Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Nosto is an ecommerce personalization and product recommendation engine. It tracks shopper behaviour such as product views, searches, cart actions and purchases to build individual profiles, then delivers tailored recommendations, content and offers. Because it relies on behavioural profiling and non essential cookies, it requires consent under GDPR and the ePrivacy rules.
Nosto is an ecommerce personalization and product recommendation engine used by online retailers. It observes how each visitor interacts with a store, including the products they view, the searches they run, the items they add to the cart and the purchases they complete. From these signals it builds individual shopper profiles and uses them to display tailored product recommendations, personalized content, pop ups and offers. It is not a generic web analytics tool, its core purpose is real time behavioural profiling for personalization.
Nosto deploys a JavaScript tag that sets first party cookies and identifiers such as 2c.cId and nosto related cookies. These persist a visitor identifier and capture browsing history, product views, cart contents and purchase behaviour. This information is linked to a profile that can recognise the same shopper across sessions. Because the data describes individual behaviour and is tied to persistent identifiers, it constitutes personal data under the GDPR.
The cookies and identifiers Nosto uses are not strictly necessary to deliver the website, so Article 5(3) of the ePrivacy Directive requires consent before they are stored or read. The profiling activity also needs a lawful basis under the GDPR, and for this kind of personalization the appropriate basis is the consent of the individual under Article 6(1)(a). Profiling carries transparency obligations, and shoppers must be informed clearly about how their behaviour is used.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent must be freely given, specific, informed and unambiguous, and Nosto should only load after the visitor has accepted personalization cookies. Depending on the hosting region and integrations, data may be transferred outside the European Economic Area, including to the United States. Such transfers require safeguards such as Standard Contractual Clauses or reliance on the EU US Data Privacy Framework, together with a transfer risk assessment.
Block the Nosto tag until consent is captured through a compliant consent management platform, document the cookies and their purposes in your cookie policy, and provide an easy way to withdraw consent. Sign a data processing agreement with Nosto, verify the hosting region, review the transfer safeguards, and assess whether a Data Protection Impact Assessment is needed given the scale of profiling. Keep records of consent and regularly audit what the tag actually loads.
Websites using Nosto must obtain user consent under GDPR regulations.
DPIA considerations
Nosto performs systematic behavioural profiling of online shoppers to personalize content and recommendations. A Data Protection Impact Assessment is recommended where profiling is extensive or combined with other data sources. Assess the scale of profiling, the use of unique identifiers, possible transfers to third countries, and the impact on individuals who cannot easily avoid the processing.
Sample consent text
We use Nosto to personalize product recommendations and content based on your browsing and purchase behaviour. This involves cookies and profiling. Do you consent to personalization powered by Nosto?
Third-party domains contacted
nosto.comconnect.nosto.comapi.nosto.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| 2c.cId | HTTP cookie | Persistent (up to 1 year) | Stores a unique visitor identifier used to build the shopper profile and serve personalized recommendations. |
| nostoTab | HTTP cookie | Session | Coordinates Nosto behaviour across browser tabs during a visit. |
| 2c.ts | HTTP cookie | Persistent | Records timestamp and session information for behavioural tracking and personalization. |
Nosto collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Nosto sets first party cookies and identifiers such as 2c.cId and other nosto related cookies. They store a visitor identifier and record browsing history, product views, cart contents and purchases so the engine can build a shopper profile and serve personalized recommendations.
Yes. The cookies and profiling Nosto relies on are not strictly necessary, so under Article 5(3) ePrivacy and Article 6(1)(a) GDPR you must obtain prior, freely given and informed consent before the tag loads.
The appropriate legal basis is consent under Article 6(1)(a) GDPR, combined with consent for cookie storage under Article 5(3) of the ePrivacy Directive. Legitimate interest is generally not sufficient for this kind of behavioural personalization.
Depending on the hosting region and integrations, data may be transferred outside the EEA, including to the United States. Such transfers require Standard Contractual Clauses or reliance on the EU US Data Privacy Framework, plus a transfer risk assessment.
A Data Protection Impact Assessment is recommended where the profiling is extensive or combined with other datasets. Nosto carries out systematic behavioural profiling, so assess scale, identifiers and transfers to decide whether a DPIA is mandatory.
Load Nosto only after consent through a consent management platform, document its cookies in your cookie policy, sign a data processing agreement, verify hosting and transfer safeguards, and provide an easy way to withdraw consent.
Alternatives include other ecommerce personalization engines and recommendation tools, or first party server side approaches with reduced tracking. Any alternative that profiles shoppers raises the same consent and transfer questions, so evaluate data location and minimisation.
List the Nosto cookies and identifiers, describe their personalization and profiling purpose, state their duration, name Nosto as a processor, and disclose possible transfers outside the EEA together with the safeguards used.