areas, the PII masking configuration, the international transfer to the United States, the EU data residency add on if subscribed and the retention of events and recordings.

Sample consent text

We use Pendo to understand how our product is used and improve the experience. Pendo processes interaction events, anonymised user identifiers and, with your additional opt in, Session Replay recordings through Pendo.io Inc in the United States. The SDK only loads after you accept analytics and performance cookies.

Technical details

Tracking methodJavaScript SDK loaded from cdn.pendo.io that instruments the application to capture user interactions (clicks, page views, feature usage), NPS survey responses, in app guide displays and product analytics events. Sets first party cookies on the operator domain and an optional Session Replay add on for full session recording.
Server locationPendo.io Inc is headquartered in Raleigh, North Carolina, USA. Production infrastructure runs on AWS US regions by default. An EU data residency option (AWS Frankfurt) is available for Enterprise customers, although the control plane and analytics layer remain US operated.
Data transferred outside the EUPendo.io Inc operates from the United States and processes product analytics events, in app guides and Session Replay recordings on AWS US regions by default. EEA visitor data is transferred to the US under the EU US Data Privacy Framework (Pendo is self certified) and Standard Contractual Clauses. Enterprise customers can opt in to the EU data residency add on for event storage in AWS Frankfurt, but the control plane and Session Replay analytics remain US operated.

Third-party domains contacted

pendo.iocdn.pendo.ioapp.pendo.iodata.pendo.io

Cookies placed

NameTypeDurationPurpose
_pendo_visitorIdhttp12 monthsAnonymous Pendo visitor identifier used to recognise the device or user across sessions.
_pendo_accountIdhttp12 monthsAccount identifier set by the operator through pendo.initialize to group visitors by tenant or workspace.
_pendo_metahttpSessionPendo metadata cookie storing the SDK state for the current page session.

Pendo uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Pendo set?

Pendo sets first party cookies on the operator domain: _pendo_visitorId (anonymous visitor identifier, 12 months), _pendo_accountId (account identifier when set by the operator, 12 months) and _pendo_meta (Pendo metadata, session). When Session Replay is enabled, additional helper identifiers tie the recording to the visitor. All cookies are non essential and require prior consent on public pages.

Does Pendo require user consent?

On public marketing pages, yes. The SDK and its cookies must be loaded only after prior opt in consent under Article 5(3) of the ePrivacy Directive. Inside an authenticated SaaS application, consent is not always required if the operator relies on Article 6(1)(b) GDPR (contract) and Article 6(1)(f) GDPR (legitimate interest), but transparency, opt out and the ability to disable Pendo per user remain mandatory.

What is the legal basis for Pendo processing?

Consent under Article 6(1)(a) GDPR on public pages. Contract or legitimate interest under Article 6(1)(b) or (f) GDPR inside authenticated SaaS applications, subject to a balancing test, transparency and the right to opt out. Session Replay always requires consent due to the risk of incidentally capturing special category data.

Does Pendo transfer data to the United States?

Yes by default. Pendo.io Inc is a US company and processes events on AWS US regions. EEA visitor data is transferred to the US under the EU US Data Privacy Framework (Pendo is self certified) and Standard Contractual Clauses. The EU data residency add on for Enterprise customers stores events in AWS Frankfurt but the control plane remains US operated.

Is a DPIA required for Pendo?

Recommended for any deployment on EU SaaS applications and required when the Session Replay add on is enabled. The DPIA must cover consent on public pages, lawful basis in authenticated areas, PII masking, US transfer, retention of events and recordings, and the safer alternatives evaluated.

How do I implement Pendo compliantly?

Defer the SDK load on public pages until consent, mask all input fields in the Pendo configuration, exclude sensitive URLs, reduce retention to the shortest period needed, sign the Pendo DPA, opt in to the EU data residency add on where available and run a DPIA when Session Replay is enabled. Use anonymous visitor IDs and avoid pushing direct identifiers through pendo.initialize.

What are safer alternatives to Pendo?

Heap, Amplitude with EU residency, Mixpanel with EU residency, FullStory with strict masking, Hotjar with EU servers, Matomo Analytics self hosted, PostHog self hosted, June.so. For regulated sectors or strict no transfer policies, self hosted alternatives (Matomo, PostHog) are usually preferred.

How do I update my cookie policy to include Pendo?

Document Pendo.io Inc as a processor located in the United States, list the Pendo cookies (_pendo_visitorId, _pendo_accountId, _pendo_meta) with retention and purpose, describe the in app analytics, guides and Session Replay if enabled, disclose the EU US Data Privacy Framework and Standard Contractual Clauses, and link to the Pendo privacy notice.