Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
TrackJS is a US JavaScript error monitoring service that captures client side errors, stack traces, and a timeline of user actions leading up to an error. It processes technical data such as IP address, browser, and URL, and its telemetry can incidentally capture data the user entered, but it does not rely on tracking cookies. Error monitoring can often be justified under legitimate interest, though the transfer of data to the US and the risk of capturing personal data in error context require care under the GDPR.
TrackJS is a client side error monitoring tool operated from the United States that helps developers detect and debug JavaScript errors in production. When added to a site, it watches for errors and records a stack trace plus a telemetry timeline of recent user actions such as clicks, network requests, and console messages. This context helps reproduce and fix bugs.
TrackJS processes the error message and stack trace, the page URL, browser and device details, and the IP address of the affected visitor. Its telemetry timeline can include values from the page, which may incidentally capture personal data the user typed unless you configure scrubbing. It typically does not set tracking cookies, relying instead on an in page token.
Because error monitoring is largely technical and does not require tracking cookies, it often avoids the ePrivacy consent requirement and can be based on legitimate interest under the GDPR. However, IP addresses and any incidentally captured input are personal data, so you must minimise and scrub them. TrackJS acts as your processor, so a data processing agreement is required.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
In its standard configuration TrackJS does not set non essential cookies, so a consent banner is usually not required for the monitoring itself. You should still inform users in your privacy notice and rely on legitimate interest, balanced against their rights. If telemetry is configured to capture form inputs or other personal data, reassess the basis and consider consent.
TrackJS is operated from the United States and processes error data there, so its use involves a third country transfer under Chapter V of the GDPR. Transfers rely on Standard Contractual Clauses and, where applicable, the EU US Data Privacy Framework, supported by a transfer impact assessment. Document the categories of data, including IP addresses, sent to the US.
To use TrackJS compliantly, enable data scrubbing to remove personal data from error telemetry, sign a data processing agreement, and complete a transfer impact assessment for the US transfer. Rely on legitimate interest with a documented balancing test, set retention limits for error data, and mention TrackJS in your privacy notice. Review the configuration when you change what telemetry captures.
Websites using TrackJS must obtain user consent under GDPR regulations.
DPIA considerations
TrackJS processes technical error data and a telemetry timeline that can incidentally capture personal data, plus IP addresses sent to the US, which shapes its risk profile. Key DPIA points: (1) transfer of personal data to TrackJS in the United States, requiring SCCs or the Data Privacy Framework and a transfer impact assessment; (2) risk that error telemetry captures form inputs or other personal data unless scrubbing is configured; (3) processing of IP addresses as part of error reports; (4) reliance on legitimate interest, requiring a balancing test; (5) the need for a data processing agreement and retention limits. A DPIA is advisable where telemetry is detailed or volumes are high.
Sample consent text
We use TrackJS to detect and fix errors on our website. TrackJS records technical details about errors, such as the page, browser, and a timeline of actions, along with your IP address, to help us debug problems. This data is processed by TrackJS in the United States under appropriate safeguards and on the basis of our legitimate interest in a reliable service. You can object to this processing as described in our privacy notice.
Third-party domains contacted
trackjs.comcapture.trackjs.comcdn.trackjs.comTrackJS collects user analytics data — you legally need a consent banner. Try FlowConsent free.
In its standard configuration TrackJS does not set tracking cookies. It identifies an error session using an in page token rather than persistent cookies, so the cookie footprint is minimal. Always confirm your specific integration.
Usually not for the monitoring itself, because it does not set non essential cookies and can rely on legitimate interest. You should inform users in your privacy notice, and you should reconsider if you configure telemetry to capture form inputs or other personal data.
Error monitoring is typically based on legitimate interest (Art. 6(1)(f)) in keeping the service reliable and secure, supported by a balancing test. Because it does not set tracking cookies, ePrivacy consent is generally not engaged for the standard setup.
Yes. TrackJS is operated from the United States and processes error data there, so its use is a third country transfer. It relies on Standard Contractual Clauses and, where applicable, the EU US Data Privacy Framework, which you should document in a transfer impact assessment.
A DPIA is advisable where telemetry is detailed or error volumes are high. Assess the US transfer, the risk that telemetry captures personal data, the processing of IP addresses, and your retention periods.
Enable data scrubbing to strip personal data from telemetry, sign a data processing agreement, complete a transfer impact assessment, and document your legitimate interest balancing test. Set retention limits for error data and mention TrackJS in your privacy notice.
Yes. Self hosted error monitoring such as GlitchTip or a self hosted Sentry instance, or EU hosted monitoring services, can keep error data in the EU. They reduce third country transfers while providing similar debugging context.
Because TrackJS does not set tracking cookies, focus your privacy notice on the error data it processes, including IP addresses and telemetry, and the fact that it is processed in the United States. If your integration does set any cookies, list them with purpose and duration, and review when the setup changes.